Wednesday, 2018-02-21

*** openstackstatus has quit IRC00:12
*** openstackstatus has joined #openstack-keystone00:14
*** ChanServ sets mode: +v openstackstatus00:14
*** AlexeyAbashkin has joined #openstack-keystone00:23
*** AlexeyAbashkin has quit IRC00:27
*** lbragstad has quit IRC00:32
*** d0ugal_ has joined #openstack-keystone00:48
*** daidv has joined #openstack-keystone00:51
*** dave-mccowan has joined #openstack-keystone01:06
*** rcernin has quit IRC01:36
*** rcernin has joined #openstack-keystone01:36
*** rcernin has quit IRC01:42
*** rcernin has joined #openstack-keystone01:43
*** sapd has joined #openstack-keystone01:51
*** rcernin has quit IRC01:53
*** rcernin has joined #openstack-keystone01:53
*** annp has joined #openstack-keystone02:28
*** harlowja_ has quit IRC02:28
*** links has joined #openstack-keystone02:49
*** oikiki_ has quit IRC03:04
*** AlexeyAbashkin has joined #openstack-keystone03:23
*** AlexeyAbashkin has quit IRC03:27
*** lbragstad has joined #openstack-keystone03:43
*** ChanServ sets mode: +o lbragstad03:43
*** gongysh has joined #openstack-keystone04:05
*** d0ugal__ has joined #openstack-keystone04:12
*** d0ugal_ has quit IRC04:15
*** AlexeyAbashkin has joined #openstack-keystone04:22
*** annp has quit IRC04:23
*** annp has joined #openstack-keystone04:23
*** AlexeyAbashkin has quit IRC04:26
*** dave-mccowan has quit IRC04:34
*** gyee has quit IRC05:27
*** lbragstad has quit IRC05:28
*** gongysh has quit IRC05:54
*** d0ugal__ has quit IRC06:27
*** d0ugal__ has joined #openstack-keystone06:32
*** nixi_girl has joined #openstack-keystone06:49
*** d0ugal__ has quit IRC06:52
*** nixi_girl has quit IRC07:00
*** narcis has joined #openstack-keystone07:02
*** nixi_girl has joined #openstack-keystone07:08
*** narcis has quit IRC07:21
*** rcernin has quit IRC07:21
*** hoonetorg has quit IRC07:46
*** pcaruana has joined #openstack-keystone07:47
*** usr2033 has joined #openstack-keystone07:53
usr2033hi07:53
usr2033i have a problem about policy.v3cloudsample.json file. Can anyone help?07:54
*** d0ugal has joined #openstack-keystone07:55
*** d0ugal has quit IRC07:55
*** d0ugal has joined #openstack-keystone07:55
*** mancdaz has quit IRC07:57
*** mancdaz_ has joined #openstack-keystone07:58
*** mancdaz_ is now known as mancdaz07:58
*** hoonetorg has joined #openstack-keystone08:00
*** d0ugal has quit IRC08:00
*** d0ugal has joined #openstack-keystone08:01
*** d0ugal has quit IRC08:06
*** d0ugal has joined #openstack-keystone08:15
*** sapd_ has joined #openstack-keystone08:17
*** sapd_ has quit IRC08:17
*** AlexeyAbashkin has joined #openstack-keystone08:22
*** d0ugal has quit IRC08:29
*** tesseract has joined #openstack-keystone08:34
*** d0ugal has joined #openstack-keystone08:34
*** d0ugal has quit IRC08:39
*** d0ugal has joined #openstack-keystone08:48
*** d0ugal has quit IRC08:48
*** d0ugal has joined #openstack-keystone08:48
*** nixi_girl has quit IRC08:56
*** d0ugal has quit IRC08:58
*** d0ugal has joined #openstack-keystone09:07
*** openstackgerrit has joined #openstack-keystone09:43
openstackgerritMerged openstack/keystone master: Remove v2.0 policies  https://review.openstack.org/54642009:43
*** daidv has quit IRC09:58
*** pcaruana has quit IRC10:05
*** d0ugal_ has joined #openstack-keystone10:06
*** d0ugal has quit IRC10:06
*** d0ugal_ has quit IRC10:11
*** d0ugal_ has joined #openstack-keystone10:13
*** d0ugal__ has joined #openstack-keystone10:17
*** d0ugal_ has quit IRC10:18
*** pcaruana has joined #openstack-keystone10:20
*** annp has quit IRC10:25
*** d0ugal__ has quit IRC10:54
*** d0ugal has joined #openstack-keystone10:54
*** d0ugal has quit IRC10:54
*** d0ugal has joined #openstack-keystone10:54
*** pcaruana has quit IRC11:19
*** d0ugal has quit IRC11:23
*** d0ugal has joined #openstack-keystone11:30
*** pcaruana has joined #openstack-keystone11:33
*** d0ugal has quit IRC12:06
*** d0ugal has