Wednesday, 2016-09-28

*** guoshan has quit IRC00:02
*** roxanaghe has quit IRC00:02
*** spzala_ has quit IRC00:04
*** lujinluo has joined #openstack-keystone00:04
*** agrebennikov has quit IRC00:08
*** nicolasbock has quit IRC00:09
*** edmondsw has quit IRC00:11
*** ddieterly has quit IRC00:13
*** aloga has quit IRC00:15
*** guoshan has joined #openstack-keystone00:16
*** markvoelker has joined #openstack-keystone00:20
*** aloga has joined #openstack-keystone00:23
*** markvoelker has quit IRC00:25
*** adrian_otto has quit IRC00:30
*** tqtran has quit IRC00:31
*** ravelar1 has joined #openstack-keystone00:32
*** markvoelker has joined #openstack-keystone00:34
*** adrian_otto has joined #openstack-keystone00:42
*** gyee has quit IRC00:43
*** ddieterly has joined #openstack-keystone00:46
*** adrian_otto has quit IRC00:46
*** adrian_otto has joined #openstack-keystone00:47
*** topol__ is now known as topol00:55
*** ChanServ sets mode: +v topol00:55
*** guoshan has quit IRC01:00
*** ddieterly has quit IRC01:01
*** adrian_otto1 has joined #openstack-keystone01:06
*** adrian_otto has quit IRC01:08
*** rvba` has quit IRC01:10
*** rvba has joined #openstack-keystone01:12
*** rvba has quit IRC01:12
*** rvba has joined #openstack-keystone01:12
*** davechen has joined #openstack-keystone01:12
*** asettle has joined #openstack-keystone01:14
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652301:17
*** asettle has quit IRC01:19
*** guoshan has joined #openstack-keystone01:20
*** ngupta has joined #openstack-keystone01:26
*** lamt has joined #openstack-keystone01:27
*** guoshan has quit IRC01:29
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652301:29
*** lamt has quit IRC01:31
openstackgerritRon De Rose proposed openstack/keystone: WIP - Validate project exists and enabled directly  https://review.openstack.org/37804701:32
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652301:32
*** EinstCrazy has joined #openstack-keystone01:35
*** haplo37_ has quit IRC01:38
*** tonytan4ever has joined #openstack-keystone01:46
*** ddieterly has joined #openstack-keystone01:49
*** tonytan4ever has quit IRC01:50
*** browne has quit IRC01:51
*** ddieterly has quit IRC01:52
openstackgerritQiming Teng proposed openstack/keystone: Reorder APIs in api-ref doc for v3 users  https://review.openstack.org/37366001:56
openstackgerritRon De Rose proposed openstack/keystone: Add revocation project event table  https://review.openstack.org/37814201:57
openstackgerritRon De Rose proposed openstack/keystone: Add revocation project event table  https://review.openstack.org/37814201:58
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652302:02
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652302:04
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652302:09
*** ddieterly has joined #openstack-keystone02:21
*** ddieterly has quit IRC02:25
*** adrian_otto1 has quit IRC02:25
openstackgerritSteve Martinelli proposed openstack/keystone: Tweak api-ref for v3 groups status codes  https://review.openstack.org/36779302:26
openstackgerritRon De Rose proposed openstack/keystone: Add revocation project event table  https://review.openstack.org/37814202:28
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652302:29
openstackgerritRon De Rose proposed openstack/keystone: Move revocation logic to SQL  https://review.openstack.org/35937102:31
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652302:40
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652302:41
*** browne has joined #openstack-keystone02:42
*** ngupta has quit IRC02:52
*** ngupta has joined #openstack-keystone02:52
*** gagehugo has quit IRC02:53
*** browne has quit IRC02:53
*** david-lyle has quit IRC03:04
*** spzala has joined #openstack-keystone03:05
*** spzala has quit IRC03:05
*** adrian_otto has joined #openstack-keystone03:13
*** sdake_ has quit IRC03:17
*** iurygregory_ has quit IRC03:18
*** aswadr_ has joined #openstack-keystone03:21
*** adrian_otto has quit IRC03:26
*** adrian_otto has joined #openstack-keystone03:26
*** tqtran has joined #openstack-keystone03:30
*** tqtran has quit IRC03:36
*** ravelar1 has quit IRC03:37
*** roxanaghe has joined #openstack-keystone03:38
*** sdake has joined #openstack-keystone03:39
*** namnh has joined #openstack-keystone03:41
*** ngupta has quit IRC03:46
*** ngupta has joined #openstack-keystone03:47
openstackgerritRon De Rose proposed openstack/keystone: Move revocation logic to SQL  https://review.openstack.org/35937103:49
