Thursday, 2017-06-29

*** spzala has quit IRC00:07
*** spzala has joined #openstack-keystone00:12
*** spzala has quit IRC00:14
*** thorst has joined #openstack-keystone00:18
*** jdwidari has joined #openstack-keystone00:21
*** thorst has quit IRC00:23
*** thorst has joined #openstack-keystone00:31
*** thorst has quit IRC00:33
*** edmondsw has joined #openstack-keystone01:07
*** liujiong has joined #openstack-keystone01:10
*** edmondsw has quit IRC01:12
*** jmlowe has quit IRC01:19
*** Shunli has joined #openstack-keystone01:19
*** jmlowe has joined #openstack-keystone01:32
*** sbezverk has quit IRC01:34
*** tobberydberg has joined #openstack-keystone01:35
*** thorst has joined #openstack-keystone01:37
*** thorst has quit IRC01:37
*** tobberydberg has quit IRC01:39
*** wlfightup has joined #openstack-keystone01:39
*** lucasxu has joined #openstack-keystone01:41
morganmordred: i'll try and come up with something on that patch chain where i had to -1 if you don't by tomorrow01:41
*** wlfightup has quit IRC01:47
*** dave-mccowan has joined #openstack-keystone01:58
*** dave-mccowan has quit IRC02:05
*** dave-mccowan has joined #openstack-keystone02:06
*** gyee has quit IRC02:14
openstackgerritOpenStack Proposal Bot proposed openstack/keystoneauth master: Updated from global requirements  https://review.openstack.org/47794502:19
*** aselius has quit IRC02:28
lbragstadcmurphy: stevemar thanks for the responses!02:33
*** Shunli has quit IRC02:33
*** Shunli has joined #openstack-keystone02:33
*** Shunli has quit IRC02:35
*** Shunli has joined #openstack-keystone02:35
*** Shunli has quit IRC02:40
*** Shunli has joined #openstack-keystone02:40
*** Shunli has quit IRC02:42
*** Shunli has joined #openstack-keystone02:42
stevemar@lbragstad np02:46
stevemari think we used to get caught up deprecating things for a single true path02:47
stevemarbut, if maintenance is low, let it be02:47
*** Shunli has quit IRC02:48
*** dave-mccowan has quit IRC02:55
*** edmondsw has joined #openstack-keystone02:56
openstackgerrityangweiwei proposed openstack/keystone master: Clean up auto created domain when creating duplicate idp in federation  https://review.openstack.org/46240802:57
*** edmondsw has quit IRC03:00
*** zhurong has quit IRC03:11
*** Shunli has joined #openstack-keystone03:12
*** thorst has joined #openstack-keystone03:38
*** thorst has quit IRC03:43
*** ducttape_ has joined #openstack-keystone03:44
*** zhurong has joined #openstack-keystone03:49
*** ducttap__ has joined #openstack-keystone03:58
*** john5223_ has joined #openstack-keystone04:00
*** lucasxu has quit IRC04:01
*** ducttap__ has quit IRC04:02
*** ducttape_ has quit IRC04:02
*** namnh has joined #openstack-keystone04:23
*** namnh has quit IRC04:23
*** namnh has joined #openstack-keystone04:23
*** phalmos has joined #openstack-keystone04:24
*** edmondsw has joined #openstack-keystone04:43
*** edmondsw has quit IRC04:49
*** liujiong has quit IRC04:49
*** links has joined #openstack-keystone04:53
*** phalmos has quit IRC05:02
*** links has quit IRC05:03
*** phalmos has joined #openstack-keystone05:09
*** pcaruana has joined #openstack-keystone05:14
*** phalmos has quit IRC05:15
*** links has joined #openstack-keystone05:15
*** gyee has joined #openstack-keystone05:15
*** Shunli has quit IRC05:18
*** Shunli has joined #openstack-keystone05:19
*** Shunli has quit IRC05:23
*** Shunli has joined #openstack-keystone05:24
*** pcaruana has quit IRC05:30
*** pcaruana has joined #openstack-keystone05:33
*** thorst has joined #openstack-keystone05:39
*** pcaruana has quit IRC05:39
*** Shunli has quit IRC05:43
*** Shunli has joined #openstack-keystone05:44
*** thorst has quit IRC05:44
*** Shunli has quit IRC05:45
*** Shunli has joined #openstack-keystone05:46
*** rcernin_ has joined #openstack-keystone05:48
*** zhurong has quit IRC05:56
*** rcernin_ is now known as rcernin06:04
*** zhurong has joined #openstack-keystone06:11
*** zhurong has quit IRC06:19
*** zhurong has joined #openstack-keystone06:22
*** edmondsw has joined #openstack-keystone06:32
openstackgerrityangweiwei proposed openstack/keystone master: Clean up auto created domain when creating duplicate idp in federation  https://review.openstack.org/46240806:32
