Monday, 2016-12-12

*** markvoelker has quit IRC00:02
*** hoangcx has joined #openstack-keystone00:38
*** tovin07 has joined #openstack-keystone00:48
*** hoangcx has quit IRC00:49
*** hoangcx has joined #openstack-keystone00:49
*** tovin07 has quit IRC00:56
*** tovin07 has joined #openstack-keystone00:57
*** Zer0Byte__ has joined #openstack-keystone01:06
*** Zer0Byte__ has quit IRC01:11
*** zhangjl has joined #openstack-keystone01:33
*** liujiong has joined #openstack-keystone01:41
*** adu has joined #openstack-keystone02:24
stevemaro/02:26
*** spzala has joined #openstack-keystone02:30
*** spzala has quit IRC02:35
*** adu has quit IRC02:45
*** markvoelker has joined #openstack-keystone03:00
*** markvoelker has quit IRC03:05
*** zhangjl has quit IRC03:15
*** nicolasbock has joined #openstack-keystone03:49
*** adu has joined #openstack-keystone03:57
*** markvoelker has joined #openstack-keystone04:01
*** markvoelker has quit IRC04:05
*** nicolasbock has quit IRC04:07
*** adu has quit IRC04:12
*** udesale has joined #openstack-keystone04:25
*** madhaviy has joined #openstack-keystone04:36
*** madhaviy has quit IRC04:41
*** markvoelker has joined #openstack-keystone05:02
*** markvoelker has quit IRC05:07
*** adriant has quit IRC05:11
*** madhaviy has joined #openstack-keystone05:37
*** markvoelker has joined #openstack-keystone06:02
*** lifeless_ has quit IRC06:02
*** lifeless has joined #openstack-keystone06:03
*** markvoelker has quit IRC06:07
*** openstackgerrit_ has joined #openstack-keystone06:23
*** jaosorior has joined #openstack-keystone06:23
*** zhangjl has joined #openstack-keystone06:24
*** openstackgerrit_ has quit IRC06:25
*** openstackgerrit_ has joined #openstack-keystone06:26
*** openstackgerrit_ has quit IRC06:27
*** spzala has joined #openstack-keystone06:31
*** openstackgerrit_ has joined #openstack-keystone06:34
*** openstackgerrit_ has quit IRC06:35
*** spzala has quit IRC06:36
*** Dinesh_Bhor has joined #openstack-keystone06:37
*** richm has quit IRC06:41
*** dikonoor has joined #openstack-keystone06:53
*** jvarlamova___ has joined #openstack-keystone06:58
*** openstackgerrit_ has joined #openstack-keystone06:59
openstackgerritJulia Varlamova proposed openstack/keystone: Change DevStack plugin to setup multi-Keystone  https://review.openstack.org/39947207:00
*** openstackgerrit_ has quit IRC07:00
*** jvarlamova has quit IRC07:01
*** markvoelker has joined #openstack-keystone07:03
*** markvoelker has quit IRC07:08
*** tobberydberg has joined #openstack-keystone07:08
*** kiran-r has joined #openstack-keystone07:32
*** jaosorior has quit IRC07:40
*** kiran-r has quit IRC07:49
*** udesale has quit IRC07:57
*** jaosorior has joined #openstack-keystone08:00
*** BlackDex_ is now known as BlackDex08:03
*** markvoelker has joined #openstack-keystone08:04
*** liujiong has quit IRC08:06
*** liujiong has joined #openstack-keystone08:07
*** Zer0Byte__ has joined #openstack-keystone08:07
*** markvoelker has quit IRC08:09
*** Zer0Byte__ has quit IRC08:11
*** pcaruana has joined #openstack-keystone08:30
*** amoralej|off is now known as amoralej08:31
*** pcaruana has quit IRC08:37
*** pcaruana has joined #openstack-keystone08:38
*** pnavarro has joined #openstack-keystone08:55
*** zzzeek has quit IRC09:00
*** zzzeek has joined #openstack-keystone09:00
*** zhangjl has quit IRC09:06
*** d0ugal has quit IRC09:09
openstackgerritShan Guo proposed openstack/keystone: [api] set `is_admin_project` on tokens for admin project  https://review.openstack.org/40967809:10
