Tuesday, 2018-04-10

*** gyee has quit IRC00:11
*** zhurong has joined #openstack-keystone00:20
*** odyssey4me has quit IRC00:34
*** odyssey4me has joined #openstack-keystone00:34
*** chenyb4 has joined #openstack-keystone00:47
*** germs has joined #openstack-keystone00:56
*** germs has quit IRC00:56
*** germs has joined #openstack-keystone00:56
*** namnh has joined #openstack-keystone02:08
*** dave-mccowan has joined #openstack-keystone02:11
*** germs has quit IRC02:22
*** germs has joined #openstack-keystone02:22
*** germs has quit IRC02:22
*** germs has joined #openstack-keystone02:22
*** germs has quit IRC02:23
*** r-daneel has joined #openstack-keystone02:36
*** dave-mccowan has quit IRC02:48
*** harlowja has quit IRC03:16
*** sonuk has joined #openstack-keystone03:30
*** zhurong has quit IRC03:41
*** harlowja has joined #openstack-keystone03:57
*** marius1 has joined #openstack-keystone04:00
*** pcaruana has joined #openstack-keystone04:06
*** marius1 has quit IRC04:09
*** pcaruana has quit IRC04:16
*** germs has joined #openstack-keystone04:23
*** germs has quit IRC04:23
*** germs has joined #openstack-keystone04:23
*** pcichy has joined #openstack-keystone04:24
*** sonuk has quit IRC04:24
*** annp has quit IRC04:25
*** sonuk has joined #openstack-keystone04:25
*** annp has joined #openstack-keystone04:25
*** germs has quit IRC04:29
*** dikonoor has joined #openstack-keystone05:08
*** links has joined #openstack-keystone05:11
*** pcichy has quit IRC05:25
*** dikonoor has quit IRC05:37
*** dikonoor has joined #openstack-keystone05:37
*** pcichy has joined #openstack-keystone05:39
*** germs has joined #openstack-keystone05:47
*** germs has quit IRC05:47
*** germs has joined #openstack-keystone05:47
*** marius1 has joined #openstack-keystone05:47
*** germs has quit IRC05:51
*** belmoreira has joined #openstack-keystone06:00
*** jaosorior has quit IRC06:04
*** namnh has quit IRC06:18
*** AlexeyAbashkin has joined #openstack-keystone06:32
*** jaosorior has joined #openstack-keystone06:37
*** pcaruana has joined #openstack-keystone06:40
*** harlowja has quit IRC06:40
*** rcernin has quit IRC06:41
*** martinus__ has joined #openstack-keystone06:44
*** AlexeyAbashkin has quit IRC06:49
*** AlexeyAbashkin has joined #openstack-keystone06:50
*** AlexeyAbashkin has quit IRC06:54
openstackgerritwangxiyuan proposed openstack/keystonemiddleware master: Double quote www_authenticate_uri  https://review.openstack.org/55992507:00
*** AlexeyAbashkin has joined #openstack-keystone07:02
*** tesseract has joined #openstack-keystone07:19
*** jaosorior has quit IRC07:23
*** jaosorior has joined #openstack-keystone07:27
*** dikonoo has joined #openstack-keystone07:30
*** dikonoor has quit IRC07:30
*** jhesketh_ has joined #openstack-keystone07:31
*** dangtrinhnt has joined #openstack-keystone07:33
*** jhesketh has quit IRC07:37
*** hoonetorg has quit IRC07:38
*** belmoreira has quit IRC07:43
*** germs has joined #openstack-keystone07:48
*** germs has quit IRC07:48
*** germs has joined #openstack-keystone07:48
*** hoonetorg has joined #openstack-keystone07:52
*** germs has quit IRC07:53
*** AlexeyAbashkin has quit IRC07:53
*** AlexeyAbashkin has joined #openstack-keystone07:56
*** dangtrinhnt has quit IRC08:13
*** mvk has quit IRC08:28
*** mvk has joined #openstack-keystone08:58
*** belmoreira has joined #openstack-keystone09:03
*** pcaruana has quit IRC09:04
*** links has quit IRC09:18
*** dikonoo has quit IRC09:20
*** mvk has quit IRC09:33
*** links has joined #openstack-keystone09:33
*** mvk has joined #openstack-keystone09:46
*** germs has joined #openstack-keystone09:49
*** germs has quit IRC09:49
*** germs has joined #openstack-keystone09:49
*** germs has quit IRC09:53
*** marius1 has quit IRC10:41
*** chenyb4 has quit IRC10:49