*** edmondsw has quit IRC06:36
*** Shunli has quit IRC07:04
*** Shunli has joined #openstack-keystone07:05
*** Shunli has quit IRC07:09
*** Shunli has joined #openstack-keystone07:10
*** Shunli has quit IRC07:11
*** gyee has quit IRC07:12
*** aojea has joined #openstack-keystone07:21
*** tesseract has joined #openstack-keystone07:31
openstackgerritkavitha h r proposed openstack/keystone master: Remove unused None from dict.get()  https://review.openstack.org/47878207:33
*** pcaruana has joined #openstack-keystone07:35
*** nkinder has quit IRC07:36
*** thorst has joined #openstack-keystone07:40
*** nkinder has joined #openstack-keystone07:41
*** thorst has quit IRC07:47
*** tesseract has quit IRC07:47
*** openstackgerrit has quit IRC07:47
*** tesseract has joined #openstack-keystone07:48
*** zzzeek has quit IRC08:00
*** zzzeek has joined #openstack-keystone08:00
*** junbo has quit IRC08:03
*** junbo has joined #openstack-keystone08:06
*** tesseract has quit IRC08:30
*** tesseract has joined #openstack-keystone08:32
*** pnavarro has joined #openstack-keystone08:38
*** aojea has quit IRC09:19
*** aojea has joined #openstack-keystone09:20
*** liujiong has joined #openstack-keystone09:38
*** tesseract has quit IRC09:38
samueldmqmorning keystone!09:40
*** tesseract has joined #openstack-keystone09:40
cmurphy\o09:41
*** thorst has joined #openstack-keystone09:43
*** openstackgerrit has joined #openstack-keystone09:47
openstackgerritSamuel de Medeiros Queiroz proposed openstack/keystone master: Move trust to DocumentedRuleDefault  https://review.openstack.org/44927809:47
*** thorst has quit IRC09:48
*** mvk has quit IRC09:58
*** aojea has quit IRC09:59
*** aojea has joined #openstack-keystone10:00
openstackgerritPavlo Shchelokovskyy proposed openstack/keystoneauth master: Add release note for 'none' auth plugin  https://review.openstack.org/47883910:02
*** liujiong has quit IRC10:23
*** mvk has joined #openstack-keystone10:25
openstackgerrityangweiwei proposed openstack/keystone master: Clean up auto created domain when creating duplicate idp in federation  https://review.openstack.org/46240810:51
*** aojea has quit IRC10:55
*** aojea has joined #openstack-keystone10:55
*** ducttape_ has joined #openstack-keystone11:03
*** ducttape_ has quit IRC11:08
*** nishaYadav has joined #openstack-keystone11:09
nishaYadavo/11:09
openstackgerritMerged openstack/keystoneauth master: Updated from global requirements  https://review.openstack.org/47794511:11
*** sjain has joined #openstack-keystone11:12
*** aojea has quit IRC11:15
*** aojea has joined #openstack-keystone11:15
nishaYadavCan anyone please help me find the source of these docs - https://docs.openstack.org/ocata/config-reference/identity/config-options.html11:30
sjainnishaYadav: I think I know where these are, just a sec11:31
cmurphynishaYadav: here http://git.openstack.org/cgit/openstack/openstack-manuals/tree/doc/config-reference/source/identity/config-options.rst11:31
sjainyup these ^^11:32
sjainthanks cmurphy!11:32
cmurphysjain: those are going to be moved into the keystone tree though right?11:32
sjainyes right11:32
sjainI'm working on those, they need integration with oslo.config which I'm trying to figure out11:33
nishaYadavthanks cmurphy sjain :)11:34
*** edmondsw has joined #openstack-keystone11:35
sjain@lbragstad: I need some help with PKI certificates, can you ping me whenever you are free, we can start working on those docs11:36
*** raildo has joined #openstack-keystone11:39
*** thorst has joined #openstack-keystone11:57
*** namnh has quit IRC12:01
*** aojea has quit IRC12:28
*** aojea has joined #openstack-keystone12:29
*** chlong_ has joined #openstack-keystone12:35
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Expose getting EndpointData on adapter and session  https://review.openstack.org/46909112:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Add support for version ranges  https://review.openstack.org/46909012:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Support a list of interface values  https://review.openstack.org/47716912:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Support explicitly requesting the 'latest' version  https://review.openstack.org/46908912:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Add flags to turn discovery on and off  https://review.openstack.org/46908812:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Clean up a few review nits  https://review.openstack.org/47765712:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Plumb endpoint_override through get_endpoint_data  https://review.openstack.org/46909212:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Update docs and add a release note  https://review.openstack.org/47756612:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Ensure we discover only when we should  https://review.openstack.org/47724212:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Optimize matching version no microversion needed  https://review.openstack.org/47027412:40