*** udesale has joined #openstack-keystone09:10
*** udesale has quit IRC09:11
*** udesale has joined #openstack-keystone09:12
*** d0ugal has joined #openstack-keystone09:14
*** d0ugal has quit IRC09:14
*** d0ugal has joined #openstack-keystone09:14
*** d0ugal has quit IRC09:17
*** d0ugal has joined #openstack-keystone09:19
*** namnh has joined #openstack-keystone09:28
*** spzala has joined #openstack-keystone09:31
*** asettle has joined #openstack-keystone09:33
*** spzala has quit IRC09:36
*** markvoelker has joined #openstack-keystone10:06
*** markvoelker has quit IRC10:10
*** daemontool has joined #openstack-keystone10:14
*** daemontool has quit IRC10:15
*** liujiong has quit IRC10:18
*** hoangcx has quit IRC10:24
*** madhaviy has quit IRC10:29
*** madhaviy has joined #openstack-keystone11:01
*** david_cu has quit IRC11:06
*** markvoelker has joined #openstack-keystone11:07
*** markvoelker has quit IRC11:11
*** richm has joined #openstack-keystone11:13
*** udesale has quit IRC11:15
*** udesale has joined #openstack-keystone11:19
*** nicolasbock has joined #openstack-keystone11:35
*** masuberu has quit IRC11:45
*** masber has joined #openstack-keystone11:46
*** AlexOughton has quit IRC12:00
*** AlexOughton has joined #openstack-keystone12:00
*** dikonoor has quit IRC12:02
*** dave-mccowan has joined #openstack-keystone12:04
*** markvoelker has joined #openstack-keystone12:07
*** namnh has quit IRC12:11
*** markvoelker has quit IRC12:12
*** iurygregory has joined #openstack-keystone12:33
stevemaro/12:35
*** udesale has quit IRC12:47
*** markvoelker has joined #openstack-keystone13:15
*** agrebennikov_ has joined #openstack-keystone13:37
*** briancurtin has quit IRC13:42
*** briancurtin has joined #openstack-keystone13:42
*** amoralej is now known as amoralej|lunch13:45
openstackgerritMerged openstack/keystone: Remove exception from v2 validation path  https://review.openstack.org/40497713:45
openstackgerritMerged openstack/keystone: Move V2TokenDataHelper to the v2.0 controller  https://review.openstack.org/38938313:46
*** clenimar has joined #openstack-keystone13:51
*** eduardo has joined #openstack-keystone13:55
*** dikonoor has joined #openstack-keystone14:00
*** arunkant has quit IRC14:09
*** zzzeek has quit IRC14:13
*** madhaviy has quit IRC14:14
*** zzzeek has joined #openstack-keystone14:14
*** madhaviy has joined #openstack-keystone14:15
samueldmqmorning keystone14:17
samueldmqstevemar: o/14:17
*** Tahvok has quit IRC14:18
knikollamorning o/14:18
*** Matias has quit IRC14:18
*** Matias has joined #openstack-keystone14:23
*** Tahvok has joined #openstack-keystone14:24
*** amoralej|lunch is now known as amoralej14:25
*** ayoung has joined #openstack-keystone14:32
*** ChanServ sets mode: +v ayoung14:32
*** jamielennox is now known as jamielennox|away14:38
lbragstado/14:39
*** udesale has joined #openstack-keystone14:41
eduardoMorning14:42
*** Ephur has joined #openstack-keystone14:44
eduardoI m having trouble with keystone and oauth2, to change the token duration. I am trying to change kestone.conf - [token] - "expiration", but no success. Does someone knows how do I change the default token durations of 3600 seconds?14:44
ayoungeduardo, that should do it14:45
