Monday, 2015-12-21

*** markvoelker has quit IRC00:04
*** chlong has joined #openstack-keystone00:05
*** gildub_ has joined #openstack-keystone00:05
*** hogepodge has quit IRC00:16
*** hogepodge has joined #openstack-keystone00:22
*** hogepodge has quit IRC00:27
*** tiny-hands has joined #openstack-keystone00:28
*** hogepodge has joined #openstack-keystone00:43
*** dims has joined #openstack-keystone00:43
openstackgerritMerged openstack/keystoneauth: Add some documentation about migrating from ksc  https://review.openstack.org/25925600:44
*** dims has quit IRC01:02
*** sdake_ has joined #openstack-keystone01:03
*** sdake has quit IRC01:04
*** markvoelker has joined #openstack-keystone01:05
*** tiny-hands has quit IRC01:06
*** EinstCrazy has joined #openstack-keystone01:06
*** markvoelker has quit IRC01:10
*** dims has joined #openstack-keystone02:07
*** jasonsb has joined #openstack-keystone02:07
*** jasonsb has quit IRC02:07
*** jasonsb has joined #openstack-keystone02:09
*** markvoelker has joined #openstack-keystone02:36
*** woodster_ has quit IRC02:36
*** markvoelker has quit IRC02:40
*** jmccrory has quit IRC02:41
*** jmccrory has joined #openstack-keystone02:43
*** sdake_ has quit IRC02:47
*** dave-mccowan has quit IRC02:51
*** jasonsb has quit IRC03:01
openstackgerritChangBo Guo(gcb) proposed openstack/keystone: Use the oslo.utils.reflection to extract the class name  https://review.openstack.org/24149403:22
*** wanghua has quit IRC03:23
*** links has joined #openstack-keystone03:26
*** dims has quit IRC03:32
*** agireud has quit IRC04:03
*** Guest55431 is now known as _RA04:26
*** markvoelker has joined #openstack-keystone04:37
*** markvoelker has quit IRC04:41
*** markvoelker has joined #openstack-keystone05:10
*** GB21 has joined #openstack-keystone05:24
*** Nirupama has joined #openstack-keystone05:27
*** urulama has quit IRC06:00
*** urulama has joined #openstack-keystone06:00
*** oomichi has joined #openstack-keystone06:06
*** _RA has quit IRC06:17
*** oomichi has quit IRC06:30
openstackgerrithenry-nash proposed openstack/keystone: Add support for strict url safe option on new projects and domains  https://review.openstack.org/25737606:49
*** oomichi has joined #openstack-keystone06:53
*** gildub has quit IRC07:03
*** gildub_ has quit IRC07:03
*** wanghua has joined #openstack-keystone07:08
*** chlong has quit IRC07:13
*** markvoelker has quit IRC07:21
*** markvoelker has joined #openstack-keystone07:25
*** steveng has joined #openstack-keystone07:38
stevengHey keystoners.. I want to know whether it is possible to fetch users from different OU's in LDAP..07:38
*** GB21 has quit IRC08:07
*** steveng has quit IRC08:19
*** GB21 has joined #openstack-keystone08:26
*** steveng has joined #openstack-keystone08:29
stevengsrc/infra/ansible/roles/connet/files/usr/share/openstack-dashboard-ubuntu-theme/static/themes/ubuntu/ubuntu.png08:29
stevengHey keystoners.. I want to know whether it is possible to fetch users from different OU's in LDAP.08:30
*** chlong has joined #openstack-keystone08:31
*** roxanaghe has joined #openstack-keystone08:43
*** steveng has quit IRC08:46
*** steveng has joined #openstack-keystone08:47
*** pnavarro has joined #openstack-keystone08:51
*** daemontool has joined #openstack-keystone09:00
*** steveng has quit IRC09:10
*** mhickey has joined #openstack-keystone09:17
*** markvoelker has quit IRC09:25
*** openstack has joined #openstack-keystone15:35
*** openstackstatus has joined #openstack-keystone15:35
*** ChanServ sets mode: +v openstackstatus15:35
*** jsavak has quit IRC15:39
*** jsavak has joined #openstack-keystone15:40
bknudson_the keystone gate jobs should be fixed now... I'll try rechecking.15:43