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Refactor volume mock urls in identity_common tests  https://review.openstack.org/47724612:40
mordredmorgan: I believe I figured it out12:40
cmurphygood morning mordred12:40
mordredcmurphy: morning! I just replied to your question on the version ranges patch - tl;dr - this is all about major versions12:44
cmurphymordred: okay then that makes a little more sense12:45
mordredoh - I need to go back and address the min_version='latest' question. blast - I had intended to address all the things before pushing the stack up again12:45
mordredcmurphy: it's a weird concept/area and pretty much confuses everyone12:45
cmurphyya :(12:46
mordredcmurphy: so you think we should accept min_version='latest' - but then maybe error if min_version='latest' and max_version is anything other than 'latest' or None ?12:46
cmurphymordred: that seems intuitive to me12:47
cmurphymorgan: ^12:47
*** masber has quit IRC12:48
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Add support for version ranges  https://review.openstack.org/46909013:00
mordredcmurphy: maybe like that ^^13:00
*** lucasxu has joined #openstack-keystone13:01
cmurphymordred: I think that makes sense13:02
mordredcool. adding test real quick13:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Expose getting EndpointData on adapter and session  https://review.openstack.org/46909113:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Add support for version ranges  https://review.openstack.org/46909013:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Support a list of interface values  https://review.openstack.org/47716913:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Clean up a few review nits  https://review.openstack.org/47765713:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Plumb endpoint_override through get_endpoint_data  https://review.openstack.org/46909213:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Update docs and add a release note  https://review.openstack.org/47756613:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Ensure we discover only when we should  https://review.openstack.org/47724213:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Optimize matching version no microversion needed  https://review.openstack.org/47027413:03
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Refactor volume mock urls in identity_common tests  https://review.openstack.org/47724613:03
mordredcmurphy, morgan, samueldmq: enjoy your daily does of version-discovery! :)13:04
*** ayoung has joined #openstack-keystone13:07
*** ducttape_ has joined #openstack-keystone13:07
*** ducttape_ has quit IRC13:12
*** sjain has quit IRC13:17
*** jsavak has joined #openstack-keystone13:18
*** sjain has joined #openstack-keystone13:29
*** pnavarro has quit IRC13:29
*** ducttape_ has joined #openstack-keystone13:31
*** nishaYadav has quit IRC13:32
*** ducttap__ has joined #openstack-keystone13:32
*** ducttap__ has quit IRC13:33
*** ducttap__ has joined #openstack-keystone13:33
*** ducttape_ has quit IRC13:36
*** nishaYadav has joined #openstack-keystone13:45
*** zhurong has quit IRC13:49
stevemarlbragstad: https://review.openstack.org/#/c/478601/113:50
openstackgerritChandan Kumar proposed openstack/keystone-tempest-plugin master: Cleaned up *-requirements.txt  https://review.openstack.org/47893813:51
*** ducttap__ has quit IRC13:56
*** ducttape_ has joined #openstack-keystone13:57
*** phalmos has joined #openstack-keystone13:57
*** nishaYadav_ has joined #openstack-keystone13:58
*** phalmos_ has joined #openstack-keystone14:00
*** spzala has joined #openstack-keystone14:01
*** phalmos has quit IRC14:03
cmurphythis could use some keystone feedback before i start harassing the horizon team for reviews https://review.openstack.org/#/c/476064/14:04