*** jamielennox|away is now known as jamielennox14:45
*** spzala has joined #openstack-keystone14:46
*** nkinder has joined #openstack-keystone14:47
*** arunkant has joined #openstack-keystone14:48
*** spzala has quit IRC14:48
eduardoI imagined it should work, but it is nothing. Maybe because of the plugin oauth2. Is there a separate configuration for it?14:49
stevemareduardo: the kestone.conf - [token] - "expiration" section changes the expiry of tokens issued by keystone14:50
stevemareduardo: those are different than oauth2 tokens14:50
stevemaroauth2 tokens will be returned by some identity provider that speaks oauth2, we don't control the expiration of those14:50
stevemarwe only consume what is in a oauth2 assertion, what goes in it is up to the identity provider14:51
*** arunkant has quit IRC14:53
*** diazjf has joined #openstack-keystone14:54
openstackgerritayoung proposed openstack/keystone: Fernet token formatter with explicit role  https://review.openstack.org/31007414:55
-openstackstatus- NOTICE: The Gerrit service on review.openstack.org is restarting now to address acute performance issues, and will be back online momentarily.15:06
*** asettle__ has joined #openstack-keystone15:08
*** david_cu has joined #openstack-keystone15:09
*** asettle has quit IRC15:10
*** ayoung is now known as ayoung_afk15:11
stevemarare there any blueprints that are close to landing this week?15:18
stevemarwe've got 11 approved for ocata, 1 complete, 6 in progress and 4 not started =\15:19
stevemarcutting ocata-2 this week15:19
*** jaugustine has joined #openstack-keystone15:24
stevemarprogress here: https://docs.google.com/spreadsheets/d/156q820cXcEc8Y9YWQgoc_hyOm3AZ2jtMQM3zdDhwGFU/edit?usp=sharing15:27
stevemarjamielennox: is there any server side work left to do for token expiration?15:31
*** dave-mccowan has quit IRC15:31
*** samueldmq has quit IRC15:37
*** samueldmq has joined #openstack-keystone15:37
*** ChanServ sets mode: +v samueldmq15:37
*** diazjf has quit IRC15:38
*** phalmos has joined #openstack-keystone15:43
*** ravelar has joined #openstack-keystone15:45
*** dave-mccowan has joined #openstack-keystone15:47
*** dikonoor has quit IRC15:47
*** tobberyd_ has joined #openstack-keystone15:47
*** ravelar1 has joined #openstack-keystone15:50
*** tobberydberg has quit IRC15:51
*** diazjf has joined #openstack-keystone15:51
*** tobberyd_ has quit IRC15:52
*** ravelar has quit IRC15:53
eduardothank you +ayoung and @stevemar. The plugin I have is within contrib, so I guess it is not part of openstack keystone15:55
eduardoI am using a version used in the project FIWARE15:55
dstanekeduardo: and putting it in keystone?15:57
eduardoputting what in keystone?16:03
dstanekeduardo: you mentioned something in contributing from a different project16:04
*** jaosorior has quit IRC16:10
*** jaosorior has joined #openstack-keystone16:10
eduardoI am not shure if there is alread a relation with this project. The version I am using, that is part of a bigger project, is: https://github.com/ging/keystone/16:12
*** spzala has joined #openstack-keystone16:15
*** ravelar1 has quit IRC16:22
*** chris_hultin|AWA is now known as chris_hultin16:29
openstackgerritSamuel Pilla proposed openstack/keystone: Add password expiration queries for PCI-DSS  https://review.openstack.org/40389816:31