*** sonuk has quit IRC11:17
*** links has quit IRC11:26
*** sonuk has joined #openstack-keystone11:28
*** links has joined #openstack-keystone11:40
*** markvoelker has joined #openstack-keystone11:40
*** zhurong has joined #openstack-keystone11:54
*** marius1 has joined #openstack-keystone11:59
*** odyssey4me has quit IRC12:00
*** odyssey4me has joined #openstack-keystone12:00
*** openstackgerrit has quit IRC12:04
*** sonuk has quit IRC12:11
*** raildo has joined #openstack-keystone12:17
*** edmondsw has joined #openstack-keystone12:17
*** dave-mccowan has joined #openstack-keystone12:19
*** edmondsw has quit IRC12:28
*** openstackgerrit has joined #openstack-keystone12:29
openstackgerritJohannes Grassler proposed openstack/keystone-specs master: Add capabilities to application credentials  https://review.openstack.org/39633112:29
*** spilla has joined #openstack-keystone12:32
*** marius1 has quit IRC12:36
*** panbalag has joined #openstack-keystone12:37
*** marius1 has joined #openstack-keystone12:37
*** pcaruana has joined #openstack-keystone12:44
*** panbalag has left #openstack-keystone12:45
*** chenyb4 has joined #openstack-keystone12:46
*** jaosorior has quit IRC12:50
*** edmondsw has joined #openstack-keystone12:51
*** zhurong has quit IRC12:54
*** zhurong has joined #openstack-keystone12:59
*** chenyb4 has quit IRC13:07
*** zhurong has quit IRC13:13
*** marius1 has quit IRC13:17
*** marius11 has joined #openstack-keystone13:17
*** marius11 has quit IRC13:20
*** marius1 has joined #openstack-keystone13:20
*** dklyle has quit IRC13:33
*** cristicalin has joined #openstack-keystone13:42
*** marius1 has quit IRC13:42
*** lbragstad has joined #openstack-keystone13:42
*** ChanServ sets mode: +o lbragstad13:42
*** cristicalin has quit IRC13:47
*** cristicalin has joined #openstack-keystone13:47
*** awestin1 has quit IRC13:48
*** awestin1 has joined #openstack-keystone13:49
*** betherly has quit IRC13:56
*** betherly has joined #openstack-keystone13:57
*** r-daneel has quit IRC14:02
*** ildikov has quit IRC14:08
*** ildikov has joined #openstack-keystone14:09
*** links has quit IRC14:13
*** mnaser has quit IRC14:15
*** mnaser has joined #openstack-keystone14:16
*** markvoelker_ has joined #openstack-keystone14:18
*** portdirect has quit IRC14:19
*** portdirect has joined #openstack-keystone14:19
*** markvoelker has quit IRC14:21
*** samueldmq has quit IRC14:21
*** samueldmq has joined #openstack-keystone14:21
*** r-daneel has joined #openstack-keystone14:22
*** tommylikehu has quit IRC14:26
*** tommylikehu has joined #openstack-keystone14:26
*** wxy has quit IRC14:27
*** wxy has joined #openstack-keystone14:27
*** dikonoor has joined #openstack-keystone14:28
*** lamt has quit IRC14:29
*** lamt has joined #openstack-keystone14:29
*** lamt is now known as Guest2981014:29
*** knikolla has quit IRC14:30
*** knikolla has joined #openstack-keystone14:30
*** r-daneel has quit IRC14:32
*** r-daneel has joined #openstack-keystone14:35
*** jamespage has quit IRC14:36
*** felipemonteiro has joined #openstack-keystone14:36
*** jamespage has joined #openstack-keystone14:36
*** markvoelker has joined #openstack-keystone14:36
knikollao/14:38
*** markvoelker_ has quit IRC14:39
*** markvoelker_ has joined #openstack-keystone14:42
*** Guest29810 is now known as lamt14:42
*** markvoelker has quit IRC14:44
*** markvoelker has joined #openstack-keystone14:46
*** dklyle has joined #openstack-keystone14:46
gagehugoo/14:47
*** felipemonteiro_ has joined #openstack-keystone14:47
*** markvoelker_ has quit IRC14:49
*** markvoelker_ has joined #openstack-keystone14:49
*** felipemonteiro has quit IRC14:51
*** markvoelker has quit IRC14:53
*** mvk has quit IRC14:53
*** markvoelker has joined #openstack-keystone14:56
*** markvoelker_ has quit IRC14:58
*** wxy| has joined #openstack-keystone15:00
*** markvoelker_ has joined #openstack-keystone15:05
*** markvoelker_ has quit IRC15:08
*** markvoelker has quit IRC15:09
*** markvoelker has joined #openstack-keystone15:10
*** markvoelker_ has joined #openstack-keystone15:10
hrybackio/15:12