*** ducttape_ has quit IRC14:05
*** nishaYadav_ has quit IRC14:05
*** ducttape_ has joined #openstack-keystone14:05
*** sjain has quit IRC14:06
*** ducttape_ has quit IRC14:23
*** pnavarro has joined #openstack-keystone14:25
*** aojea has quit IRC14:25
*** aojea has joined #openstack-keystone14:26
*** ducttape_ has joined #openstack-keystone14:30
*** zhurong has joined #openstack-keystone14:30
*** ducttape_ has quit IRC14:39
*** zhurong has quit IRC14:40
*** lbragstad has quit IRC14:40
*** ducttape_ has joined #openstack-keystone14:41
*** jmlowe has quit IRC14:46
*** ducttape_ has quit IRC14:47
*** spzala has quit IRC14:57
*** ayoung has quit IRC15:01
*** jmlowe has joined #openstack-keystone15:02
*** ducttape_ has joined #openstack-keystone15:07
*** lbragstad has joined #openstack-keystone15:14
*** ChanServ sets mode: +o lbragstad15:14
*** jistr is now known as jistr|afk15:20
*** ayoung has joined #openstack-keystone15:21
knikollao/15:21
lbragstado/15:21
*** rcernin has quit IRC15:28
*** gyee has joined #openstack-keystone15:38
*** aselius has joined #openstack-keystone15:40
gagehugoo/15:49
*** aojea has quit IRC15:51
*** nishaYadav has quit IRC15:54
*** jistr|afk is now known as jistr16:07
lbragstadstevemar: need a release for stable/newton i think https://review.openstack.org/#/c/478984/16:10
stevemarlbragstad: isn't stable/newton borked?16:10
lbragstadstevemar: ?16:10
lbragstadstevemar: how so?16:10
stevemarhttps://review.openstack.org/#/c/469514/16:11
stevemargate-keystone-dsvm-functional-ubuntu-xenial has been failing consistently16:11
lbragstadugh16:12
lbragstadsomething must have changed in tempest?16:12
lbragstadso apparently https://github.com/openstack/keystone-tempest-plugin/blob/360bbafa385624f1e86841875baabbbf1104e877/keystone_tempest_plugin/tests/api/identity/v3/test_identity_providers.py#L228-L244 is possible in stable/newton16:16
samueldmqcmurphy: about https://review.openstack.org/#/c/47606416:18
morganmordred: well then16:19
samueldmqcmurphy: how do users on a private hidden domain log in into horizon (it their domain does not appear in the dropdown)?16:19
lbragstadstevemar: damn...16:21
lbragstadstevemar: it's because https://github.com/openstack/keystone/commit/de8fbcf9a0072c84adf4f3630088bc34f9e9782e didn't get back ported16:22
lbragstadthat ^ patch adds validation for mapping_ids16:22
lbragstadwhich didn't make it back to stable/newton16:22
lbragstadas a result, we wrote tests in out tempest plugin to assert that functionality16:22
lbragstadwhich breaks stable/newton (because it doesn't have it...)16:22
morganmordred: have a nit on the chain (needs to be fixed, but can be done as a followup), so far looking like +2s the whole way16:25
stevemar@lbragstad backport it :)16:26
mordredmorgan: WOOT16:26
lbragstadstevemar: ok - not sure if it falls within the realm of acceptable backport material (since it's not a security fix) but since stable/newton is borked - what do we have to lose16:27
mordredmorgan: I have a 'fix-nits' patch at the end we can add the nit fixes to16:27
morganyeah, the latest != latest bit16:27
morganthat should be ValueError not TypeError16:27
morgani know you're looking at types, but we care about the values, since we allow string and int16:28
morganand float or whatever16:28
*** mvk has quit IRC16:28
morgancommented and tossed a +2 on it16:28
morganmordred: https://review.openstack.org/#/c/477169 did you see my in-line question?16:28
morganon the earlier patchset?16:28
morganthat one ^ and i'm now reviewing https://review.openstack.org/#/c/477242 -- but pretty much the whole chain looks good16:30
mordredmorgan: good point re: ValueError16:30
morganso, +2s all across, need the ValueError fixed at the end of the chain and answer the question re interface names.16:31
morgan(477169 will get a +2 with an answerto my question)16:32
mordredmorgan: we are not adding a new hard-lock on those values - the comment about the valid values was deeper in the chain and I just copied it to all the places that take interface16:32
morganwfm16:32
morganjust wanted a sanity check on that16:32
mordredmorgan: yah- if you look at the bottom of https://review.openstack.org/#/c/477169/5/keystoneauth1/access/service_catalog.py - you can see the old copies of that comment16:32
morgannext time, don't change docs like that.16:32
morganmake the relatively unrelated doc change separately16:33
mordredmorgan: fair16:33
morganwill make it more clear that we're not changing something unexpected16:33