*** dikonoor has joined #openstack-keystone16:40
*** asettle__ is now known as asettle16:45
*** evrardjp has quit IRC16:46
*** evrardjp has joined #openstack-keystone16:47
*** raildo has joined #openstack-keystone16:59
*** pcaruana has quit IRC16:59
*** gagehugo has quit IRC17:08
*** Zer0Byte__ has joined #openstack-keystone17:17
*** diazjf has quit IRC17:17
*** ravelar has joined #openstack-keystone17:19
stevemareduardo: first i've heard about FIWARE -- the wiki is really outdated: http://forge.fiware.org/plugins/mediawiki/wiki/fiware/index.php/OpenStack_Keystone17:22
*** ravelar has quit IRC17:24
*** ravelar has joined #openstack-keystone17:24
*** ravelar has quit IRC17:28
eduardoyes @stevemar, it is not easy to get information17:29
*** ravelar has joined #openstack-keystone17:31
*** dikonoor has quit IRC17:31
*** udesale has quit IRC17:37
*** arunkant has joined #openstack-keystone17:44
openstackgerritRon De Rose proposed openstack/keystone: WIP - Add domain_id to the user table  https://review.openstack.org/40987417:49
*** openstack has joined #openstack-keystone17:57
*** jaosorior has quit IRC18:03
openstackgerritRon De Rose proposed openstack/keystone: WIP - Add domain_id to the user table  https://review.openstack.org/40987418:04
*** eduardo has quit IRC18:06
*** madhaviy has quit IRC18:10
*** martinus__ has quit IRC18:10
*** tqtran has joined #openstack-keystone18:11
*** martinus__ has joined #openstack-keystone18:13
*** harlowja has joined #openstack-keystone18:20
*** ayoung_afk is now known as ayoung18:32
ayoungstevemar, https://review.openstack.org/#/c/395760/4  can you kick it on through?18:38
stevemarayoung: done18:44
*** gagehugo has joined #openstack-keystone18:45
*** pnavarro has quit IRC18:52
*** asettle has quit IRC19:14
*** asettle has joined #openstack-keystone19:32
*** jamielennox is now known as jamielennox|away19:46
*** edmondsw has joined #openstack-keystone19:50
*** amoralej is now known as amoralej|off19:51
*** edmondsw has quit IRC19:52
*** jamielennox|away is now known as jamielennox19:53
*** woodster_ has joined #openstack-keystone20:01
*** phalmos_ has joined #openstack-keystone20:07
*** phalmos has quit IRC20:10
openstackgerritSamuel Pilla proposed openstack/keystone: Add password expiration queries for PCI-DSS  https://review.openstack.org/40389820:39
*** spzala has quit IRC20:40
*** spzala has joined #openstack-keystone20:41
*** spzala_ has joined #openstack-keystone20:43
*** spzala has quit IRC20:45
*** spzala_ has quit IRC20:48
*** chlong has joined #openstack-keystone21:01
stevemarrodrigods: samueldmq can either of you talk me out of reverting https://review.openstack.org/#/c/405574/16 ? :)21:02
rodrigodsstevemar, hmm let check the comments21:02
*** raildo has quit IRC21:03
rodrigodsstevemar, yeah... think you have made pretty good comments there21:03
stevemarrodrigods: also, we should never be merging the docs before the impl is complete :P21:03
stevemaror maybe not, i'm not so harsh on that rule21:04
openstackgerritSteve Martinelli proposed openstack/keystone: Revert "API Documentation for user password expires"  https://review.openstack.org/40992321:04
rodrigodsstevemar, this is the chicken/egg problem, i remember we used to only approve specs with the correspondent API changes21:06
*** asettle has quit IRC21:06
rodrigodsstevemar, about https://review.openstack.org/#/c/409010/21:06
rodrigodsi mean to add a new log entry21:06
rodrigodsdo not reuse the "name" one21:06
stevemarrodrigods: doesn't seem to be an issue here: https://review.openstack.org/#/q/topic:bp/pci-dss-notifications21:06
stevemarrodrigods: they are properly dependent21:06