*** sdake_ has joined #openstack-keystone03:50
*** ngupta has quit IRC03:51
*** sdake has quit IRC03:51
*** roxanaghe has quit IRC03:52
*** adrian_otto has quit IRC03:53
openstackgerritNam Nguyen Hoai proposed openstack/keystone: Fix typo in docstring  https://review.openstack.org/37821803:58
*** roxanaghe has joined #openstack-keystone03:59
*** dikonoo has joined #openstack-keystone04:00
*** roxanaghe has quit IRC04:23
openstackgerritRon De Rose proposed openstack/keystone: Add revocation event indexes  https://review.openstack.org/37652304:23
openstackgerritRon De Rose proposed openstack/keystone: Move revocation logic to SQL  https://review.openstack.org/35937104:24
openstackgerritRon De Rose proposed openstack/keystone: Add revocation project event table  https://review.openstack.org/37814204:26
*** haplo37- has quit IRC05:00
*** vaishali has joined #openstack-keystone05:02
*** haplo37_ has joined #openstack-keystone05:02
*** links has joined #openstack-keystone05:09
*** links has quit IRC05:15
*** links has joined #openstack-keystone05:17
*** woodster_ has quit IRC05:30
*** sdake_ has quit IRC05:30
*** richm has quit IRC05:40
*** jaosorior has joined #openstack-keystone05:46
openstackgerritDave Chen proposed openstack/keystone: Deprecate `endpoint_filter.sql` backend  https://review.openstack.org/37593106:13
*** rcernin has joined #openstack-keystone06:14
openstackgerritNam Nguyen Hoai proposed openstack/keystone: Fix typo in docstring  https://review.openstack.org/37821806:26
*** crinkle_ is now known as crinkle06:33
*** pcaruana has joined #openstack-keystone06:37
*** mrsoul has quit IRC06:47
*** mrsoul has joined #openstack-keystone06:48
*** jrist has joined #openstack-keystone06:54
*** jrist has quit IRC07:04
*** amoralej|off is now known as amoralej07:04
*** links has quit IRC07:16
*** links has joined #openstack-keystone07:45
*** ktychkova has joined #openstack-keystone07:47
openstackgerritzhangyanxian proposed openstack/python-keystoneclient: Fix typos inconsistent with the guide lines  https://review.openstack.org/37831907:50
openstackgerritzhangyanxian proposed openstack/python-keystoneclient: Fix docstrings inconsistent with the guide lines  https://review.openstack.org/37831907:53
openstackgerritzhangyanxian proposed openstack/python-keystoneclient: Fix docstrings inconsistent with the guide lines  https://review.openstack.org/37831907:54
*** zzzeek has quit IRC08:00
*** zzzeek has joined #openstack-keystone08:01
*** sc68cal_ has joined #openstack-keystone08:02
*** sc68cal has quit IRC08:03
openstackgerritDave Chen proposed openstack/keystone: Deprecate `endpoint_filter.sql` backend  https://review.openstack.org/37593108:08
*** links has quit IRC08:21
*** pnavarro has joined #openstack-keystone08:28
*** code-R has joined #openstack-keystone08:29
*** code-R_ has joined #openstack-keystone08:31
*** code-R has quit IRC08:33
*** tqtran has joined #openstack-keystone08:34
*** code-R_ has quit IRC08:36
*** links has joined #openstack-keystone08:37
*** tqtran has quit IRC08:38
*** sdake has joined #openstack-keystone08:41
*** sdake has quit IRC08:42
*** jed56 has joined #openstack-keystone08:45
*** openstackgerrit has quit IRC08:48
*** openstackgerrit has joined #openstack-keystone08:48
*** jamielennox is now known as jamielennox|away08:59
*** jorge_munoz has joined #openstack-keystone09:00
*** dmellado_ is now known as dmellado09:18
*** code-R has joined #openstack-keystone09:38
*** amoralej is now known as amoralej|out09:40
openstackgerritStephen Finucane proposed openstack/oslo.policy: Add sphinx extension to build sample policy  https://review.openstack.org/37654409:40
*** aswadr_ has quit IRC09:42
*** haplo37_ has quit IRC09:44
*** haplo37_ has joined #openstack-keystone09:47
*** code-R_ has joined #openstack-keystone09:49
*** code-R has quit IRC09:52
openstackgerritStephen Finucane proposed openstack/oslo.policy: doc: Add introduction to index page  https://review.openstack.org/37849009:57
openstackgerritStephen Finucane proposed openstack/oslo.policy: Add sphinx extension to build sample policy  https://review.openstack.org/37654409:59
openstackgerritBoris Bobrov proposed openstack/keystone: Remove support for PKI and PKIz tokens  https://review.openstack.org/37447910:07
*** EinstCrazy has quit IRC10:08
*** EinstCrazy has joined #openstack-keystone10:08
*** richm has joined #openstack-keystone10:10
*** lujinluo has quit IRC10:13
*** EinstCrazy has quit IRC10:13
*** davechen has left #openstack-keystone10:20
*** nicolasbock has joined #openstack-keystone10:38
*** links has quit IRC10:53
*** links has joined #openstack-keystone11:02
*** asettle has joined #openstack-keystone11:17
*** namnh has quit IRC11:31
openstackgerritMerged openstack/keystone: Reorder APIs in api-ref doc for v3 users  https://review.openstack.org/37366011:32