*** markvoelker has quit IRC15:15
*** belmoreira has quit IRC15:17
*** r-daneel_ has joined #openstack-keystone15:25
*** r-daneel has quit IRC15:26
*** r-daneel_ is now known as r-daneel15:26
*** gyee has joined #openstack-keystone15:31
*** AlexeyAbashkin has quit IRC15:33
lbragstado/15:35
hrybackilbragstad: FYI I'm gonna be in-and-out all afternoon (tons of meetings I'm getting pulled into today)15:43
lbragstadhrybacki: thanks for the heads up15:44
hrybackiack. I'll be in the weekly meeting though15:45
lbragstadcool15:45
*** AlexeyAbashkin has joined #openstack-keystone15:47
*** thomasduval has joined #openstack-keystone15:51
*** germs has joined #openstack-keystone15:51
*** germs has quit IRC15:51
*** germs has joined #openstack-keystone15:51
*** cristicalin has quit IRC15:52
*** germs has quit IRC15:56
lbragstadreminder that the keystone team meeting is starting in a minute in #openstack-meeting-alt15:59
SamYaplethis might be an olso.log question.. but im noticing when running keystone behind uwsgi that when it spits out the DEBUG running config the name of application is 'uwsgi' in logging15:59
SamYapleon glance, it is 'glance.common.config'15:59
SamYapleso i have to filter for (^keystone|^uwsgi) on keystone, but only (^glance) for glance16:00
*** edmondsw has quit IRC16:00
SamYapleis there anything i can do to get the module to report something a bit more 'keystone' named16:00
*** edmondsw has joined #openstack-keystone16:01
kmallocSamYaple: it is likely uwsgi is configurable16:01
kmallocSamYaple: i haven't looked though16:01
SamYaplekmalloc: my knowledge of uwsgi as relates to python logging approaches zero, do you have a param or option for me to start searching for in uwsgi to control the name?16:02
SamYapleim running glance behind uwsgi as well, same configuration16:03
kmallocah16:03
kmallocyou might need to supply a keystone-specific uwsgi with logging prefix or some such16:03
kmalloci'll look post meeting/lunch16:03
kmallocand see if i can help you. FWIW, I'm setting up an openstack for my home network today, so I'll specifically poke at that16:04
SamYapleok yea, this is really a non-critical issue16:04
SamYapleim just working on openstack logging right now for my company16:05
SamYapleappreciate the comments16:05
openstackgerritMerged openstack/keystone-specs master: Add capabilities to application credentials  https://review.openstack.org/39633116:16
*** eschwartz is now known as anyone16:18
*** timss has quit IRC16:20
*** felipemonteiro_ has quit IRC16:27
*** blake has joined #openstack-keystone16:27
*** felipemonteiro_ has joined #openstack-keystone16:27
gagehugoI should be back after awhile, may not make the rest of the meeting though16:31
*** jessegler has joined #openstack-keystone16:31
*** cristicalin has joined #openstack-keystone16:49
*** felipemonteiro__ has joined #openstack-keystone16:53
*** marius1 has joined #openstack-keystone16:55
*** thomasduval has quit IRC16:57
*** felipemonteiro_ has quit IRC16:57
*** AlexeyAbashkin has quit IRC16:59
*** dikonoor has quit IRC17:00
lbragstad#startmeeting keystone-office-hours17:01
openstacklbragstad: Error: Can't start another meeting, one is in progress.  Use #endmeeting first.17:01
*** blake has quit IRC17:01
lbragstad#endmeeting17:01
*** openstack changes topic to "Rocky release schedule: https://releases.openstack.org/rocky/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/wmyzbFq5/keystone-rocky-roadmap"17:01
openstackMeeting ended Tue Apr 10 17:01:30 2018 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)17:01