rodrigodsstevemar, right - maybe ask to be always in the same topic branch21:07
stevemarrodrigods: oh i see what you mean, you don't want to write "duplicate name found `myidp`" when it's really an ID21:08
stevemarmeh, it kinda serves as the name IMO21:08
rodrigodsstevemar, it does21:09
rodrigodsbut if you give a slightly not accurate information21:09
rodrigodsa person who is debugging something will have issues21:09
stevemarrodrigods: whats your proposed alternative?21:09
rodrigodsstevemar, add a another conditional branch there21:09
rodrigodshehe21:09
*** adriant has joined #openstack-keystone21:09
rodrigodsif id...21:09
rodrigodselif id..21:10
rodrigodsstevemar, or we can fill a dict with {'name': ..., 'id': ..., 'domain_id': ...}  and create the message based on the parameters21:11
rodrigodsdon't know21:11
stevemarrodrigods: i commented on it21:12
stevemarrodrigods: your request was reasonable, just confused me initially, add more detail :)21:13
rodrigodsstevemar, thx, it was exactly what i tried to say21:13
openstackgerritSteve Martinelli proposed openstack/keystone: API Documentation for user password expires  https://review.openstack.org/40993621:32
stevemarrodrigods: gagehugo samueldmq ^21:32
openstackgerritRodrigo Duarte proposed openstack/keystone: API Documentation for user password expires  https://review.openstack.org/40993621:39
gagehugostevemar: thanks for fixing that!21:47
openstackgerritRon De Rose proposed openstack/keystone: WIP - Make user to nonlocal_user a 1:1 relationship  https://review.openstack.org/40994621:48
*** Ephur has quit IRC22:02
*** Ephur has joined #openstack-keystone22:02
openstackgerritRon De Rose proposed openstack/keystone: WIP - Make user to nonlocal_user a 1:1 relationship  https://review.openstack.org/40994622:05
stevemargagehugo: np! just trying to set good habits ;)22:06
*** asettle has joined #openstack-keystone22:06
openstackgerritSteve Martinelli proposed openstack/keystone: API Documentation for user password expires  https://review.openstack.org/40993622:07
*** asettle has quit IRC22:08
*** asettle has joined #openstack-keystone22:09
openstackgerritRon De Rose proposed openstack/keystone: Make user to nonlocal_user a 1:1 relationship  https://review.openstack.org/40994622:10
jamielennoxstevemar: so allow_expired is done from a server side, it needs: https://review.openstack.org/#/c/382100/22:10
jamielennoxstevemar: which is a problem22:11
jamielennoxwe need to protect the service_token messages so that only the services should be allowed to extend operations22:11
openstackgerritRichard Avelar proposed openstack/keystone: Add doctor checks for ldap symptoms  https://review.openstack.org/40929222:13
jamielennoxbut so we need a policy check on the service token, but setting a reasonable default here is not backwards compatible22:15
stevemarjamielennox: oye22:15
openstackgerritRichard Avelar proposed openstack/keystone: Add doctor checks for ldap symptoms  https://review.openstack.org/40929222:16
jamielennoxstevemar: writing this out i might have a solution, it'll just be a bit odd22:17
jamielennoxstevemar: main question is do we want to use oslo.policy on that check or just a list of required roles22:18
jamielennoxthere's no other usages of oslo.policy in middleware22:18
openstackgerritRon De Rose proposed openstack/keystone: Make user to nonlocal_user a 1:1 relationship  https://review.openstack.org/40994622:22