joined #openstack-keystone12:10
*** gongysh has joined #openstack-keystone12:12
*** gongysh has quit IRC12:13
*** raildo has joined #openstack-keystone12:13
*** jmlowe has quit IRC12:18
*** jmlowe has joined #openstack-keystone12:18
*** mgagne has quit IRC12:19
*** d0ugal has quit IRC12:20
*** d34dh0r53 has quit IRC12:20
*** chris_hultin has quit IRC12:20
*** evrardjp has quit IRC12:22
*** d0ugal has joined #openstack-keystone12:22
*** evrardjp has joined #openstack-keystone12:26
*** d34dh0r53 has joined #openstack-keystone12:26
*** d0ugal has quit IRC12:34
*** mgagne has joined #openstack-keystone12:36
*** mgagne is now known as Guest2094612:36
*** chris_hultin|AWA has joined #openstack-keystone12:38
*** chris_hultin|AWA is now known as chris_hultin12:39
*** melwitt has quit IRC12:47
*** melwitt has joined #openstack-keystone12:52
*** Supun has joined #openstack-keystone13:06
*** dave-mccowan has joined #openstack-keystone13:08
*** d0ugal has joined #openstack-keystone13:13
*** d0ugal_ has joined #openstack-keystone13:19
*** d0ugal has quit IRC13:20
*** d0ugal_ has quit IRC13:25
*** d0ugal_ has joined #openstack-keystone13:38
*** d0ugal_ has quit IRC13:48
*** d0ugal has joined #openstack-keystone13:48
*** d0ugal has quit IRC13:48
*** d0ugal has joined #openstack-keystone13:48
*** d0ugal has quit IRC13:58
*** d0ugal has joined #openstack-keystone13:59
*** jdennis has quit IRC14:00
*** d0ugal has quit IRC14:04
*** lbragstad has joined #openstack-keystone14:15
*** ChanServ sets mode: +o lbragstad14:15
lbragstadusr2033 are you still having some issues with policy.v3cloudsample?14:17
*** d0ugal has joined #openstack-keystone14:22
*** links has quit IRC14:29
*** panbalag has joined #openstack-keystone14:34
openstackgerritMerged openstack/ldappool master: Updated from global requirements  https://review.openstack.org/53846514:34
*** dmellado has quit IRC14:37
*** dmellado has joined #openstack-keystone14:42
*** d0ugal has quit IRC14:49
openstackgerritMerged openstack/keystone-tempest-plugin master: Updated from global requirements  https://review.openstack.org/53631214:53
*** d0ugal has joined #openstack-keystone14:57
*** spilla has joined #openstack-keystone15:03
*** usr2033 has quit IRC15:08
*** dklyle has joined #openstack-keystone15:15
*** david-lyle has quit IRC15:16
*** itlinux has joined #openstack-keystone15:26
openstackgerritGage Hugo proposed openstack/keystone master: Add functional testing gate  https://review.openstack.org/53101415:31
gagehugoo/15:33
openstackgerritMerged openstack/python-keystoneclient master: Updated from global requirements  https://review.openstack.org/53716415:43
*** r-daneel has joined #openstack-keystone15:54
knikollao/15:57
*** r-daneel_ has joined #openstack-keystone16:01
*** r-daneel has quit IRC16:02
*** r-daneel_ is now known as r-daneel16:02
m3m0following the instructions here: https://docs.openstack.org/keystone/queens/install/keystone-install-ubuntu.html, when I run apt install keystone, is there a way to make it non-interactive? it ask me for a database configuration16:07
gagehugom3m0 Is that the mysql password prompts?16:12
knikollawas thinking the same, but it doesn't look like installing keystone installs mysql.16:14
knikollajust tried it now. Didn't ask me for anything while apt installing. Are you referring to the database config section of /etc/keystone/keystone.conf?16:16
*** pcaruana has quit IRC16:16
*** openstackgerrit has quit IRC16:19
lbragstadcmurphy i know i asked you this already, but you have an idea of what you want to go over for the cross-project application credentials session, yeah?16:19
cmurphylbragstad: um not really actually16:20
cmurphyi guess i imagined a bit of q&a and a bit of "what would you like to see"16:21
cmurphyfine-grained access control is the obvious thing16:21
cmurphyit's not that critical of a session now that the base feature is there16:22