*** jsavak has quit IRC15:45
*** sdake_ has joined #openstack-keystone15:53
*** dave-mccowan has quit IRC15:53
*** tonytan4ever has joined #openstack-keystone15:55
*** vgridnev has quit IRC15:56
openstackgerritNavid Pustchi proposed openstack/keystone: Forbid disabling the default domain  https://review.openstack.org/26006715:57
*** sdake has joined #openstack-keystone16:00
*** vgridnev has joined #openstack-keystone16:00
*** sdake_ has quit IRC16:02
*** vgridnev has quit IRC16:05
*** dave-mccowan has joined #openstack-keystone16:07
stevemar_zncbknudson_: thanks for fixing the gate16:12
bknudson_I'm the one who broke it.16:13
bknudson_in my previous job that would get you an award (fixing a critical problem you created)16:13
openstackgerritHaneef Ali proposed openstack/keystone: Fix 500 error when no fernet token is passed  https://review.openstack.org/25956316:18
*** nodir has joined #openstack-keystone16:20
*** pnavarro has quit IRC16:22
stevemar_zncbknudson_: can't fix a critical problem without creating one in the first place16:27
zaoPractice makes perfect.16:28
*** stevemar_znc is now known as stevemar16:28
nodirHello all16:31
nodirI'd like to ask for your advice16:31
nodirI want to use OpenLDAP as a backend for keystone16:32
nodirAnd apply password policy using OpenLDAP password policies16:32
stevemarnodir: you can have a variety of backends for users, one backend per "domain"16:33
nodirIn keystone configuration I indicated rootdn as a user16:33
nodirThe problem is the following: when a user is changing the password on dashboard, request to change the password is sent using rootdn credentials16:34
nodirOpenLDAP ignore password policy when the request comes from rootdn account16:35
nodirSo, password policy doesn't really get applied to keystone16:35
nodirMaybe somebody has faced this issue and knows what I might be doing wrong?16:35
*** gyee has joined #openstack-keystone16:37
*** ChanServ sets mode: +v gyee16:37
bknudson_typically when you do LDAP it's read-only. as in, you can't modify user passwords through keystone16:38
bknudson_you modify the user password by going to the LDAP directory directly16:38
bknudson_but if you want keystone to work differently open a bug and provide a fix.16:39
nodirYes, read-only - that's an option16:39
nodirBut I wanted to give the user an option to change the password, thanks for the advice bknudson_16:41
*** markvoelker has joined #openstack-keystone16:43
*** diazjf has joined #openstack-keystone16:43
notmorganstevemar: did you see my comment re bootstrap?16:43
stevemarnotmorgan: yes, late start today, just getting caught up, but it makes sense16:46
stevemarnotmorgan: i'll change my -1 back to +2, and change up my devstack patch16:46
*** diazjf1 has joined #openstack-keystone16:48
notmorganstevemar: long term we can improve the ux16:48
notmorganand eliminate the silly catalog is empty error16:48
*** markvoelker has quit IRC16:48
stevemarnotmorgan: agreed, that should be fixed.16:48
notmorganeven when specifying an end-point explicitly16:48
notmorganbut, that can come later16:48
*** diazjf has quit IRC16:50
*** vgridnev has joined #openstack-keystone16:50
*** rderose has joined #openstack-keystone17:00
*** pwp has joined #openstack-keystone17:08
*** woodster_ has quit IRC17:16
notmorganstevemar: uhmm.17:23
notmorganshould this be "Fixed Released"? https://bugs.launchpad.net/keystoneauth/+bug/150223217:23
openstackLaunchpad bug 1502232 in keystoneauth "Loads of unit test failures in Python 3.5: OrderedDict mutated during iteration" [High,Fix released] - Assigned to Corey Bryant (corey.bryant)17:23
*** roxanaghe has quit IRC17:26
*** rderose has quit IRC17:27
*** fawadkhaliq has quit IRC17:30
navidphi, how can i log keystone client17:31
navidpany help17:31