morgan+2.16:33
morgannow you just need someone else to +2/+A the ones that don't already have +2s16:33
morganerm 2x+216:33
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Clean up a few review nits  https://review.openstack.org/47765716:34
mordredmorgan: ^^ that's got the ValueError bits16:34
morgannice16:35
lbragstadstevemar: well - let's see what happens https://review.openstack.org/#/c/478994/16:39
morganlbragstad: uhm https://review.openstack.org/#/c/475929 -- doesn't this leak if a bad user password is used16:42
morganwhen using ldap?16:42
morgani.e. shouldn't this be a security error?16:43
lbragstadmorgan: what information would leak?16:48
lbragstadmorgan: if a user used a bad password anyway?16:48
*** pcaruana has quit IRC16:48
*** jdwidari has quit IRC16:49
morganwe say "bad username / password" elsewhere16:50
morganthis explicitly communicates a bad password16:50
morganit's inconsistent16:50
lbragstadmorgan: oh - i see what you mean16:50
lbragstadmorgan: good point16:50
lbragstadcc gagehugo ^16:50
morganand breaks current security guidelines we implemented in keystone16:50
morganit's not "wrong" to do this, but we should be consistent in one direction or another16:51
lbragstadmorgan: yeah - that makes sense16:51
lbragstadmorgan: well - does credentials mean only password or username + password?16:53
*** sjain has joined #openstack-keystone16:54
*** jsavak has quit IRC16:56
openstackgerritMerged openstack/keystone master: Remove keystone_tempest_plugin from setup.cfg  https://review.openstack.org/47860116:56
morgani don't know in this case16:56
*** jsavak has joined #openstack-keystone16:56
morganthis is why i asked.16:56
lbragstadmorgan: it's a good question16:57
lbragstadgagehugo: ping*16:57
*** tesseract has quit IRC16:58
*** jsavak has quit IRC17:01
*** rderose has joined #openstack-keystone17:04
gagehugoimo credentials is username/password, but I'm fine with being explicit in saying "username / password" instead17:06
gagehugohttps://github.com/openstack/keystone/blob/59177627b36236466baaeac6484c4550d4a0ba11/keystone/auth/plugins/password.py#L4017:07
gagehugoIt says username or password there, I'm fine with using that for LDAP as well17:08
*** jsavak has joined #openstack-keystone17:11
*** nishaYadav has joined #openstack-keystone17:11
*** aojea has joined #openstack-keystone17:15
openstackgerritGage Hugo proposed openstack/keystone master: Clarify LDAP invalid credentials exception  https://review.openstack.org/47592917:17
gagehugomorgan lbragstad ^17:17
*** sjain_ has joined #openstack-keystone17:18
samueldmqlbragstad: so we run current code against old (in stable branches) tempest17:18
samueldmq?17:18
lbragstadsamueldmq: yeah17:18
lbragstadgagehugo: thanks - looks good to me17:19
lbragstadgagehugo: morgan thoughts on adding a releasenote for that?17:19
lbragstadgagehugo: morgan i'm not sure how the wording work go, but it fixes a bug17:19
samueldmqlbragstad: so every single change that changes an API behavior needs to be backported to the affected stable branches17:20
*** sjain has quit IRC17:20
lbragstadsamueldmq: yeah - essentially17:20
*** aojea has quit IRC17:20
samueldmqlbragstad: I thought there were some requirements to meet in order to be able to backport17:20
samueldmqlike needs to be a security issue, etc17:20
lbragstadsamueldmq: yeah - i looked into that, stable/newton is in phase II17:20
lbragstadwhich means it's acceptable to backport critical fixes and security fixes17:21
lbragstadphase III is security fixes only17:21
lbragstadaccording to https://docs.openstack.org/project-team-guide/stable-branches.html#support-phases17:21
samueldmqlbragstad: https://github.com/openstack/keystone/commit/de8fbcf9a0072c84adf4f3630088bc34f9e9782e does not look to be critical17:21
samueldmqnor a security thing, does it?17:22
lbragstadsamueldmq: it does change the API, but it also fixes the gate :-/17:22
lbragstadotherwise stable/newton is broken17:22
lbragstadsamueldmq: i was considering the fact the stable/newton is broken without it to be critical17:23
samueldmqyeah I know we fix the gate, my whole point is that our methods/approach in tempest in stable branches might not be in agreement with what we have from the stable branches requirements17:23
lbragstadsamueldmq: we also don't run stable branches against changes in master17:23
lbragstadbecause of the lack of resources17:23