*** asettle has quit IRC22:26
stevemarrderose: i feel like all those bugs that you're fixing for federation would have been better served as part of a spec or bp22:28
rderosestevemar: hmm... yeah, probably22:29
stevemarrderose: cause they could go in independent of the federated query APIs spec22:29
rderosestevemar: yeah, but I sort of feel we should fix things before starting that work22:30
rderosestevemar: and its seem everyone agrees that an IdP should be mapped to a domain22:30
*** jaugustine has quit IRC22:33
stevemarrderose: totally22:36
rderosestevemar: before starting the federated query API, federated users need to belong to a domain and I want to fix a few issues with the data model22:36
stevemarrderose: i just wish there was a single reference instead of a set of bugs22:36
stevemarrderose: yep22:36
rderosestevemar: I see22:36
stevemaryou can probably write 'bp whatever-the-name-was' in the commit message22:36
rderosestevemar: can we create a bp without a spec?22:36
stevemarnah, just link it back up to the federated query stuff22:37
stevemarit's foundation for it22:37
rderosestevemar: ah, right22:37
rderoseokay22:37
*** Ephur has quit IRC22:37
*** Ephur has joined #openstack-keystone22:38
*** Ephur has quit IRC22:38
*** Ephur has joined #openstack-keystone22:39
*** Ephur has quit IRC22:39
*** Ephur has joined #openstack-keystone22:40
*** Ephur has quit IRC22:40
*** Ephur has joined #openstack-keystone22:40
*** Ephur has quit IRC22:41
*** Ephur has joined #openstack-keystone22:41
*** ravelar has quit IRC22:41
*** Ephur has quit IRC22:42
*** Ephur has joined #openstack-keystone22:42
*** Ephur has quit IRC22:43
jamielennoxstevemar: so thoughts on auth_token depending on oslo.policy?22:43
*** Ephur has joined #openstack-keystone22:43
openstackgerritRon De Rose proposed openstack/keystone: Require domain_id when registering Identity Providers  https://review.openstack.org/39968422:43
*** Ephur has quit IRC22:43
stevemarjamielennox: not crazy about it22:44
*** Ephur has joined #openstack-keystone22:44
jamielennoxneither22:44
*** chris_hultin is now known as chris_hultin|AWA22:44
*** Ephur has quit IRC22:44
openstackgerritRon De Rose proposed openstack/keystone: WIP - Set the domain for federated users  https://review.openstack.org/40833222:44
*** Ephur has joined #openstack-keystone22:45
*** Ephur has quit IRC22:45
openstackgerritRon De Rose proposed openstack/keystone: WIP - Add domain_id to the user table  https://review.openstack.org/40987422:46
*** Ephur has joined #openstack-keystone22:46
*** asettle has joined #openstack-keystone22:46
*** Ephur has quit IRC22:46
*** Ephur has joined #openstack-keystone22:47
openstackgerritRon De Rose proposed openstack/keystone: Make user to nonlocal_user a 1:1 relationship  https://review.openstack.org/40994622:47
*** Ephur has joined #openstack-keystone22:47
*** Ephur has quit IRC22:48
*** Ephur has joined #openstack-keystone22:49
*** asettle has quit IRC22:49
*** Ephur has quit IRC22:49
*** asettle has joined #openstack-keystone22:49
*** Ephur has joined #openstack-keystone22:49
*** Ephur has quit IRC22:50
*** Ephur has joined #openstack-keystone22:50
*** Ephur has quit IRC22:50
*** spzala has joined #openstack-keystone22:51
*** Ephur has joined #openstack-keystone22:51
*** Ephur has quit IRC22:51
*** Ephur has joined #openstack-keystone22:52
*** Ephur has quit IRC22:52
*** Ephur has joined #openstack-keystone22:53
*** Ephur has quit IRC22:53
*** asettle has quit