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-03-17.01.html17:01
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-03-17.01.txt17:01
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-03-17.01.log.html17:01
lbragstad#startmeeting keystone-office-hours17:01
openstackMeeting started Tue Apr 10 17:01:45 2018 UTC and is due to finish in 60 minutes.  The chair is lbragstad. Information about MeetBot at http://wiki.debian.org/MeetBot.17:01
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.17:01
*** openstack changes topic to " (Meeting topic: keystone-office-hours)"17:01
*** ChanServ changes topic to "Rocky release schedule: https://releases.openstack.org/rocky/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/wmyzbFq5/keystone-rocky-roadmap"17:01
openstackThe meeting name has been set to 'keystone_office_hours'17:01
lbragstadwell - sorry about that17:02
lbragstadi apparently forgot to end the meeting last week17:02
lbragstaddespite my efforts - http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-03-17.01.log.html#l-4117:02
lbragstadmust have been issues it the openstack bot17:03
lbragstadwith*17:03
lbragstadi'll be back in about 15 to 20 minutes17:03
wxy|lbragstad: https://review.openstack.org/#/c/558489/ replied the question for the test code. I'll address other comments tomorrow.17:03
lbragstadwxy|: awesome17:03
lbragstadi'll review the hierarchical limits specs17:03
wxy|thanks17:04
*** wxy| has quit IRC17:05
*** AlexeyAbashkin has joined #openstack-keystone17:07
*** mugsie has joined #openstack-keystone17:10
*** david-lyle has joined #openstack-keystone17:10
mugsieso, random question - I know in the past project IDs could be basically any string ... has that changed? or is project id's being UUIDs just the default so that is all anyone sees?17:11
*** AlexeyAbashkin has quit IRC17:12
*** blake has joined #openstack-keystone17:13
*** itlinux has joined #openstack-keystone17:14
*** dklyle has quit IRC17:14
SamYaplemugsie: my ldap projects are much longer than uuid4s still17:14
mugsieSamYaple: that is what I thought :) just wanted to confirm before blocking a patch :)17:14
mugsiethanks!17:15
*** tesseract has quit IRC17:16
*** annp has quit IRC17:17
*** annp has joined #openstack-keystone17:18
*** cristicalin has quit IRC17:21
*** nicolasbock has joined #openstack-keystone17:24
*** openstackgerrit has quit IRC17:34
*** r-daneel_ has joined #openstack-keystone17:35
*** r-daneel has quit IRC17:36
*** r-daneel_ is now known as r-daneel17:36
kmalloclbragstad: back17:38
kmallocmugsie: Keystone is very opinionated17:38
kmallocmugsie: project_ids are intended to be uuid417:39
kmallocmugsie: legacy stuff that included ldap may not have been limited to uuid417:39
mugsieI knew it was the long term plan, but if there is still people out there using non uuid IDs, I can't allow a patch that enforces it on people17:40
kmallochold on, let me give you our specific table sizes17:40
mugsiei.e. I know the hp public cloud had ints back in the day17:40
mugsieits a string(64) afaik17:40
kmallocthat will break keystone.17:40
kmallocso you can give that guidance.17:40
*** blake has quit IRC17:40
kmallocmugsie: id = sql.Column(sql.String(64), primary_key=True)17:41
mugsiekmalloc: thanks17:42
kmallocmugsie: we allow for 64bytes, so a sha256 (we use that in some caseS) for ids17:43
kmallocit may not be a uuid4, it might be a sha256 hexdigest17:43
kmallocif someone proposes a patch that enforces uuid or less than 64bytes, we cannot guarantee we wont break you17:44
mugsieyeah - the patch is for uuidutils.is_uuid_like(project_id)17:44
kmallocyeah i'd -2 that17:44
* mugsie wang17:44
kmallocand never let it land17:44
kmalloc:)17:44
mugsiedamn17:44