*** pnavarro has quit IRC11:46
*** jrist has joined #openstack-keystone11:49
*** markvoelker has quit IRC11:53
*** sdake has joined #openstack-keystone12:02
*** haplo37_ has quit IRC12:05
*** haplo37_ has joined #openstack-keystone12:07
*** edmondsw has joined #openstack-keystone12:09
samueldmqmorning keystone12:23
*** jamielennox|away is now known as jamielennox12:29
openstackgerritDave Chen proposed openstack/keystone: Remove the check for admin token in build_auth_context middleware  https://review.openstack.org/37858812:40
*** amoralej|out is now known as amoralej12:46
*** rodrigods has quit IRC12:47
*** rodrigods has joined #openstack-keystone12:47
*** pnavarro has joined #openstack-keystone12:52
openstackgerritDave Chen proposed openstack/keystone: Remove the check for admin token in build_auth_context middleware  https://review.openstack.org/37858812:54
*** markvoelker has joined #openstack-keystone12:55
*** vaishali has quit IRC12:56
*** david-lyle has joined #openstack-keystone12:57
stevemaro/13:03
openstackgerritQiming Teng proposed openstack/keystone: Tweak api-ref for v3 groups status codes  https://review.openstack.org/36779313:05
*** woodster_ has joined #openstack-keystone13:13
openstackgerritQiming Teng proposed openstack/keystone: Tweak api-ref for v3 groups status codes  https://review.openstack.org/36779313:16
*** aswadr_ has joined #openstack-keystone13:18
*** jaosorior has quit IRC13:20
*** jaosorior has joined #openstack-keystone13:21
*** agrebennikov has joined #openstack-keystone13:36
*** links has quit IRC13:38
*** tonytan4ever has joined #openstack-keystone13:40
*** roxanaghe has joined #openstack-keystone13:43
*** roxanaghe has quit IRC13:45
*** ngupta has joined #openstack-keystone13:45
*** ngupta has quit IRC13:45
*** ngupta has joined #openstack-keystone13:45
*** vkramskikh has joined #openstack-keystone13:47
*** asettle has quit IRC13:48
openstackgerritRon De Rose proposed openstack/keystone: Remove deprecated code from core  https://review.openstack.org/37863713:52
*** ddieterly has joined #openstack-keystone13:52
openstackgerritRon De Rose proposed openstack/keystone: Remove deprecated code from core  https://review.openstack.org/37863713:52
openstackgerritLance Bragstad proposed openstack/keystone: Ensure all v2.0 tokens are validated the same way  https://review.openstack.org/37265513:55
*** woodburn has quit IRC13:57
*** woodburn has joined #openstack-keystone13:59
*** gagehugo has joined #openstack-keystone14:01
dstanekmorning stevemar14:03
*** gagehugo has quit IRC14:06
*** adrian_otto has joined #openstack-keystone14:09
*** haplo37_ has quit IRC14:10
openstackgerritMerged openstack/keystonemiddleware: Use method constant_time_compare from oslo.utils  https://review.openstack.org/37623514:10
*** gsilvis has quit IRC14:11
*** haplo37_ has joined #openstack-keystone14:13
*** gagehugo has joined #openstack-keystone14:13
*** pnavarro has quit IRC14:14
*** chris_hultin|AWA is now known as chris_hultin14:18
stevemardstanek: you coming to barcelona right?14:21
*** raildo has joined #openstack-keystone14:21
*** marekd2 has joined #openstack-keystone14:22
stevemarrderose: i put up https://review.openstack.org/#/c/375928/ earlier14:25
stevemarrderose: as an FYI, since you just put up https://review.openstack.org/#/c/378637/2 :)14:25
*** gsilvis has joined #openstack-keystone14:28
dstanekstevemar: sadly i am not14:35
dstanek...errr. sadly may not be the correct word :-)14:35
*** ravelar has joined #openstack-keystone14:35
rderosestevemar: ah, you beat me to it14:36
rderosestevemar: cool, I'll abandon mine14:37
dstanekstevemar: that's actually the main reason i didn't run for PTL again this cycle14:37
*** AlexeyAbashkin has joined #openstack-keystone14:38
*** spzala has joined #openstack-keystone14:38
*** dikonoo has quit IRC14:39
*** jorge_munoz_ has joined #openstack-keystone14:39
*** jorge_munoz has quit IRC14:41
*** jorge_munoz_ is now known as jorge_munoz14:41
*** mah has left #openstack-keystone14:42
openstackgerritRon De Rose proposed openstack/keystone: Remove deprecated code from core  https://review.openstack.org/37863714:44
openstackgerritRon De Rose proposed openstack/keystone: Remove deprecated auth core  https://review.openstack.org/37863714:45