*** markvoelker has joined #openstack-keystone17:44
*** mhickey has quit IRC17:47
*** e0ne has quit IRC17:49
*** markvoelker has quit IRC17:49
*** ayoung has quit IRC17:51
*** gyee has quit IRC17:51
*** aix has quit IRC17:58
*** jsavak has joined #openstack-keystone18:03
*** jsavak has quit IRC18:07
*** jsavak has joined #openstack-keystone18:08
*** jsavak has quit IRC18:13
*** Guest95009 is now known as jgriffith18:15
*** mfedosin has quit IRC18:15
*** ayoung has joined #openstack-keystone18:18
*** ChanServ sets mode: +v ayoung18:18
*** urulama has quit IRC18:20
*** urulama has joined #openstack-keystone18:20
*** electrichead is now known as redrobot18:21
*** gyee has joined #openstack-keystone18:22
*** ChanServ sets mode: +v gyee18:22
*** tonytan4ever has quit IRC18:24
*** gyee has quit IRC18:25
openstackgerritMerged openstack/keystone: Fix use of TokenNotFound  https://review.openstack.org/22700418:25
openstackgerritMerged openstack/keystone: Enable os_inherit of Keystone v3 API  https://review.openstack.org/25758018:26
openstackgerritMerged openstack/keystone: Common arguments for fernet payloads assembly  https://review.openstack.org/23016518:27
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/25870318:28
*** woodster_ has joined #openstack-keystone18:30
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/25870318:32
openstackgerritBrant Knudson proposed openstack/keystone: Parameter to return audit ids only in revocation list  https://review.openstack.org/26015318:33
*** pwp has quit IRC18:34
*** e0ne has joined #openstack-keystone18:34
*** spotz_zzz is now known as spotz18:40
*** petertr7_away is now known as petertr718:51
*** gyee has joined #openstack-keystone18:53
*** ChanServ sets mode: +v gyee18:53
*** tonytan4ever has joined #openstack-keystone18:59
*** petertr7 is now known as petertr7_away19:02
*** tonytan4ever has quit IRC19:03
*** urulama has quit IRC19:06
*** urulama has joined #openstack-keystone19:07
*** agireud has joined #openstack-keystone19:09
openstackgerritBrant Knudson proposed openstack/keystone: Parameter to return audit ids only in revocation list  https://review.openstack.org/26015319:23
*** doug-fish has quit IRC19:29
*** pwp has joined #openstack-keystone19:33
openstackgerritBrant Knudson proposed openstack/keystone: Parameter to return audit ids only in revocation list  https://review.openstack.org/26015319:33
openstackgerritMorgan Fainberg proposed openstack/keystoneauth: Add betamax to test-requirements.txt  https://review.openstack.org/26018319:34
notmorganstevemar: ^ testing for ksa, but if it requires a major version increase i'm backing it out and doing a conditional import in the test19:36
*** diegows has quit IRC19:38
*** markvoelker has joined #openstack-keystone19:45
*** markvoelker has quit IRC19:50
*** diegows has joined #openstack-keystone19:50
*** diegows has quit IRC19:52
*** pwp has quit IRC19:53
*** maxabidi has joined #openstack-keystone20:00
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Get revocation list with only audit ids  https://review.openstack.org/26019620:00
openstackgerritHaneef Ali proposed openstack/keystone: Fix 500 error when no fernet token is passed  https://review.openstack.org/25956320:19
*** e0ne has quit IRC20:25
*** pwp has joined #openstack-keystone20:28
*** e0ne has joined #openstack-keystone20:29
*** e0ne has quit IRC20:34
*** maxabidi has quit IRC20:35
*** pwp has quit IRC20:36
*** pwp has joined #openstack-keystone20:38
*** e0ne has joined #openstack-keystone20:38
*** mfedosin has joined #openstack-keystone20:42
*** e0ne has quit IRC20:45
navidpbknudson_, about disabling default domain, what do you think I should change?20:46
bknudson_navidp: what administrative actions are evaluated against the default domain?20:48
bknudson_we shouldn't be evaluating any actions against the default domain.20:48
navidpby default domain, I mean the domain that is set in conf20:48