lbragstadcmurphy ok - so we can just stage it for a short q&a type thing and if it evolves into something else that's fine16:23
lbragstadattempting to flesh it out here - https://etherpad.openstack.org/p/application-credentials-rocky-ptg16:25
*** kukacz_ has joined #openstack-keystone16:26
knikollayeah, i think we should spend some time talking about fine grained access. maybe could be tied to the discussion about rbac and default roles.16:26
lbragstadthey are closely related16:28
lbragstadfor some reason, our discussions always seem to come full circle lol16:29
*** kukacz_ is now known as kukacz16:29
knikollamore like spiral, cause after every revolution we get a little closer.16:29
knikollahypnotizing.16:29
lbragstadpsh - no wonder i'm so dizzy all the time16:30
mnaseri'm trying to troubleshoot an issue that comes up from time to time in puppet-openstack ci .. "This is not a recognized Fernet token"16:30
mnasertempest tests all run with no problems... but from time to time, a request will be accepted by nova for a new server, then it will try to contact neutron to get list of security groups, but neutron responds with a 40116:31
mnaserand in the neutron logs, keystone says the token ain't good, and keystone logs show the 40116:31
mnaser"TokenNotFound: This is not a recognized Fernet token gAAAAABajZJB2pixOrz1RPc_RATriy4CLp1abIDZMI8i9tYNCHmibVCOQIWjGv9r71lFNI2auP1qhb5pDn9ZrUP8f9BpoayI1l6hVO3avfNTQEWnS4xrpDgRjUQFZRmJtTMppawUzkEdYfapFJHlrtKlTgLHSSsHRwS-ca9Ofg8M5WEPdqBx8m0=" .. any idea what could be causing this?16:31
lbragstadmnaser we raise that exception in one place16:31
lbragstadwhich is handling an InvalidToken exception from the library that actually does the encryption/decryption bits for us16:32
mnaserlbragstad: ok i see it here indeed https://github.com/openstack/keystone/blob/68df7bf1f3b3d6ab3f691f59f1ce6de6b0b1deab/keystone/token/token_formatters.py#L81-L9416:32
lbragstadwhich mean, if that exception is getting thrown, then it's could be a key is missing or the token was tampered with in such a way the cryptography library can't make sense of it16:33
mnaserits interesting you say this16:33
mnaseri saw something in the syslogs16:33
lbragstadyep - that's the stop16:33
lbragstadspot*16:33
mnaser(in around the same time frame-ish)16:33
mnaserah it might be unrelated16:33
mnaser"UnicodeDecodeError: 'ascii' codec can't decode byte 0x80 in position 33: ordinal not in range(128)"16:33
lbragstadmmm16:34
mnaserthrown by nova processes inside oslo_log16:34
lbragstadah - ok16:34
lbragstadis disk utilization fine on the host?16:34
mnaserhttp://logs.openstack.org/40/546440/1/gate/puppet-openstack-integration-4-scenario001-tempest-centos-7/8f765c2/logs/df.txt.gz16:34
mnaser11% USED16:34
lbragstadyou're not running out of disk space in the middle of a rotation, then16:34
mnaserOH HOLD ON16:35
mnaseroops caps16:35
mnaserhttp://logs.openstack.org/40/546440/1/gate/puppet-openstack-integration-4-scenario001-tempest-centos-7/8f765c2/logs/etc/keystone/fernet-keys/16:35
mnaser5 6 716:35
mnaseri wonder if maybe something is rotating keys...16:35
*** AlexeyAbashkin has quit IRC16:35
mnaserthe job takes less than an hour to run16:35
lbragstadmnaser how long is this host up?16:35
mnaserand we have a 40 minute token expiration in the gate16:35
lbragstad\ok16:35
lbragstadso...16:35
lbragstadhow often is the key rotation happening?16:35
mnaser2018-02-21 15:30:02 +0000 /Stage[main]/Keystone::Cron::Fernet_rotate/Cron[keystone-manage fernet_rotate]/ensure (notice): created16:36
mnaserlet me see16:36
mnaserevery 5 minutes.16:36
mnaserhttps://github.com/openstack/puppet-openstack-integration/blob/master/manifests/keystone.pp#L51-L5416:36
mnaserheh16:36
lbragstadhow many keystone hosts are there?16:36
mnaserlbragstad: only 116:36
lbragstadlol16:36
mnaserbut we have memcache in there16:36
mnaserso im gonna guess nova keeps the token cached for 40 minutes16:37