kmallocwe may go to 64bytes for ids.17:44
* mugsie *wants* to wait for the keystone unified limits17:44
kmallocwe may not, we future planned17:44
kmallocbut we will be opinionated we should generate the ids17:45
kmalloc:)17:45
kmallocif that helps ya17:45
mugsiethe problem is people are setting quotas on non existant projects, and want a way to validate the input - but this helps a lot :) I wanted to make sure I was right in my suspissions17:45
kmalloc:)17:46
kmallocwe're working on the limit things17:46
kmallocbut it is slow =/17:46
kmallocmugsie: man, i need to get my openstack control plane up and running17:47
lbragstadkmalloc: we wrapped up the meeting talking about the domain to idp mappings17:49
kmalloclbragstad: cool.17:50
*** jaosorior has joined #openstack-keystone17:50
lbragstadand if there is a use case to have more than one domain per idp17:50
kmallocthere could be.17:50
kmallocbut that said, you could make it work with a 1-per restriction17:51
*** germs has joined #openstack-keystone17:52
*** germs has quit IRC17:52
*** germs has joined #openstack-keystone17:52
*** david-lyle has quit IRC17:53
*** dklyle has joined #openstack-keystone17:54
lbragstadwe had someone in boston ask for multiple domains per identity provider17:56
lbragstadi specifically remember that17:56
*** germs has quit IRC17:56
lbragstadkmalloc: how would you do it with a workaround?18:00
kmallocassignments cross domains18:01
lbragstadoh - from the shadow user across domains you mean?18:02
kmallocyeah, just assign the role for the <user> to <domain1> <domain2> whatever18:02
lbragstadi suppose18:02
lbragstadthat would work18:02
lbragstadsince that's an option, i don't really see a reason to not have a one to one mapping18:03
kmallocyeh18:03
lbragstadbetween identity providers and domains18:03
*** dikonoor has joined #openstack-keystone18:04
kmallocyou can also register another idp in the system if you need clear isolation18:04
kmalloce.g. some users in domain x and some in y18:04
kmallocthe same idp could be used multiple times.18:04
kmalloca flat 1-to-1 mapping is not really needed. but also explicitly multiple domains per idp isn't needed afaict18:05
kmallocwithout knowing more use-case specifics18:05
*** Pete_ has joined #openstack-keystone18:05
Pete_hello18:06
lbragstadkmalloc: sure18:06
lbragstadPete_: hi18:07
*** germs has joined #openstack-keystone18:12
*** germs has quit IRC18:12
*** germs has joined #openstack-keystone18:12
*** r-daneel_ has joined #openstack-keystone18:16
*** r-daneel has quit IRC18:17
*** r-daneel_ is now known as r-daneel18:17
*** panbalag has joined #openstack-keystone18:22
*** harlowja has joined #openstack-keystone18:25
*** panbalag has left #openstack-keystone18:26
*** openstackgerrit has joined #openstack-keystone18:27
openstackgerritGage Hugo proposed openstack/keystone master: Move fernet doctor checks into tokens checks  https://review.openstack.org/52752718:27
*** oikiki has joined #openstack-keystone18:28
*** marius1 has quit IRC18:35
*** AlexeyAbashkin has joined #openstack-keystone18:36
lbragstadgagehugo: with https://review.openstack.org/#/c/555196/18:46
lbragstadwhen you generate the api-ref, where are you seeing the changes?18:46
lbragstadi've tried generating the API reference with and without the change, but i don't notice a difference18:46
*** mvk has joined #openstack-keystone18:47
*** jaosorior has quit IRC18:48
*** germs has quit IRC18:49
*** germs has joined #openstack-keystone18:51
*** germs has quit IRC18:51
*** germs has joined #openstack-keystone18:51
*** germs has quit IRC18:58
*** timss has joined #openstack-keystone19:04
*** openstackgerrit has quit IRC19:04
*** marius1 has joined #openstack-keystone19:17
*** openstackgerrit has joined #openstack-keystone19:18
openstackgerritGage Hugo proposed openstack/keystone master: Update keystone functional tests  https://review.openstack.org/56012919:18