bknudson_I know what the default domain is20:49
bknudson_we shouldn't be treating it in a special way. it's just another domain20:49
bknudson_it just happens to be the domain that's used for v2 operations20:50
*** e0ne has joined #openstack-keystone20:50
bknudson_disabling the default domain should thus disable v2 operations, which is fine by me20:50
navidpbknudson_, i think and correct me if i am wrong, the admin from default domain is considered as cloud admin20:51
bknudson_there doesn't have to even be an admin user in the default domain.20:51
navidpif you disable the domain it resides it does not make any issues?20:51
bknudson_I can create an admin user in a non-default domain20:52
*** roxanaghe has joined #openstack-keystone20:52
bknudson_I imagine if you disable the domain that's got your only admin user in it that would cause problems, but the domain with your admin user in it might not be the default domain20:53
navidpIf you create a user in non-default domain then I think they dont have similar rights20:54
bknudson_that would be a bug.20:54
stevemarbknudson_: hey blku, what are your thoughts on this patch? https://review.openstack.org/#/c/259563/20:55
bknudson_stevemar: keystone should never return a 500 error20:56
stevemarbknudson_: agreed20:56
stevemarbknudson_: just thoughts on using tokenNotFound and then "" as the id20:56
navidpmaybe i make a mistake but can look at this https://github.com/openstack/keystone/blob/master/etc/policy.v3cloudsample.json#L320:56
stevemaroh it's updated now, yay20:56
stevemar"empty or none token is given"20:57
bknudson_navidp: that file is a sample. You don't need to use it.20:57
bknudson_navidp: you can use any domain for admin_domain_id , it doesn't have to be the default domain id20:57
bknudson_stevemar: exception handling in keystone is a mess20:58
navidpbknudson_, right now you can not delete fedault domain, dont you agree if you can not delete it then why do you want to be able to disable it>20:58
bknudson_navidp: I don't know why you can't delete the default domain. I can see a customer wanting to disable the default so I think they should be able to disable it.21:00
navidpthey can disable the default as long as they move it from being default, If i may ask why a customer want to disable their default domain, (i dont want to be rude just trying to make my case)21:01
*** pwp has quit IRC21:02
bknudson_why would a customer disable any domain? they want to stop people signing in so they can do some maintenance?21:02
navidpcorrect, then you are right.21:03
navidpbknudson_, if the policy.v3cloudsample.json is not used, then i dont think disabling the default domain creates any issues,21:05
navidpbknudson_, as long as you have admins which can enable it back again, but with this policy file..21:06
bknudson_it would be hard to tell in code if you have admins that can enable it back again?21:07
bknudson_you could configure your policy so that another user is the admin21:07
navidpyes you are right.21:08
bknudson_so maybe there's a problem here where a customer can cause problems for themselves but I'm not sure that just disabling the default domain fixes the problem.21:11
bknudson_should have said "disallow disabling the default domain"21:11
openstackgerritBrant Knudson proposed openstack/keystonemiddleware: Support audit_id-only revocation list  https://review.openstack.org/26022021:18
*** petertr7_away is now known as petertr721:19
*** marekd has joined #openstack-keystone21:23
*** ChanServ sets mode: +v marekd21:23
*** markvoelker has joined #openstack-keystone21:30
openstackgerritMerged openstack/keystone: Normalize fernet payload disassembly  https://review.openstack.org/23018121:31
notmorganjamielennox: ping21:32
notmorganjamielennox: need to ask you a question re plugin discovery21:32