lbragstadso - tokens are valid for 40 minutes?16:37
mnaserbut rotating every 5 minutes means all tokens are invalid at 15 minutes16:37
lbragstadbut encryption keys are being rotated every 5 minutes16:37
mnaserour tempest runs last 15 minutes (barely)16:37
lbragstadyep - exactly16:37
mnaserwhich explains why we hit it sometimes and sometimes we didn't lol16:37
lbragstadright16:37
lbragstadyou should bump you max_active_key setting16:37
lbragstadyour*16:38
lbragstadhttps://github.com/openstack/keystone/blob/master/keystone/conf/fernet_tokens.py#L44-L5416:38
mnaserlbragstad: max_active_key = 5 + every 10 minutes should be good for a 40 minute token right?16:38
mnaserso if our rotations mess up, it'll be caught in the tempest runs i guess16:39
lbragstadyeah - if rotation happens every 10 minutes, 5 keys should cover you16:39
lbragstadbut ideally, you'll want to factor in your token expiration time16:39
mnaserlbragstad: thank you so much!  this was quite a hassle in the gate with the intermittent timeouts16:40
lbragstadi think it would be the token expiration (in minutes) / the intervals of key rotation (in minutes)16:40
mnaser#thanks lbragstad for helping troubleshoot an intermittent fernet token validation failure in puppet gates16:40
openstackstatusmnaser: Added your thanks to Thanks page (https://wiki.openstack.org/wiki/Thanks)16:40
lbragstadwoot16:41
lbragstadanytime mnaser :)16:41
mnaserlbragstad: agreed but i would +1 on interval too16:41
lbragstadyeah - the extra buffer can't hurt16:41
mnaserbecause cronjobs dont really run at the start of token allocation16:41
mnaserso if you're running at :10 and :20 you might have your token expire if you got it exactly a minute before cronjob or so16:41
lbragstadand keystone-manage fernet_rotate will obviously keep the disk clean once you reach the max_active_key limit16:41
* mnaser wonders why clients dont retry once at least when they get a 40116:42
lbragstad++16:42
mnaserif token_not_valid: grab_new_token -> retry else -> fail .. should fix all of those weird caching issues etc16:42
mnaserbut oh well16:42
*** r-daneel_ has joined #openstack-keystone16:43
lbragstadhttps://twitter.com/_mnaser/status/87079688205810483216:44
lbragstadthat just reminded me of ^16:44
*** jdennis has joined #openstack-keystone16:44
*** r-daneel has quit IRC16:44
*** r-daneel_ is now known as r-daneel16:44
mnaserlbragstad: its always funny when you see old things you've said still make sense now16:46
mnaserlbragstad: i find this happen a lot when i go over old code .. thinking about how to do it in some better way and finding out that's how i did it in the first place after going over it lol16:46
*** panbalag has quit IRC16:47
*** panbalag has joined #openstack-keystone16:48
lbragstad:)16:48
*** gyee has joined #openstack-keystone17:04
*** dklyle has quit IRC17:08
kmalloc.... man my hands hurt. stupid sudden cold with high humidity.17:14
kmallocmnaser: clients SHOULD retry ;)17:16
kmallocbut many people do the naive implementation.17:16
kmallocand explode on failure.17:16
kmalloceven reasonable/valid failure modes that justify a retry17:17
*** eEbx has joined #openstack-keystone17:19
*** oikiki has joined #openstack-keystone17:21
*** dikonoor has joined #openstack-keystone17:27
dikonoorcmurphy: Hi . Would you be able to take a look at https://bugs.launchpad.net/openstack-requirements/+bug/1750843 when you get a chance ?17:27
openstackLaunchpad bug 1750843 in OpenStack Global Requirements "pysaml2 version in global requirements must be updated to 4.5.0" [Undecided,New]17:27
eEbxHey guys, I would like to ask you if anyone of you has relevant keystone benchmark tests. I would like to know if 200ms to get/validate token is ok.17:28
dikonoorcmurphy: Defects need inputs from someone who knows Keystone Federation17:28
dikonoorand how it uses the pysaml2 apis17:28