IRC22:53
*** Ephur has joined #openstack-keystone22:54
*** Ephur has quit IRC22:54
*** Ephur has joined #openstack-keystone22:55
*** Ephur has quit IRC22:55
*** Ephur has joined #openstack-keystone22:55
*** Ephur has quit IRC22:56
*** Ephur has joined #openstack-keystone22:56
*** Ephur has quit IRC22:57
*** Ephur has joined #openstack-keystone22:57
*** Ephur has quit IRC22:58
*** Ephur has joined #openstack-keystone22:58
*** Ephur has quit IRC22:58
*** Ephur has joined #openstack-keystone22:59
*** Ephur has quit IRC22:59
*** Ephur has joined #openstack-keystone23:00
*** Ephur has quit IRC23:00
*** Ephur has joined #openstack-keystone23:01
*** Ephur has quit IRC23:01
*** Ephur has joined #openstack-keystone23:02
*** Ephur has quit IRC23:02
*** Ephur has joined #openstack-keystone23:03
*** Ephur has quit IRC23:03
openstackgerritMerged openstack/keystone-specs: clean up approved specs for ocata  https://review.openstack.org/40893123:03
*** Ephur has joined #openstack-keystone23:04
*** Ephur has quit IRC23:04
*** Ephur has joined #openstack-keystone23:04
*** Ephur has quit IRC23:05
*** Ephur has joined #openstack-keystone23:05
*** Ephur has quit IRC23:05
*** Ephur has joined #openstack-keystone23:06
*** Ephur has quit IRC23:06
*** Ephur has joined #openstack-keystone23:07
*** Ephur has quit IRC23:07
*** Ephur has joined #openstack-keystone23:08
*** Ephur has quit IRC23:08
*** Ephur has joined #openstack-keystone23:09
*** Ephur has quit IRC23:09
openstackgerritayoung proposed openstack/keystone-specs: Role Check from Middleware  https://review.openstack.org/39162423:10
*** Ephur has joined #openstack-keystone23:10
*** Ephur has quit IRC23:10
*** Ephur has joined #openstack-keystone23:10
*** Ephur has quit IRC23:11
*** Ephur has joined #openstack-keystone23:11
*** Ephur has quit IRC23:12
*** Ephur has joined #openstack-keystone23:12
*** Ephur has quit IRC23:13
*** Ephur has joined #openstack-keystone23:13
*** Ephur has quit IRC23:13
*** Ephur has joined #openstack-keystone23:14
*** Ephur has quit IRC23:14
*** Ephur has joined #openstack-keystone23:15
*** Ephur has quit IRC23:15
*** Ephur has joined #openstack-keystone23:16
*** Ephur has quit IRC23:16
*** Ephur has joined #openstack-keystone23:17
*** Ephur has quit IRC23:17
*** Ephur has joined #openstack-keystone23:17
*** Ephur has quit IRC23:18
*** Ephur has joined #openstack-keystone23:19
*** Ephur has quit IRC23:19
*** Ephur has joined #openstack-keystone23:19
*** Ephur has quit IRC23:20
*** Ephur has joined #openstack-keystone23:20
*** Ephur has quit IRC23:20
*** Ephur has joined #openstack-keystone23:21
*** Ephur has quit IRC23:21
*** Ephur has joined #openstack-keystone23:22
*** Ephur has quit IRC23:22
*** Ephur has joined #openstack-keystone23:23
*** Ephur has quit IRC23:23
*** Ephur has joined #openstack-keystone23:24
*** Ephur has quit IRC23:24
*** Ephur has joined #openstack-keystone23:25
*** Ephur has quit IRC23:25
*** Ephur has joined #openstack-keystone23:26
*** Ephur has quit IRC23:26
*** Ephur has joined #openstack-keystone23:26
*** Ephur has quit IRC23:27
*** Ephur has joined #openstack-keystone23:27
*** Ephur has quit IRC23:28
*** Ephur has joined #openstack-keystone23:28
*** Ephur has quit IRC23:28
*** Ephur has joined #openstack-keystone23:29
*** Ephur has quit IRC23:29
*** Ephur has joined #openstack-keystone23:30
*** Ephur has quit IRC23:30
*** Ephur has joined #openstack-keystone23:31
*** Ephur has quit