*** adrian_otto has quit IRC14:50
openstackgerritLance Bragstad proposed openstack/keystone: Make test_v3_auth exercise the whole API  https://review.openstack.org/37868114:55
*** ddieterly has quit IRC14:56
*** ddieterly has joined #openstack-keystone14:56
*** Guest78091 is now known as redrobot14:59
*** adrian_otto has joined #openstack-keystone15:01
rodrigodsrderose, so... for the password uniqueness requirement, if it is set to 2, and i try to update using the current password, should it work?15:01
rderoserodrigods: it you try to change it to the current password, then no, it should fail15:04
*** rcernin has quit IRC15:04
rderoserodrigods: https://github.com/openstack/keystone/blob/master/keystone/tests/unit/identity/test_backend_sql.py#L16815:06
stevemarrderose: i left a few questions in the review :\15:06
*** tonytan_brb has joined #openstack-keystone15:06
openstackgerritSteve Martinelli proposed openstack/keystone: remove stable driver interfaces  https://review.openstack.org/37592815:07
rderosestevemar: which patch?15:07
stevemarrderose: ^ the stable driver one, check the n-1 patch set15:08
*** ayoung_ has joined #openstack-keystone15:09
*** tonytan4ever has quit IRC15:09
*** ayoung_ is now known as ayoung15:11
stevemargoing to update to sierra15:11
stevemar!!15:11
openstackstevemar: Error: "!" is not a valid command.15:11
*** ashyoung has joined #openstack-keystone15:12
rderosestevemar: responded to your comments15:14
rderosestevemar: if you are removing the other versions (v8, v9), then the base version should contain all of the method signatures15:15
rodrigodsrderose, hmm i have a test where i don't change to a new one, it try to change using the current one15:19
rodrigodsand it updates15:19
rodrigodsjust don't know if should be the expected behavior, or not15:19
rodrigodsrderose, see line 88: https://review.openstack.org/#/c/378624/1/tempest/scenario/test_security_compliance.py15:20
*** dikonoo has joined #openstack-keystone15:22
*** xek__ has joined #openstack-keystone15:23
rderoserodrigods: where is CONF.identity.user_unique_last_passwords_count getting set?15:23
rderoseand are you sure it's greater than 1 when it hits this test?15:23
*** xek_ has quit IRC15:25
*** nk2527 has quit IRC15:55
stevemarrderose: cool, i'll update15:58
stevemarrderose: or you can, if you're feeling eager :P15:58
stevemaryay upgrading to sierra didn't blow things up15:59
knikollamac upgrades are boring15:59
stevemarconsidering i was at n-2, i was a bit worried :P15:59
stevemarknikolla: not like openstack upgrades :P15:59
*** tonytan_brb is now known as tonytan4ever15:59
rderose:)16:00
knikollastill better than android phones16:00
rderosestevemar: yeah, I'll update it16:01
*** lamt has joined #openstack-keystone16:03
*** ashyoung has quit IRC16:03
*** gyee has joined #openstack-keystone16:07
stevemarrderose: coolio16:08
*** browne has joined #openstack-keystone16:11
rodrigodsrderose, yes, it is set in tempest.conf (same value as in keystone.conf) and the call is made16:11
*** roxanaghe has joined #openstack-keystone16:11
rodrigodsand succeeds16:12
rodrigodslet me try to modify the test you sent so i can confirm the behavior16:12
rderoseokay16:12
*** nk2527 has joined #openstack-keystone16:14
*** ddieterly is now known as ddieterly[away]16:18
*** jamielennox is now known as jamielennox|away16:21
*** Guest46101 is now known as mgagne16:21
*** mgagne has quit IRC16:21
*** mgagne has joined #openstack-keystone16:21
*** ddieterly[away] is now known as ddieterly16:22
*** jaosorior has quit IRC16:27
*** jrist has quit IRC16:28
*** haplo37_ has quit IRC16:29
*** haplo37_ has joined #openstack-keystone16:31
lbragstadstevemar dstanek question for you16:35
*** ravelar has quit IRC16:37
*** frontrunner has quit IRC16:41
lbragstadstevemar dstanek we seem to have test_v2.py and test_auth.py - the tests in test_v2.py seem to be restful and the tests in test_auth.py call directly into specific provider methods16:42
lbragstadthey both do a bunch of testing against the v2.0 token API16:42
lbragstaddo we want to consolidate them into a single module?16:43
lbragstadI'd like to remove as much of the self.token_provider_api calls from the tests as I can16:43
*** code-R_ has quit IRC16:45
*** richm has quit IRC16:50
*** adrian_otto has quit IRC16:54
lbragstadlunch!16:55
*** code-R has joined #openstack-keystone16:56
*** adrian_otto has joined #openstack-keystone16:59
openstackgerritOpenStack Proposal Bot proposed openstack/pycadf: Updated from global requirements  https://review.openstack.org/37888017:00
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/37888717:00
