Friday, 2018-08-17

openstackgerritMerged openstack/keystone master: Do not log token string
mbuilcmurphy: yesterday I had a talk with the edge guys and they had in mind a demo where a user logs into Horizon from the SP using federation. As far as I saw yesterday, the only way to interact with the SP is through a token and changing OS_URL, so I guess what they had in mind is currently not possible, or?07:08
cmurphymbuil: it is possible to use horizon but you have to log in to the IdP not the SP07:28
mbuilcmurphy: and could you see or interact with the SP resources from the IdP somehow?07:29
cmurphymbuil: yes, it should actually be pretty seamless, you just select the SP from a menu and then it will pretty much act like you've logged into the SP07:30
mbuilcmurphy: ah nice. I'll try that right away :)07:31
cmurphybecause it gets the token up front and has the catalog from that, it knows where all the endpoints are07:31
openstackgerritMerged openstack/ldappool master: fix tox python3 overrides
*** raildo has joined #openstack-keystone12:12
*** r-daneel has joined #openstack-keystone14:44
openstackgerritMerged openstack/keystonemiddleware master: add releasenotes to readme.rst
openstackgerritGage Hugo proposed openstack/keystoneauth master: Add nosec to usage of SHA1
gagehugokmalloc ^ bandit was updated to 1.5, ksa now is failing the bandit check16:01
gagehugoon a sha1 usage16:01
kmallocjust exempt it16:53
kmallocthere is zero reason our use of SHA1 is an issue we're using it for obfuscating logs.16:53
kmalloci see you did that.16:53
kmallocgagehugo: alternative is to use sha25616:54
kmallocgagehugo: really it is fine to change the hash we use as long as we're consisting within a release16:54
openstackgerritMerged openstack/keystone master: Remove get_catalog from manage layer
kmallocgagehugo: -1, but only becaue the TODO is pointless.16:58
kmallocgagehugo: we can not suppress by moving to sha256 or we can nosec and say "this is for logging only"16:59
gagehugokmalloc ok, I'll update that17:27
openstackgerritGage Hugo proposed openstack/keystoneauth master: Change log hashing to SHA256
openstackgerritMerged openstack/keystoneauth master: Change log hashing to SHA256