dikonoorlbragstad: If you or cmurphy could take a look, that would be great..https://bugs.launchpad.net/openstack-requirements/+bug/175084317:29
openstackLaunchpad bug 1750843 in OpenStack Global Requirements "pysaml2 version in global requirements must be updated to 4.5.0" [Undecided,New]17:29
*** Supun has quit IRC17:38
lbragstaddikonoor checking17:40
*** dikonoor has quit IRC17:41
*** david-lyle has joined #openstack-keystone17:41
*** itlinux has quit IRC17:46
*** AlexeyAbashkin has joined #openstack-keystone17:57
*** AlexeyAbashkin has quit IRC18:01
*** openstackgerrit has joined #openstack-keystone18:01
openstackgerritLance Bragstad proposed openstack/keystone master: Update 3.10 versioning to reflect system scope changes  https://review.openstack.org/54671618:01
lbragstad^ another thing we'll probably have to backport18:01
lbragstadi swear that was noted in the implementation but apparently not18:02
*** narcis has joined #openstack-keystone18:03
*** narcis has quit IRC18:03
lbragstadknikolla you all do k2k right?18:11
lbragstadeEbx the answer depends on how you have keystone configured18:12
lbragstadit can vary depending on how things are setup18:12
knikollalbragstad: yes, but not on production yet.18:13
lbragstadknikolla ok - so do you have keystone setup as an idp somewhere?18:13
lbragstadand you authenticate to it for saml assertions that you give to the service provider keystone?18:14
knikollaYes18:14
knikollaThere’s an api call for keystone that gives back signed saml18:14
eEbxlbragstad: two keystone servers with nginx load balancer, db is 5 node gallera cluster18:14
knikollaYou send that to sp keystone’s shibboleth18:14
lbragstadknikolla the saml assertion is only generated from information in keystone, right? there isn't a way for someone to authenticate for a saml assert and provide some extra XML to inject into the assertion is there?18:15
lbragstadeEbx do you have caching configured?18:15
lbragstador memcache servers that are configured to work with keystone?18:15
knikollaNo, it’s a get call with no params18:15
lbragstadknikolla ack - thank you18:15
lbragstadknikolla i'm going to paraphrase you in https://bugs.launchpad.net/openstack-requirements/+bug/175084318:16
openstackLaunchpad bug 1750843 in OpenStack Global Requirements "pysaml2 version in global requirements must be updated to 4.5.0" [Undecided,New]18:16
lbragstad:)18:16
eEbxyes I have memcache servers configured18:16
knikollaWhat info are you looking to put in there?18:16
lbragstadi'm not, but there appears to be a security issue with pysaml218:16
lbragstadspecifically when a user has the ability to pass data to the thing that generates the assertions18:16
lbragstadwhich doesn't sound like it affects us18:16
kmallocoh, fun18:16
kmalloclet me take a look at that18:16
knikollaWe don’t parse xml, shibboleth/mellon does that for us18:17
knikollaWe merely generate and sign it18:18
kmallocthat shouldn't ever effect us18:18
kmallocbut.18:18
kmallocfor sake of forward looking safe18:18
kmallocwe should update18:18
kmalloci can't believe people use assert for anything outside of testing/non-critical errors18:19
kmallocexpect assert wont fire before using it.18:19
kmallocwe probably should evaluate assert usages in keystone (we might have some lingering ones that are similar)18:19
lbragstadok - updated with a comment18:21
lbragstadeEbx do you know if you're caching tokens?18:22
kmalloclbragstad: haha i just commented too on it :P18:22
lbragstadnice!18:22
kmalloc200ms seems a little slow (eEbx) but i haven't done recent testing.18:22
lbragstadeEbx 200 ms is on par if you're generating the token (without caching) on every request18:23
kmalloc++18:23
lbragstadwithout knowing what hardware you're running on, i would expect utilization of memcache to drastically improve that18:23
*** tesseract has quit IRC18:25
kmallocyeah18:25
kmallocit also depends on the load of the DB (is it used for other applciations? if so, what is the general io latency on it for lookups)18:25