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient-kerberos: Updated from global requirements  https://review.openstack.org/37368617:00
*** richm has joined #openstack-keystone17:01
openstackgerritRon De Rose proposed openstack/keystone: remove stable driver interfaces  https://review.openstack.org/37592817:04
*** slberger has joined #openstack-keystone17:08
*** ddieterly is now known as ddieterly[away]17:15
*** slberger has quit IRC17:18
openstackgerritRon De Rose proposed openstack/keystone: Remove stable driver interfaces  https://review.openstack.org/37592817:18
rderosestevemar: done ^17:20
rderosetoo much work to break it up, but fixed the abstract base class problems17:25
*** sc68cal_ is now known as sc68cal17:27
*** aswadr_ has quit IRC17:42
dstaneklbragstad: i wouldn't - i'd leave REST in one module and the other tests in another17:43
dstanekmaybe a rename would make it clearer though17:43
dstanektest_v2.py is actually v2 API testing right? not v2 tokens17:44
*** dikonoo has quit IRC17:45
stevemarlbragstad: i agree with dstanek, it's not uncommon for us to test the REST call as a whole, and the provider / backend17:49
bknudsonyes, let's have "functional" tests going through the API and component tests for each of the components17:50
*** gagehugo has quit IRC17:50
bknudsonthat will make it easier to maintain the tests since hopefully the reason for failure will be more obvious since they're testing less code17:50
*** marekd2 has quit IRC17:50
*** marekd2 has joined #openstack-keystone17:51
stevemarayoung: jamielennox|away is it time to retire python-keystoneclient-kerberos? are you satisfied with the move to keystoneauth now?17:53
*** adrian_otto has quit IRC17:54
*** adrian_otto has joined #openstack-keystone17:55
*** marekd2 has quit IRC17:55
openstackgerritAndrew Laski proposed openstack/oslo.policy: Update docs on policy sample generator  https://review.openstack.org/37423217:55
*** adrian_otto has quit IRC17:55
ayoungstevemar, kill it when we end support for the last version of Keystone that still requires it17:56
ayoungI think that is Mitaka?17:56
lbragstadstevemar dstanek makes sense17:58
*** adrian_otto has joined #openstack-keystone17:59
lbragstaddstanek stevemar so we will leave test_v2.py as the API tests18:00
lbragstaddstanek stevemar and leave test_auth.py as the provider tests18:00
lbragstaddstanek stevemar I would love to rename these...18:01
stevemarlbragstad: rename them then18:01
lbragstadstevemar cool18:01
bknudsonprovider tests should be in http://git.openstack.org/cgit/openstack/keystone/tree/keystone/tests/unit/token/test_provider.py18:01
lbragstadwhat about v2 provider tests versus v3 provider tests?18:01
lbragstadshould they all be in test_provider.py?18:02
*** asettle has joined #openstack-keystone18:02
bknudsonthere's no separate code files for v2 providers vs v3 providers so they should be in the same unit test file18:02
openstackgerritMerged openstack/ldappool: Updated from global requirements  https://review.openstack.org/37883518:02
stevemarayoung: no version of keystone required it... let me see18:04
ayoungstevemar, let me rephrase18:04
*** gagehugo has joined #openstack-keystone18:04
ayoungsupport it as long as there are versions of nova, etc shipped with versions of kc code that requires it18:04
stevemarayoung: i think only horizon had support for it, specifically doa-kerb18:06
stevemarayoung: and that project looks unmaintained18:07
stevemarayoung: and no one updated django_openstack_auth to use keystoneauth18:07
ayoungstevemar, Nah, you have to assume that nova calling keystone and using it, or some other path.  But it can got with Mitaka, I think18:07
*** asettle__ has joined #openstack-keystone18:09
*** asettle has quit IRC18:10
*** ddieterly[away] is now known as ddieterly18:12
*** tqtran has joined #openstack-keystone18:14
*** chris_hultin is now known as chris_hultin|AWA18:14
*** amoralej is now known as amoralej|off18:15
*** chris_hultin|AWA is now known as chris_hultin18:18
*** tqtran has quit IRC18:18
stevemarhenrynash: if you would be so kind to review https://review.openstack.org/#/c/375928/718:20
stevemarayoung: i will send a note18:20
stevemarayoung: i want to retire both doa-kerb and ksc-kerb, or at least have a plan for that18:21
stevemarksc-kerb has been integrated into ksa18:21
stevemardoa uses keystoneauth18:21
stevemarbut i don't know if it knows how to load kerberos specific bits18:21
stevemarat which point, we should properly deprecate doa-kerb, as it's not18:22