IRC23:31
*** Ephur has joined #openstack-keystone23:32
*** Ephur has quit IRC23:32
*** Ephur has joined #openstack-keystone23:32
*** Ephur has quit IRC23:33
*** Ephur has joined #openstack-keystone23:34
*** Ephur has quit IRC23:34
*** Ephur has joined #openstack-keystone23:34
*** Ephur has quit IRC23:35
*** Ephur has joined #openstack-keystone23:35
*** Ephur has quit IRC23:36
*** gagehugo has quit IRC23:36
*** Ephur has joined #openstack-keystone23:36
*** Ephur has quit IRC23:36
*** Ephur has joined #openstack-keystone23:37
*** Ephur has quit IRC23:37
*** Ephur has joined #openstack-keystone23:38
*** Ephur has quit IRC23:38
*** Ephur has joined #openstack-keystone23:39
*** Ephur has quit IRC23:39
*** Ephur has joined #openstack-keystone23:40
*** adrian_otto has joined #openstack-keystone23:40
*** Ephur has quit IRC23:40
*** Ephur has joined #openstack-keystone23:41
*** Ephur has quit IRC23:41
*** Ephur has joined #openstack-keystone23:41
*** Ephur has quit IRC23:42
*** Ephur has joined #openstack-keystone23:42
*** Ephur has quit IRC23:43
*** Ephur has joined #openstack-keystone23:43
*** Ephur has quit IRC23:43
*** spzala has quit IRC23:44
*** spzala has joined #openstack-keystone23:44
*** Ephur has joined #openstack-keystone23:44
*** Ephur has joined #openstack-keystone23:45
*** Ephur has quit IRC23:45
*** stingaci has joined #openstack-keystone23:46
*** Ephur has joined #openstack-keystone23:46
*** Ephur has quit IRC23:46
stingaciHey guys. I have a question regarding the "admin_and_matching_domain_id" example rule defined here: http://docs.openstack.org/security-guide/identity/policies.html. Anyone around with a few short cycles to spare?23:46
*** Ephur has joined #openstack-keystone23:47
*** Ephur has quit IRC23:47
*** Ephur has joined #openstack-keystone23:48
*** Ephur has quit IRC23:48
*** Ephur has joined #openstack-keystone23:48
*** Ephur has quit IRC23:49
*** asettle has joined #openstack-keystone23:49
*** Ephur has joined #openstack-keystone23:49
*** Ephur has quit IRC23:50
*** Ephur has joined #openstack-keystone23:50
*** Ephur has quit IRC23:51
ayoungstingaci, you don't take the easy path do you23:51
ayoungstevemar, can you ban Ephur?23:51
*** Ephur has joined #openstack-keystone23:51
*** Ephur has quit IRC23:51
*** Ephur has joined #openstack-keystone23:52
*** Ephur has quit IRC23:52
*** dave-mccowan has quit IRC23:53
*** Ephur has joined #openstack-keystone23:53
*** Ephur has quit IRC23:53
*** Ephur has joined #openstack-keystone23:54
*** Ephur has quit IRC23:54
*** asettle has quit IRC23:54
stingaciwhat do you mean? My goal is to restrict access (to users with the admin role) to the domain they're currently scoped to23:54
stingaciIs there an easier way?23:54
*** Ephur has joined #openstack-keystone23:55
*** Ephur has quit IRC23:55
*** ravelar has joined #openstack-keystone23:55
*** Ephur has joined #openstack-keystone23:56
*** Ephur has quit IRC23:56
*** Ephur has joined #openstack-keystone23:57
stingaciAlso, with that rule in my keystone policy.json, I can't perform any of the regular admin operations. Conceptually, the rule makes sense to me, but I don't understand why it's not working..23:57
*** Ephur has joined #openstack-keystone23:57
*** Ephur has quit IRC23:58
*** Ephur has joined #openstack-keystone23:58
*** Ephur has quit IRC23:58
*** Ephur has joined #openstack-keystone23:59
*** Ephur has quit IRC23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!