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file  https://review.openstack.org/25870321:33
*** dims_ has quit IRC21:33
*** dims has joined #openstack-keystone21:33
openstackgerritBrant Knudson proposed openstack/keystone: Parameter to return audit ids only in revocation list  https://review.openstack.org/26015321:35
*** markvoelker has quit IRC21:36
*** mfedosin has quit IRC21:37
*** vgridnev has quit IRC21:42
*** dims has quit IRC21:43
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Get revocation list with only audit ids  https://review.openstack.org/26019621:45
openstackgerritBrant Knudson proposed openstack/keystonemiddleware: Support audit_id-only revocation list  https://review.openstack.org/26022021:46
openstackgerritBrant Knudson proposed openstack/keystonemiddleware: Support audit_id-only revocation list  https://review.openstack.org/26022021:47
openstackgerritBrant Knudson proposed openstack/keystonemiddleware: Support audit_id-only revocation list  https://review.openstack.org/26022021:47
*** dims has joined #openstack-keystone21:49
navidpbknudson_, thanks i will update it22:03
*** petertr7 is now known as petertr7_away22:05
openstackgerritBrant Knudson proposed openstack/keystone: De-duplicate fernet payload tests  https://review.openstack.org/23019322:07
*** dims_ has joined #openstack-keystone22:08
*** dims has quit IRC22:08
*** dims has joined #openstack-keystone22:12
*** dims_ has quit IRC22:13
*** simondodsley has joined #openstack-keystone22:15
*** sdake has quit IRC22:21
openstackgerritBrant Knudson proposed openstack/keystone: Cleanup tox.ini py34 tests  https://review.openstack.org/26023122:22
*** dims has quit IRC22:29
*** e0ne has quit IRC22:35
*** markvoelker has joined #openstack-keystone22:46
jamielennoxbknudson_: nice job on the oslo.config generator fix, i had played with fixing it on the ksa side and it makes way more sense there22:50
bknudson_jamielennox: based on the docs ksa was using it correctly22:50
bknudson_so the fix was just to stop warning for valid uses22:50
bknudson_... maybe the idea was that you were actually supposed to use the config opt classes.22:51
bknudson_not sure if you want to enhance ksa to use those22:51
*** markvoelker has quit IRC22:51
jamielennoxi think you are, but that would need us to have a dependency on oslo.config22:51
jamielennoxwhich is why we got away from using those types in the first place22:52
bknudson_well, unless you didn't define the symbols unless oslo.config was available22:52
bknudson_or switched somehow. It would be ugly. And I'm not sure how much better the result is22:52
jamielennoxthe options are needed for CLI and other methods that config22:52
jamielennoxso it gets funky22:53
jamielennoxanyway, because we are using the python types str(opt.type) should be pretty good and if not we can enhance oslo.config to recognize a few of those22:54
bknudson_y, that would be another enhancement22:54
bknudson_I'll admit I didn't look to see what the output is in either case22:54
jamielennoxstevemar: doing a meeting tomorrow?22:58
bknudson_ldap3 is not even close to python-ldap23:04
*** woodster_ has quit IRC23:06
*** roxanaghe has quit IRC23:13
*** dims has joined #openstack-keystone23:21
*** dims has quit IRC23:30
*** spotz is now known as spotz_zzz23:31
*** dims has joined #openstack-keystone23:32
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/26025223:41
openstackgerritOpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements  https://review.openstack.org/26025323:41
*** gordc has quit IRC23:42
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/26026523:45
*** sdake has joined #openstack-keystone23:45
*** gildub has joined #openstack-keystone23:54

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!