*** asettle has joined #openstack-keystone18:22
stevemarthen remove both repos18:22
*** asettle__ has quit IRC18:25
*** spilla has joined #openstack-keystone18:26
ayoungstevemar, yes, doakerb should probably go away.  Anyone doing Kerb should probably go with a Federation based solution18:28
ayoungEspecially for Horizon18:28
*** ddieterly is now known as ddieterly[away]18:33
stevemarayoung: i lack the history on why doakerb was created in the first place18:34
ayoungstevemar, http://adam.younglogic.com/2014/05/keystoneclient-s4u2proxy/18:35
ayoungI have all the history18:35
*** ravelar has joined #openstack-keystone18:35
ayounghttp://adam.younglogic.com/2014/05/s4u2proxy-horizon/  is alittle bit more on the history18:36
*** woodster_ has quit IRC18:40
*** chris_hultin is now known as chris_hultin|AWA18:43
*** sdake has quit IRC18:46
*** asettle__ has joined #openstack-keystone18:49
*** slberger has joined #openstack-keystone18:49
*** asettle has quit IRC18:50
*** slberger has quit IRC19:01
*** hogepodge has quit IRC19:01
*** spzala has quit IRC19:01
*** tqtran has joined #openstack-keystone19:06
rodrigodsrderose, around?19:11
*** spilla has quit IRC19:13
*** hoonetorg has quit IRC19:14
*** ddieterly[away] is now known as ddieterly19:14
openstackgerritMerged openstack/keystoneauth: Updated from global requirements  https://review.openstack.org/37882719:14
*** gyee has quit IRC19:16
rodrigodsrderose, can you try to reproduce this http://paste.openstack.org/show/583366/ ?19:16
*** slberger has joined #openstack-keystone19:18
*** tqtran has quit IRC19:26
*** nk2527 has quit IRC19:26
*** xenogear has quit IRC19:26
*** tqtran has joined #openstack-keystone19:31
*** nk2527 has joined #openstack-keystone19:31
*** hoonetorg has joined #openstack-keystone19:31
openstackgerritRodrigo Duarte proposed openstack/keystone: Improve password change req tests  https://review.openstack.org/37893319:31
*** xenogear has joined #openstack-keystone19:32
*** sdake has joined #openstack-keystone19:34
openstackgerritMerged openstack/pycadf: Updated from global requirements  https://review.openstack.org/37888019:48
openstackgerritMerged openstack/keystone: Updated from global requirements  https://review.openstack.org/37882519:54
*** code-R has quit IRC19:59
*** spzala has joined #openstack-keystone20:01
stevemarrderose: about the stable patch, why don't those methods need to go into base?20:01
*** chris_hultin|AWA is now known as chris_hultin20:04
*** spzala has quit IRC20:07
*** ddieterly is now known as ddieterly[away]20:09
rderosestevemar: responded to your comments, none of the v8 methods need to come over20:10
rderoseshould be good20:10
*** asettle__ has quit IRC20:15
*** ddieterly[away] is now known as ddieterly20:17
stevemarrderose: i see the comment, but why don't they need to come over :)20:18
rderosestevemar: they were either replaced or removed in v920:21
rderoseboth v8 and v9 inherit from the base class20:22
rderoseor did anyway20:22
*** roxanaghe has quit IRC20:22
*** tonytan4ever has quit IRC20:23
rderosestevemar: and the sql.py backend implemented v920:23
openstackgerritLance Bragstad proposed openstack/keystone: Make test_v3_auth exercise the whole API  https://review.openstack.org/37868120:23
rderosestevemar: so v8 was only there to support driver versioning20:24
*** ddieterly is now known as ddieterly[away]20:34
*** ddieterly[away] is now known as ddieterly20:34
*** jorge_munoz has quit IRC20:34
openstackgerritMerged openstack/python-keystoneclient: Updated from global requirements  https://review.openstack.org/37888720:34
*** jorge_munoz has joined #openstack-keystone20:35
openstackgerritMerged openstack/oslo.policy: Updated from global requirements  https://review.openstack.org/37887520:37
*** adrian_otto has quit IRC20:37
*** ddieterly is now known as ddieterly[away]20:43
*** jamielennox|away is now known as jamielennox20:45
*** slberger has quit IRC20:48
*** spzala has joined #openstack-keystone20:49
*** spzala has quit IRC20:53
*** jlopezgu has left #openstack-keystone20:57
*** ngupta has quit IRC20:57
*** tqtran_ has joined #openstack-keystone20:57
*** ngupta has joined #openstack-keystone20:57
*** slberger has joined #openstack-keystone20:58
*** raildo has quit IRC20:58
*** tqtran has quit IRC20:59
*** tqtran_ has quit IRC21:04
*** spzala has joined #openstack-keystone21:04
*** ngupta has quit IRC21:04
*** ngupta has joined #openstack-keystone21:04
openstackgerritayoung proposed openstack/keystone-specs: Fetch Policy by Tag  https://review.openstack.org/29878821:05