kmallocalso, what is the concurrency of token issuance / validation18:26
*** r-daneel_ has joined #openstack-keystone18:31
lbragstadlol thanks kmalloc and cmurphy for commenting on that bug :)18:31
*** r-daneel has quit IRC18:32
*** r-daneel_ is now known as r-daneel18:32
cmurphyglad to know i wasn't wildly off base :)18:36
lbragstadfantastic response time18:40
* lbragstad steps away for lunch18:40
*** panbalag has quit IRC19:08
*** itlinux has joined #openstack-keystone19:19
*** AlexeyAbashkin has joined #openstack-keystone19:21
*** AlexeyAbashkin has quit IRC19:25
*** lbragstad has quit IRC19:40
*** lbragstad has joined #openstack-keystone20:01
*** ChanServ sets mode: +o lbragstad20:01
openstackgerritLance Bragstad proposed openstack/keystone master: Update 3.10 versioning to limits and system scope  https://review.openstack.org/54671620:12
lbragstadcc gagehugo ^ '20:12
gagehugolbragstad I like the experimental note20:13
lbragstadfigured we should add the limit stuff in there, too20:13
lbragstadi'll propose a backport20:13
lbragstaddone - https://review.openstack.org/54676220:14
*** lbragstad has quit IRC20:29
*** lbragstad has joined #openstack-keystone20:30
*** ChanServ sets mode: +o lbragstad20:30
*** lbragstad has quit IRC20:32
*** lbragstad has joined #openstack-keystone20:33
*** ChanServ sets mode: +o lbragstad20:33
lbragstadin case folks haven't seen it yet - http://lists.openstack.org/pipermail/openstack-dev/2018-February/127611.html20:40
lbragstadit looks like the PTG feedback session is going to be at the same time we were planning on having our retrospective20:41
lbragstadgame night is also on thursday20:41
lbragstadfyi - i was thinking about bringing some games - would anyone be interested?20:41
*** belmoreira has joined #openstack-keystone20:43
*** rmascena has joined #openstack-keystone20:57
*** dave-mccowan has quit IRC21:00
*** raildo has quit IRC21:00
*** rmascena__ has joined #openstack-keystone21:01
*** openstackgerrit has quit IRC21:03
*** rmascena has quit IRC21:05
cmurphyi would game with y'all21:06
lbragstadthere's gonna be so much to do on thursday21:11
lbragstadbut i can bring the resistance, dutch blitz, and exploding kittens21:13
* lbragstad double checks the game cabinet21:20
*** oikiki has quit IRC21:21
lbragstadyeah - those are the travel friendly games i have21:21
cmurphy:D21:24
gagehugosure21:24
gagehugoI think I have the oregon trail card game as well21:25
*** oikiki has joined #openstack-keystone21:25
lbragstadoh - that one is fun21:26
lbragstadnostalgia in a deck of cards21:26
*** belmoreira has quit IRC21:37
mnaserlbragstad: anyone say nostalgia? https://review.openstack.org/#/c/7464/ :P21:40
mnaserbut also i've been digging in my emails/launchpad to find the bug regarding admin-ness with v3 domains.. anyone know where that one is tracked or has a link around?21:41
*** bhagyashris has quit IRC21:44
lbragstadmnaser hah - like the v3.samplepolicy bug?21:45
mnaserlbragstad: yes, i think it ended up being marked as a dup of another one21:45
lbragstadi think i know which one you're talking about21:46
lbragstadchecking21:49
*** rmascena__ has quit IRC21:53
*** dmellado has quit IRC22:00
*** openstackgerrit has joined #openstack-keystone22:02
openstackgerritGage Hugo proposed openstack/keystone master: Handle empty token key files  https://review.openstack.org/54678522:02
lbragstadkmalloc do you want to kick this through https://review.openstack.org/#/c/546762/ ?22:05
openstackgerritMerged openstack/keystone master: Update 3.10 versioning to limits and system scope  https://review.openstack.org/54671622:06
lbragstadmnaser isn't not this one is it?22:06
mnaserlbragstad: are you talking about the changes above ^ ?22:08
lbragstadmnaser sorry - forgot to paste22:08
lbragstadhttps://bugs.launchpad.net/keystone/+bug/163043422:08