samueldmqlbragstad: so https://github.com/openstack/keystone/commit/de8fbcf9a0072c84adf4f3630088bc34f9e9782e is from Ocata17:23
lbragstadthe change that added that test to the keystone_tempest_plugin would have broken17:24
*** raildo has quit IRC17:24
lbragstadsamueldmq: yeah - which is prior to our tempest plugin support, which is where that test was added17:24
samueldmqok, I just would like to point out that there might be some exceptions to the stable branches rules17:25
samueldmqand this looks to be one17:26
openstackgerritKelly Hall proposed openstack/keystone master: Trim Whitespace from X-Subject-Token  https://review.openstack.org/47042517:26
lbragstadsamueldmq: yeah - it's a weird edge case17:26
lbragstadsamueldmq: we're kind of stuck between a rock and a hard place17:27
samueldmqlbragstad: ++17:28
lbragstadthat branch is in phase II, but the fix isn't security related or critical and changes an API :-/17:28
*** aojea has joined #openstack-keystone17:30
lbragstadgrabbing lunch17:31
*** mvk has joined #openstack-keystone17:33
samueldmqlbragstad: exactly, and this is cause by the process we have. so something might need to be fixed (in addition to the gate) :)17:34
samueldmqcaused17:35
openstackgerritKelly Hall proposed openstack/keystone master: Trim Whitespace from X-Subject-Token  https://review.openstack.org/47042517:35
*** sjain_ has quit IRC17:48
*** nishaYadav has quit IRC17:51
*** raildo has joined #openstack-keystone17:52
cmurphysamueldmq: re horizon they wouldn't be able to log in if the domain isn't in the dropdown, but for instance service users wouldn't want that anyway17:56
*** aojea_ has joined #openstack-keystone18:00
*** aojea has quit IRC18:02
*** aojea_ has quit IRC18:10
*** aojea has joined #openstack-keystone18:11
lbragstadstevemar: https://review.openstack.org/#/c/478994/ passed18:14
*** aojea has quit IRC18:15
*** jmlowe has quit IRC18:19
openstackgerritLance Bragstad proposed openstack/keystone master: Ensure there isn't duplication in federated auth  https://review.openstack.org/47902618:20
*** mnaser has left #openstack-keystone18:21
*** rmascena has joined #openstack-keystone18:34
*** raildo has quit IRC18:36
*** jdennis1 has joined #openstack-keystone18:44
*** jdennis has quit IRC18:45
*** sbezverk has joined #openstack-keystone18:52
lbragstadrodrigods: ^ addresses a couple of you comments from an old review18:54
*** jmlowe_ has joined #openstack-keystone18:55
openstackgerritMonty Taylor proposed openstack/keystoneauth master: Clean up a few review nits  https://review.openstack.org/47765718:56
mordredmorgan: when you update the exception something throws, you need to update the test that tests thta it throws that exception too :)18:56
mordredcmurphy: didja see? the ksa stack has a morgan +2 all the way up!!!18:57
morganmordred: hah18:57
cmurphymordred: very impressive18:59
cmurphymordred: i may not get a chance to revisit till tomorrow18:59
mordredcmurphy: that's perfectly fine - I appreciate all of your reviews19:01
*** aojea has joined #openstack-keystone19:05
*** thorst has quit IRC19:06
*** thorst has joined #openstack-keystone19:08
*** thorst has quit IRC19:13
lbragstadgagehugo: want to add a release note to https://review.openstack.org/#/c/475929/8 ?19:15
gagehugolbragstad sure19:15
lbragstadgagehugo: awesome - thanks!19:15
gagehugowill do after this meeting19:16
lbragstadgagehugo: no worries19:16
lbragstadgagehugo: i left a comment on the review, too19:16
*** sbezverk has quit IRC19:16
lbragstadknikolla: do you want to add a release note for https://bugs.launchpad.net/keystone/+bug/1696111 to keystone so that we don't miss it?19:18
openstackLaunchpad bug 1696111 in python-keystoneclient "Keystone confuses users when creating a trust when there's a roles name conflict" [Low,Fix committed] - Assigned to Kristi Nikolla (knikolla)19:18
lbragstadknikolla: thanks for the fixes there, it looks like all of them merged19:19
*** ducttap__ has joined #openstack-keystone19:22
*** ducttape_ has quit IRC19:22
*** thorst has joined #openstack-keystone19:23
*** sbezverk has joined #openstack-keystone19:23
*** jmlowe_ has quit IRC19:28
*** jmlowe has joined #openstack-keystone19:40
*** sjain has joined #openstack-keystone19:45
*** jmlowe_ has joined #openstack-keystone19:48
*** jmlowe has quit IRC19:49
*** sjain has quit IRC19:51
*** sbezverk has quit IRC19:57
*** aojea has quit IRC20:01
*** eandersson has quit IRC20:10
*** aojea has joined #openstack-keystone20:11
*** sbezverk has joined #openstack-keystone20:15
*** pnavarro has quit IRC20:39
lbragstadsamueldmq: ping20:42