ayoungOK...I should have thought of ^^ years ago21:05
*** ddieterly[away] is now known as ddieterly21:06
*** tqtran has joined #openstack-keystone21:06
*** ravelar has quit IRC21:09
*** slberger has quit IRC21:12
rodrigodsstevemar, rderose https://bugs.launchpad.net/keystone/+bug/162869221:14
openstackLaunchpad bug 1628692 in OpenStack Identity (keystone) "Password history constraints not enforced via /v3/users/<user_id>/password path" [Undecided,New]21:14
rderoserodrigods: just so I'm understanding...21:17
rderoserodrigods: you created a user with 12345 password and then changed it to qwerty, correct?21:18
rodrigodsrderose, right21:18
rodrigodsand them back to 1234521:18
rodrigodsthen*21:18
rderoserodrigods: that should be okay21:18
rderosehmm...21:19
rodrigodsrderose, the "change_password" backend method doesn't call the _validate_password_history()21:19
rderoserodrigods: ahhhhhhhhhhhhhhhhhhhhh21:21
rderoserodrigods: darn, my bad21:21
rodrigodsrderose, i wonder why we don't have a common method to change password21:21
rderoserodrigods: yeah, nice catch21:22
rderoseI added change_password to the backend; missed this21:22
*** roxanaghe has joined #openstack-keystone21:22
rderosewhile they both change passwords (change_password, update_user), they have different business logic21:22
rderoserodrigods: change_password is intended to be self-service21:23
rderosewhereas update_user is admin reset21:23
rderosebut yeah, need a common method here21:23
rodrigodsrderose, ++21:23
rderoserodrigods: anyway, nice catch21:23
*** tonytan4ever has joined #openstack-keystone21:23
*** edmondsw has quit IRC21:25
rodrigodsrderose, would be nice to start requiring functional/integration tests for new features21:25
rodrigodsmaybe it is something for us to bring in barcelona since ocata won't be a "feature heavy" cycle21:25
*** slberger has joined #openstack-keystone21:26
*** tonytan4ever has quit IRC21:28
*** hogepodge has joined #openstack-keystone21:28
*** chris_hultin is now known as chris_hultin|AWA21:31
rderoserodrigods: yeah21:32
*** slberger has left #openstack-keystone21:36
*** ngupta_ has joined #openstack-keystone21:37
*** ngupta has quit IRC21:40
*** ngupta_ has quit IRC21:42
lbragstadinteresting - apparently our token provider api has a revoke_token() method, which accepts a revoke_chain kwarg - but it doesn't look like we use it in either the v2.0 or v3 token controllers21:43
*** spzala has quit IRC21:44
openstackgerritRon De Rose proposed openstack/keystone: Validate password history for self service password changes  https://review.openstack.org/37901821:59
openstackgerritRon De Rose proposed openstack/keystone: Validate password history for self-service password changes  https://review.openstack.org/37901822:00
*** lamt has quit IRC22:09
*** tqtran has quit IRC22:09
*** tqtran has joined #openstack-keystone22:11
*** tonytan4ever has joined #openstack-keystone22:23
openstackgerritRon De Rose proposed openstack/keystone: Validate password history for self-service password changes  https://review.openstack.org/37901822:24
*** agrebennikov has quit IRC22:26
*** markvoelker has quit IRC22:36
morganlbragstad: we didn't implement it because of issues with long running tasks22:50
morganlbragstad: it was added more for future proofing and/or internal chain revokes22:50
*** tonytan4ever has quit IRC22:51
morganlbragstad: at one point we did use it internally but i can't remember when22:51
morganrderose: to be honest, admin set of password should be exempt from password restrictions22:52
morganrderose: most cases if an admin is setting the password, you don't validate history etc.22:52
morganrderose: so I'd say it shouldn't have a common password set method that does all the same business logic22:52
rderosemorgan: hmm... good point22:52
morganin fact, i am near certain we discussed this22:53
morganand why it isn't checking history there ;)22:53
rderosemorgan: it is checking password history for admin reset; wasn't checking for self-service22:53
morganwe should invert that22:53
rderosemorgan: I'll throw up a patch to do that22:54
rderosemorgan: makes sense22:54
morgan++22:54
jamielennoxstevemar, dolphm, ayoung: for fetching an expired token we said that we would want to only do it when a X-Service-Token was also specified22:54
morganyeah admin reset is a special case. it does mean admins can set their own passwords to whatever --- ignoring the rules. but that is a people problem not a tech problem22:54
jamielennoxdoes this (X-Service-Token) seem like something we would actually want to enforce at the keystone level22:55