openstackLaunchpad bug 1630434 in OpenStack Identity (keystone) "policy.v3cloudsample.json doesn't allow domain admin list role assignments on project" [Medium,Triaged]22:08
mnaserlbragstad: oh yeah something similar, the one i had reported had a whole bunch of discussion if i remember22:09
mnaseri cant find it.. i have no idea why22:09
mnaserhttps://bugs.launchpad.net/keystone/+bug/168432022:10
openstackLaunchpad bug 968696 in OpenStack Identity (keystone) "duplicate for #1684320 "admin"-ness not properly scoped" [High,In progress] - Assigned to Adam Young (ayoung)22:10
mnaserahh yes combined with https://bugs.launchpad.net/keystone/+bug/96869622:10
openstackLaunchpad bug 968696 in OpenStack Identity (keystone) ""admin"-ness not properly scoped" [High,In progress] - Assigned to Adam Young (ayoung)22:10
lbragstadmnaser this is the one you reported - https://bugs.launchpad.net/keystone/+bug/168432022:12
openstackLaunchpad bug 968696 in OpenStack Identity (keystone) "duplicate for #1684320 "admin"-ness not properly scoped" [High,In progress] - Assigned to Adam Young (ayoung)22:12
mnaserah yes22:13
lbragstadaha - yep - just missed that like22:13
lbragstadlink*22:13
mnaseri guess when its marked as duplicate it disappers22:13
lbragstadsearch queries in lp have a toggle for it22:13
lbragstadapparently22:14
mnaserlbragstad: maybe it would be nice as a ptg topic to follow up on this (perhaps an openstack-wide goal..)22:14
lbragstad++22:14
lbragstadhttps://etherpad.openstack.org/p/keystone-rocky-ptg22:14
lbragstadhttps://etherpad.openstack.org/p/baremetal-vm-rocky-ptg22:15
lbragstadand finally - https://etherpad.openstack.org/p/rbac-and-policy-rocky-ptg22:15
lbragstadmnaser we have a session dedicated to it on tuesday morning22:16
mnaserlbragstad: oh cool i'll try to be there22:18
*** spilla has quit IRC22:24
*** itlinux has quit IRC22:29
*** rcernin has joined #openstack-keystone22:32
*** r-daneel has quit IRC22:40
*** lbragstad has quit IRC22:47
*** lbragstad has joined #openstack-keystone22:47
*** ChanServ sets mode: +o lbragstad22:47
*** oikiki has quit IRC23:05
*** oikiki has joined #openstack-keystone23:06
gagehugohttps://bugs.launchpad.net/keystone/+bug/1735250 confuses me a bit23:08
openstackLaunchpad bug 1735250 in OpenStack Identity (keystone) queens "Password column limit (128 char) in the Password table exceeded when using passwords exceeding 2000 characters" [High,Confirmed]23:08
lbragstadgagehugo that's because we hash the passwords23:14
lbragstadso when you pass keystone a password over 2k, the hash will exceed the limit of the password hash table23:14
gagehugolbragstad I don't understand why password.expression would ever have the non-hashed version23:14
gagehugobut that is likely sqla wizardry that I don't completely understand23:14
lbragstadohh23:16
lbragstadyeah,,,23:16
lbragstadit does have something to do with how hybrid_property works23:16
lbragstadkmalloc and i were discussing that in irc one day23:16
kmallocbtw, that is a documented limitation (iirc) in the password system23:17
kmallocbecause of issues with how the password column works23:17
kmalloclet me read the bug.23:17
kmallocbut... it's wonky23:17
lbragstadit's been a while since i've dug into that23:17
lbragstadgotta run to an appt quick, i'll be on later though23:17
kmallocoh wait. i think there WAS a bug on this23:18
kmallocand we fixed it.23:18
kmallocah the silly password.Password23:19
kmallocthing23:19
kmallocoh we didn't fix this.23:19
kmalloci think the solution is just deleting the @password.expression23:20
kmalloci can roll up some code for that... today or tomrorow23:21
kmallocbut like i said, i think the fix is just dropping @password.expression def.23:22
gagehugohmm23:30
openstackgerritGage Hugo proposed openstack/keystone master: Handle empty token key files  https://review.openstack.org/54678523:34

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!