lbragstadsamueldmq: were you about to recreate https://bugs.launchpad.net/keystone/+bug/1688123 per gagehugo's comment?20:42
openstackLaunchpad bug 1688123 in OpenStack Identity (keystone) "ignore_password_expiry is not honored" [Undecided,New]20:42
*** lucasxu has quit IRC20:44
*** sbezverk has quit IRC20:44
*** sbezverk has joined #openstack-keystone20:45
openstackgerritKelly Hall proposed openstack/keystone master: Trim Whitespace from X-Subject-Token  https://review.openstack.org/47042521:01
*** jmlowe has joined #openstack-keystone21:02
*** jmlowe_ has quit IRC21:03
openstackgerritGage Hugo proposed openstack/keystone master: Clarify LDAP invalid credentials exception  https://review.openstack.org/47592921:08
gagehugolbragstad ^ lemme know if that works21:08
lbragstadgagehugo: commented21:10
gagehugoah yeah will do21:11
openstackgerritGage Hugo proposed openstack/keystone master: Clarify LDAP invalid credentials exception  https://review.openstack.org/47592921:17
openstackgerritNicolas Helgeson proposed openstack/keystone master: WIP: Add project tags  https://review.openstack.org/47031721:17
*** f13o has joined #openstack-keystone21:21
gagehugosamueldmq lbragstad I also played around with the unit test/freezegun for the expiry bug and I couldn't get it to break21:21
lbragstadsamueldmq: gagehugo so - i think i figured out the problem21:21
lbragstadsamueldmq: gagehugo http://paste.openstack.org/show/614119/ sets the resource option21:22
lbragstadbut the clients interpret http://paste.openstack.org/show/614120/ as also being "valid" because it's in extras21:23
lbragstadso - you end up with something like this21:24
*** rmascena has quit IRC21:25
gagehugohmm21:25
*** raildo has joined #openstack-keystone21:26
*** jmlowe has quit IRC21:27
lbragstadhttp://paste.openstack.org/show/614121/21:28
lbragstadi can't actually update the resource options via the api because json schema is expecting a boolean but the actual json body isn't marshalling it to a boolean21:28
lbragstadwhich seems wrong21:28
lbragstadcc morgan ^21:28
*** aojea_ has joined #openstack-keystone21:29
morganweird21:29
lbragstadfwiw - my update_user.json file looks like this - http://paste.openstack.org/show/614119/21:29
gagehugoI just curl'd to update my example21:29
morganhm21:29
lbragstadhttp://paste.openstack.org/show/614119/ is value json but keystone is giving me a 40021:30
morgan"True" != True21:30
lbragstadright - somewhere along the line keystone isn't making u"True" -> True21:30
*** sbezverk has quit IRC21:31
morgandon't quote it21:31
morganJSON doesn't quote booleans21:31
*** aojea has quit IRC21:31
gagehugohttp://paste.openstack.org/show/614123/21:31
gagehugoI used true instead of "True"21:31
morgan>>> json.loads('{"t": true}')21:32
morgan{u't': True}21:32
lbragstadhttp://paste.openstack.org/show/614124/21:32
morganlowercase21:32
lbragstadderp21:32
morgansorry.21:32
lbragstadyeah - ok21:32
morgantrue vs True ;)21:32
*** sbezverk has joined #openstack-keystone21:32
gagehugoheh21:33
lbragstadok - it works!21:33
lbragstadhttp://paste.openstack.org/show/614125/21:33
morganyup21:33
morgan"True" != true != True ...21:34
lbragstadmorgan: ture21:34
lbragstadtrue*21:34
lbragstadso there isn't an issue with https://bugs.launchpad.net/keystone/+bug/168812321:34
openstackLaunchpad bug 1688123 in OpenStack Identity (keystone) "ignore_password_expiry is not honored" [Undecided,New]21:34
*** raildo has quit IRC21:34
lbragstadsamueldmq: was attempting to update the user by using http://paste.openstack.org/show/614120/21:35
lbragstadwhich wasn't getting filed as an option21:35
lbragstadbut the client actually returns is in the response because it's in extras21:35
* lbragstad hates extras21:35
gagehugodoes it show up in options though if it's stored in extras?21:38
lbragstadgagehugo: no21:38
lbragstadgagehugo: it's just a weird usability wart21:38
gagehugohmm21:38
lbragstadif you attempt to update the user with http://paste.openstack.org/show/614120/21:38
gagehugoyeah that gets dumped in extras21:39
lbragstadyou see if rendered as http://paste.openstack.org/show/614126/21:39
lbragstadbut the password expiry logic is right in requiring you to update it as http://paste.openstack.org/show/614119/21:40