jamielennoxor is it sufficient to pass a ?expired=True flag to keystone and enforce the service token in middleware?22:55
morganjamielennox:  i'd say it's fine for anyone who is allowed to validate a token to ask for expiry exception22:55
jamielennoxi'm not sure i see a problem with people asking for an expired token if they flag it22:55
rderosemorgan: yeah22:56
openstackgerritRodrigo Duarte proposed openstack/keystone: Improve password history constraint tests  https://review.openstack.org/37893322:56
*** sdake has quit IRC22:56
jamielennoxmorgan: yea, so long as we don't break compat i'm not sure i see any security issues to this22:56
morganjamielennox: if someone wants to restrict it, let them restrict validation to x-service-token. but there is no reason you cannot validate a token that is expired22:56
morganjamielennox: exactly22:56
morganjamielennox: just make sure it's documented clearly22:56
jamielennoxmorgan: well it's a matter of whether we send x-service-token from auth_token -> keystone22:56
morganjamielennox: don't add the restriction in keystone22:57
morganlet it be a policy thing and let KSM send x-service-token (iirc we can do that today)22:57
morganbut it shouldn't be a hard requirment to have x-service-token22:57
jamielennoxso auth_token will validate the service token, and we can say that you only add the ?expired flag if the service token is valid22:58
jamielennoxthat has to be in place at the auth_token level22:58
jamielennoxbut we don't submit the X-Service-token to keystone when validating the X-Subject-Token22:58
morganwe probably should make it so KSM can always submit an x-service-token22:59
morganbut we should not require it for expired tokens22:59
*** ddieterly has quit IRC22:59
jamielennoxmorgan: we might be talking cross purposes22:59
morganjamielennox: nope.22:59
jamielennoxif you submit an x-service-token to auth_token middleware it will validate it22:59
morganjamielennox: right now, don't require it22:59
morganjust don't require for expired tokens22:59
morganat all22:59
jamielennoxhowever it does that as a normal token vlaidation22:59
morganlook at options if we need to lock it down in the future23:00
jamielennoxit does not send the X-Service-Token to keystone along with the X-Auth-Token23:00
morganbut i don't think we need to23:00
jamielennoxif we added the restriction in keystone then we would have to make it send both, but i think you're right (and it was the way i was going) that there's no reason to add that to keystone level23:01
morganif we need to add teh ability for that restriction later... we can explore the options23:01
morgani highly doubt it will ever come up outside of this conversation ;)23:02
jamielennoxso the restriction has to exist, we just have to decide where to enforce it23:02
jamielennoxheh, yea, no one cares23:02
openstackgerritRon De Rose proposed openstack/keystone: Validate password history for self-service password changes  https://review.openstack.org/37901823:04
openstackgerritRon De Rose proposed openstack/keystone: Remove password history validation from admin password resets  https://review.openstack.org/37903023:06
openstackgerritRon De Rose proposed openstack/keystone: WIP - Remove password history validation from admin password resets  https://review.openstack.org/37903023:07
openstackgerritMerged openstack/oslo.policy: Update docs on policy sample generator  https://review.openstack.org/37423223:07
*** tqtran_ has joined #openstack-keystone23:13
*** tqtran has quit IRC23:14
*** nicolasbock has quit IRC23:17
*** tqtran_ has quit IRC23:18
jamielennoxstevemar: realistically the only thing that should override the auth_token implementation is keystone, so if i fix the keystone side first can i just make a slight API change to auth_token?23:24
jamielennoxor do i need to do a whole API workaroudn thign23:24
*** sdake has joined #openstack-keystone23:32
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Specify that unknown arguments can be passed to fetch_token  https://review.openstack.org/37903423:33
openstackgerritJamie Lennox proposed openstack/keystone: Ignore unknown arguments to fetch_token  https://review.openstack.org/37903523:34
*** sdake_ has joined #openstack-keystone23:35
*** markvoelker has joined #openstack-keystone23:37
*** sdake has quit IRC23:38
*** markvoelker has quit IRC23:41
*** marekd2_ has joined #openstack-keystone23:53
*** marekd2_ has quit IRC23:57
*** roxanaghe has quit IRC23:58

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!