gagehugolbragstad I looked at that locally vs the latest page19:26
gagehugounder "code documentation" it's a bit different19:26
gagehugooh19:26
gagehugonot the api-ref19:27
gagehugothe docs that are auto-generated via sphinx-apidocs19:27
lbragstadoh19:27
lbragstadchecking that quick19:27
lbragstadgagehugo: you compared them to https://docs.openstack.org/keystone/latest/ ?19:28
gagehugoye19:30
gagehugothe toctree is a bit different here: https://docs.openstack.org/keystone/latest/api/modules.html19:31
gagehugovs change19:31
gagehugoit looks like it's nesting differently, but the info ends up being there19:31
lbragstadsome of the configuration options look different too19:31
Pete_need help19:31
Pete_Error: Could not prefetch keystone_role provider 'openstack': Execution of '/bin/openstack role list --quiet --format csv' returned 1: SSL exception connecting to https://127.0.0.1:35357/v3/roles: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:579) (tried 47, for a total of 170 seconds) Error: Not managing Keystone_role[_member_] due to earlier Keystone API failures. Error: /Stage[main]/Pra_openstack::Ke19:32
Pete_What is this and how to fix19:32
Pete_we config the admin_url/public_url as "https://<fqdn>:35357"19:32
Pete_but why "/bin/openstack role list" talks to 127.0.0.1 instead?19:33
gagehugohmm19:33
*** pcichy has quit IRC19:33
Pete_the scenario is like this, in an existing env which keystone/and other components runs w/o SSL19:34
Pete_we are putting change through puppet to setup SSL for keystone19:34
Pete_change admin/public_url from "http" to "https" using the same port "5000/35357"19:34
Pete_and provides "ssl_cert, ssl_key, ssl_cacert, use_ssl=true" to start keystone19:35
*** pcichy has joined #openstack-keystone19:35
lbragstadopenstack cli should look for an auth url to authenticate against19:36
lbragstadare you sure openstack client is finding that?19:36
Pete_when you say "openstack client" you mean "/bin/openstack"?19:37
lbragstadyeah - is that python-openstackclient?19:37
lbragstadhttps://pypi.python.org/pypi/python-openstackclient19:37
Pete_I can't tell19:38
Pete_from where the openstack client get the auth_url?19:38
Pete_from the 'table keystone" or from env vars?19:38
lbragstadopenstackclient can get the auth url a couple different ways19:38
lbragstadone of the most common is it use environment variables19:39
lbragstadhttps://docs.openstack.org/python-openstackclient/latest/cli/man/openstack.html#authentication-methods19:39
lbragstadis to use*19:39
Pete_export OS_AUTH_URL="http://piab1-praccn1-1-piab.eng.sfdc.net:35357/v3" export OS_IDENTITY_API_VERSION="3" export OS_IMAGE_API_VERSION="2"19:40
Pete_export OS_PROJECT_DOMAIN_NAME="Default" export OS_PROJECT_NAME="admin" export OS_USERNAME="admin" export OS_USER_DOMAIN_NAME="Default"19:40
Pete_export OS_PASSWORD="blabla"19:40
Pete_that is the env vars setting19:40
*** markvoelker_ has quit IRC19:41
*** markvoelker has joined #openstack-keystone19:41
lbragstadok - are you able to get a token?19:41
lbragstadusing `openstack token issue` for example?19:42
Pete_how?19:42
Pete_declare -x OS_AUTH_URL="https://piab1-praccn1-1-piab.eng.sfdc.net:35357/v3"19:43
Pete_i changed this19:43
Pete_run "openstack user list"19:43
Pete_[centos@piab1-praccn1-1-piab ~]$ openstack user list Discovering versions from the identity service failed when creating the password plugin. Attempting to determine version from URL. SSL exception connecting to https://piab1-praccn1-1-piab.eng.sfdc.net:35357/v3/auth/tokens: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:579)19:43
lbragstadthat still looks like a certificate error19:44
Pete_but I run "openssl" to verify the cert/key are fine19:44