gagehugoah ok21:40
lbragstadbecaus that's the official option21:40
lbragstadmake sense?21:40
gagehugoyup21:40
gagehugoI was just confused why it was showing up for samueldmq in the report as correct21:40
lbragstadi literally had to stare at this for an hour to figure out why samueldmq was hitting the issue and you weren't21:40
gagehugooptions | {'ignore_lockout_failure_attempts': True, 'ignore_password_expiry': True, 'ignore_change_password_upon_first_use': True}21:41
lbragstadyeah - that's how it *should* render21:41
lbragstadnot like http://paste.openstack.org/show/614126/21:41
gagehugobut no that makes sense cause I ran into the 400 issue cause I was trying to do "True" as well opposed to true21:41
lbragstadyeah21:42
lbragstadwe need to update https://docs.openstack.org/developer/keystone/admin/identity-security-compliance.html :(21:44
*** aojea_ has quit IRC21:49
*** f13o has quit IRC21:53
lbragstadgagehugo: updated https://bugs.launchpad.net/keystone/+bug/168812321:54
openstackLaunchpad bug 1688123 in OpenStack Identity (keystone) "ignore_password_expiry is not honored" [Undecided,Invalid]21:54
lbragstadmake sense?21:54
lbragstadcc samueldmq ^21:55
gagehugolbragstad yup21:56
*** jsavak has quit IRC21:59
*** aojea has joined #openstack-keystone22:01
*** jdennis1 has quit IRC22:01
*** jdennis has joined #openstack-keystone22:01
*** thorst has quit IRC22:01
lbragstadgagehugo: samueldmq opened https://bugs.launchpad.net/keystone/+bug/1701389 as a result22:01
openstackLaunchpad bug 1701389 in OpenStack Identity (keystone) "Security compliance documentation in admin-guide is out of date" [High,Triaged]22:01
gagehugolbragstad I can pick that up if no one else is dying to do it22:05
lbragstadgagehugo: all yours if you want it :)22:05
*** aojea has quit IRC22:05
lbragstadgagehugo: it falls in line with all the documentation work we're doing, too22:06
gagehugolbragstad yup22:06
lbragstadwe effectively have to take the relevant bits from https://docs.openstack.org/developer/keystone/advanced-topics/security_compliance.html and move it into https://docs.openstack.org/developer/keystone/admin/identity-security-compliance.html22:06
lbragstadand make sure https://docs.openstack.org/developer/keystone/admin/identity-security-compliance.html is up to date22:07
lbragstadthen remove https://docs.openstack.org/developer/keystone/advanced-topics/security_compliance.html22:07
lbragstadthat sounds like a lot of work, but it could all be done in a single patch set as far as i'm concerned22:07
lbragstadi don't see a reason not to anyway22:07
gagehugook22:08
lbragstadgagehugo: thanks for picking it up, i appreciate it22:08
gagehugonp!22:10
lbragstadhere's an easy federated review - https://review.openstack.org/#/c/479026/22:18
*** ducttape_ has joined #openstack-keystone22:30
*** jmlowe has joined #openstack-keystone22:31
*** ducttap__ has quit IRC22:33
lbragstadalright - stepping away for a bit22:53
*** jamielennox has quit IRC22:57
*** jamielennox has joined #openstack-keystone23:03
*** ducttape_ has quit IRC23:12
*** johnthetubaguy has quit IRC23:18
openstackgerritJaewoo Park proposed openstack/keystone master: WIP: Add project tags  https://review.openstack.org/47031723:27
*** johnthetubaguy has joined #openstack-keystone23:28
openstackgerritJaewoo Park proposed openstack/keystone master: WIP: Add project tags  https://review.openstack.org/47031723:30
*** thorst has joined #openstack-keystone23:32
*** thorst has quit IRC23:37
samueldmqnishaYadav has a post in OpenStack superuser about mentoring23:40
samueldmqshe was our mentee last year for Outreachy23:40
samueldmq#link http://superuser.openstack.org/articles/tips-mentor-openstack/23:40
samueldmq:)23:40
*** enriquetaso_ has joined #openstack-keystone23:42
samueldmqlbragstad: yes I think it makes sense, I will try to reproduce that tomorrow morning, but I guess somehting was weird in my environment23:46
samueldmqlbragstad: it's worth giving another try, at least to figure out what I was doing wrong23:46
*** rderose has quit IRC23:47
samueldmqalso, I think I can pick up that bug about documenting PCI. I spent some time on it, so shouldn't be too hard23:47
*** dougshelley66 has quit IRC23:50
*** ducttape_ has joined #openstack-keystone23:51
*** ducttape_ has quit IRC23:55
*** phalmos_ has quit IRC23:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!