lbragstaddid you use the upstream openstack puppet modules to setup SSL19:45
lbragstadif so, the puppet team might be able to help19:45
*** panbalag has joined #openstack-keystone19:45
*** markvoelker has quit IRC19:45
*** jessegler has quit IRC19:45
Pete_we use github/puppet-keystone19:46
Pete_https://github.com/openstack/puppet-keystone/19:47
lbragstadyeah - the folks in #puppet-openstack might be able to help19:48
lbragstadfrom what i can tell, it looks like an issue with the certificates19:48
lbragstadwhich means the request likely isn't even getting to the keystone application yet19:49
Pete_'/bin/openstack role list --quiet --format csv' returned 1: SSL exception connecting to https://127.0.0.1:35357/v3/roles:19:50
Pete_anyidea19:50
Pete_why "/bin/openstack role list" talk to 127.0.0.119:50
*** markvoelker has joined #openstack-keystone19:54
lbragstadhow is your service catalog setup/19:54
lbragstad?19:54
Pete_what command to run?19:55
Pete_whatever command "openstack" I ran all hit19:55
Pete_Discovering versions from the identity service failed when creating the password plugin. Attempting to determine version from URL. SSL exception connecting to https://piab1-praccn1-1-piab.eng.sfdc.net:35357/v3/auth/tokens: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:579)19:56
lbragstadyeah - thats an ssl error19:56
Pete_any idea how to trouble shoot it?19:57
lbragstadwhen you setup the service catalog, how did you do it?19:57
Pete_this is an existing env which was setup before20:00
lbragstaddo you know what was used to set it up? was it setup using puppet?20:00
*** pcaruana has quit IRC20:01
Pete_yes20:01
Pete_  class { '::keystone':     admin_token         => $::pra_openstack::constant::keystone_admin_token,     admin_password      => $::pra_openstack::config::keystone_admin_pwd,     database_connection => "mysql+pymysql://keystone_admin:${keystone_cfg_ks_db_pw}@${keystone_cfg_mariadb_host}/keystone",     token_provider      => 'fernet',     enable_fernet_setup => true,     debug               => $::pra_openstack::constant::debu20:02
Pete_we just add enable_ssl => true20:02
Pete_ssl_certfile=>20:03
Pete_ssl_keyfile=>20:03
Pete_ssl_ca_certs20:03
Pete_validate_insecure=> true20:03
Pete_to config keystone with SSL20:03
lbragstadjust a heads up, but http://paste.openstack.org/ helps if you have a bunch of information20:03
lbragstadoften times pastes don't turnout well in IRC due to formatting20:04
Pete_http://paste.openstack.org/show/718860/20:05
lbragstadawesome - thanks20:05
lbragstadpublic_bind_host and admin_bind_host are commented out20:05
Pete_first we didn't comment them out, but the same failure20:06
lbragstadi'm not very familiar with how openstack puppet does their orchestration, but someone in #puppet-openstack might20:07
openstackgerritGage Hugo proposed openstack/keystone master: Have project get domain_id from parent  https://review.openstack.org/48965520:07
Pete_ok, i will try taht channel, thx20:10
*** Pete_ has left #openstack-keystone20:10
*** AlexeyAbashkin has quit IRC20:16
*** AlexeyAbashkin has joined #openstack-keystone20:17
*** markvoelker_ has joined #openstack-keystone20:17
*** markvoelker has quit IRC20:21
*** AlexeyAbashkin has quit IRC20:25
*** pcichy has quit IRC20:32
*** panbalag has left #openstack-keystone20:33
*** raildo has quit IRC20:44
*** dikonoor has quit IRC20:52
*** dikonoor has joined #openstack-keystone20:54
*** felipemonteiro__ has quit IRC20:56
lbragstad#endmeeting21:08
*** openstack changes topic to "Rocky release schedule: https://releases.openstack.org/rocky/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/wmyzbFq5/keystone-rocky-roadmap"21:08
openstackMeeting ended Tue Apr 10 21:08:26 2018 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)21:08
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-10-17.01.html21:08
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-10-17.01.txt21:08
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone_office_hours/2018/keystone_office_hours.2018-04-10-17.01.log.html21:08
*** jrist has quit IRC21:14
*** dikonoor has quit IRC21:16
*** mchlumsky has quit IRC21:21
*** martinus__ has quit IRC21:22
*** mchlumsky has joined #openstack-keystone21:24
*** mchlumsky has quit IRC21:27
*** marius1 has quit IRC21:36
*** jrist has joined #openstack-keystone21:41
*** edmondsw has quit IRC21:42
*** edmondsw has joined #openstack-keystone21:42
*** edmondsw has quit IRC21:43
*** harsha has joined #openstack-keystone21:46
harshaHello, does anyone know if keystone supports exponential backout or some sort of hardening mechanism to handle multiple failed login attempts(DDOS)... is there a conf to handle that?21:47
*** marius1 has joined #openstack-keystone21:49
*** marius1 has quit IRC21:53
*** Pete__ has joined #openstack-keystone21:54
Pete__We have an existing env running keystone/other components in non-SSL and in the process of setting keystone w/ SSL and hit an issue21:55
Pete__We configured ::keystone with ssl_cert, ssl_key, ssl_ca, usessl=>true21:56
Pete__and run puppet21:56
*** germs has joined #openstack-keystone21:56
*** germs has quit IRC21:56
*** germs has joined #openstack-keystone21:56
Pete__Notice: /Stage[main]/Glance::Deps/Anchor[glance::dbsync::end]: Triggered 'refresh' from 1 events Notice: /Stage[main]/Apache::Service/Service[httpd]: Triggered 'refresh' from 8 events Error: Could not prefetch keystone_role provider 'openstack': Execution of '/bin/openstack role list --quiet --format csv' returned 1: SSL exception connecting to https://127.0.0.1:35357/v3/roles: [SSL: CERTIFICATE_VERIFY_FAILED] certificate21:56
Pete__the admin_url we configured is "https://<fqdn>:35357"21:56
*** adriant has quit IRC21:59
*** adriant has joined #openstack-keystone21:59
*** harsha has quit IRC22:05
*** edmondsw has joined #openstack-keystone22:09
*** edmondsw has quit IRC22:10
*** harsha has joined #openstack-keystone22:15
*** itlinux has quit IRC22:15
Pete__but the command "/usr/openstack user list" failed at "SSL exception connecting to 127.0.0.1"22:16
Pete__does anyone know why?22:16
lbragstadharsha: yeah - we have some support for pci dss22:17
harshalbragstad: https://specs.openstack.org/openstack/keystone-specs/specs/keystone/newton/pci-dss.html -- >this doc says it's not yet supported22:20
lbragstadharsha: https://docs.openstack.org/keystone/latest/admin/identity-security-compliance.html#setting-an-account-lockout-threshold22:21
lbragstadi think that feature came after the newton release22:21
harshalbragstad thanks for the info :)22:22
lbragstadno problem22:22
*** rcernin has joined #openstack-keystone22:23
*** oikiki has quit IRC22:40
*** lbragstad has quit IRC22:42
openstackgerritTim Burke proposed openstack/keystonemiddleware master: Properly zero out max_retries in test_http_error_not_cached_token  https://review.openstack.org/54722822:43
*** dave-mccowan has quit IRC22:49
openstackgerritTim Burke proposed openstack/keystonemiddleware master: Only include response body if there's a response  https://review.openstack.org/53810822:49
*** r-daneel has quit IRC22:59
*** r-daneel has joined #openstack-keystone22:59
*** harsha has quit IRC23:04
*** lbragstad has joined #openstack-keystone23:09
*** ChanServ sets mode: +o lbragstad23:09
*** Pete__ has quit IRC23:10
*** adriant has quit IRC23:11
*** adriant has joined #openstack-keystone23:12
*** spilla has quit IRC23:12
*** r-daneel has quit IRC23:14
*** adriant has quit IRC23:46
*** adriant has joined #openstack-keystone23:47

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!