Monday, 2018-09-24

*** imacdonn has quit IRC01:17
*** imacdonn has joined #openstack-keystone01:17
*** rcernin has quit IRC01:40
*** rcernin has joined #openstack-keystone01:40
*** imacdonn has quit IRC02:35
*** imacdonn has joined #openstack-keystone02:50
*** pooja_jadhav has joined #openstack-keystone04:14
*** viks__ has joined #openstack-keystone04:28
*** shyamb has joined #openstack-keystone04:52
*** spsurya has joined #openstack-keystone05:02
*** shyamb has quit IRC05:09
*** shyamb has joined #openstack-keystone05:23
*** shyamb has quit IRC05:33
*** dave-mccowan has joined #openstack-keystone05:36
*** shyamb has joined #openstack-keystone05:49
*** pcaruana has joined #openstack-keystone06:05
*** shyamb has quit IRC06:24
*** shyamb has joined #openstack-keystone06:24
*** shyam89 has joined #openstack-keystone06:29
*** shyamb has quit IRC06:32
*** belmoreira has joined #openstack-keystone06:35
*** nick_kar_ has joined #openstack-keystone06:42
*** belmoreira has quit IRC06:45
*** belmoreira has joined #openstack-keystone06:47
*** rcernin has quit IRC07:06
*** shyam89 has quit IRC07:07
*** shyamb has joined #openstack-keystone07:13
*** shyamb has quit IRC07:18
*** shyamb has joined #openstack-keystone07:20
*** mattgo has joined #openstack-keystone07:31
*** shyamb has quit IRC07:35
*** openstackgerrit has quit IRC08:22
*** shyamb has joined #openstack-keystone08:30
*** kukacz has quit IRC09:10
*** jaosorior has quit IRC09:11
*** kukacz has joined #openstack-keystone09:12
*** shyamb has quit IRC09:26
*** shyamb has joined #openstack-keystone09:35
*** shyamb has quit IRC09:46
*** shyamb has joined #openstack-keystone09:52
*** sapd1__ has quit IRC09:54
*** sapd1_ has joined #openstack-keystone09:59
*** Emine has joined #openstack-keystone10:01
*** shyamb has quit IRC10:21
*** shyamb has joined #openstack-keystone10:21
*** jaosorior has joined #openstack-keystone10:22
*** shyamb has quit IRC10:35
*** mvkr has quit IRC11:17
*** mvkr has joined #openstack-keystone11:29
*** shyamb has joined #openstack-keystone11:33
*** shyamb has quit IRC11:45
*** shyamb has joined #openstack-keystone11:47
*** openstackgerrit has joined #openstack-keystone11:50
openstackgerritMerged openstack/oslo.limit master: Ignore documentation builds  https://review.openstack.org/60316711:50
*** devx has quit IRC12:09
*** shyamb has quit IRC12:37
*** viks__ has quit IRC12:37
mordredkmalloc, cmurphy: https://review.openstack.org/#/c/604635/ is green with the testing and ready for review12:41
*** jaosorior has quit IRC12:42
*** jaosorior has joined #openstack-keystone12:44
*** jrist has joined #openstack-keystone12:59
knikollao/13:15
*** lbragstad has joined #openstack-keystone13:18
*** ChanServ sets mode: +o lbragstad13:18
lbragstado/13:23
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Render API reference documentation  https://review.openstack.org/60026413:23
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Add a conceptual overview to docs  https://review.openstack.org/60026513:23
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Allow ProjectClaims to support multiple resources  https://review.openstack.org/60026613:23
openstackgerritLance Bragstad proposed openstack/oslo.limit master: Use openstackdocstheme for documentation  https://review.openstack.org/60086613:24
*** lbragstad changes topic to "Rocky release schedule: https://releases.openstack.org/rocky/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/rj0ECz2c/keystone-stein-roadmap !!NOTE!! This Channel is Logged ( https://tinyurl.com/OpenStackKeystone )"13:29
*** lbragstad changes topic to "Stein release schedule: https://releases.openstack.org/stein/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/rj0ECz2c/keystone-stein-roadmap !!NOTE!! This Channel is Logged ( https://tinyurl.com/OpenStackKeystone )"13:29
*** belmorei_ has joined #openstack-keystone13:30
*** belmoreira has quit IRC13:32
*** SteelyDan is now known as dansmith13:34
*** mbeierl has joined #openstack-keystone13:41
*** edmondsw has joined #openstack-keystone13:48
*** jaosorior has quit IRC13:55
*** beekneemech is now known as bnemec13:57
*** raildo has joined #openstack-keystone14:02
openstackgerritVishakha Agarwal proposed openstack/keystone master: Adresses LDAP case-sensitive issue  https://review.openstack.org/60334514:04
*** jdennis has quit IRC14:06
*** jdennis has joined #openstack-keystone14:13
openstackgerritVishakha Agarwal proposed openstack/oslo.limit master: Make callbacks required for enforcement  https://review.openstack.org/60479514:14
*** belmorei_ has quit IRC14:19
hrybackio/14:29
*** belmoreira has joined #openstack-keystone14:30
lbragstadhrybacki morning - do we wanna try and go through the stein board sometime this week?14:31
hrybackilbragstad: yes -- I can do tomorrow before the weekly meeting if that works for you?14:31
lbragstadyessir14:31
* hrybacki goes to send off an invite14:32
lbragstadmy schedule is wide open this week so...14:32
cmurphykmalloc: knikolla query for you on the ml http://lists.openstack.org/pipermail/openstack-dev/2018-September/135006.html14:34
kmallocI saw, was reading the email, pre-coffee so brain is.... OoooooOOOooooOoooOoo14:35
cmurphykmalloc: no rush :)14:36
*** mchlumsky has joined #openstack-keystone14:40
*** mchlumsky has quit IRC14:45
*** mchlumsky has joined #openstack-keystone14:47
*** dave-mccowan has quit IRC14:50
aningcmurphy: I have a keystone instance setup as SP and testshib.org as Idp. When I login in with the Idp, Horizon gives an error: The current path, auth/login/default/auth/OS-FEDERATION/websso/saml2, didn't match any of these.14:50
gagehugoo/14:50
aningcmurphy: but I tried "identity/v3/auth/OS-FEDERATION/websso/saml2" directly, it works.14:51
aningcmurphy: looks like some settings are missed in Horizon, that it doesn't redirect to the right URL14:52
cmurphyaning: are you using master of horizon? i think I saw something similar last week but haven't had time to report the bug yet14:53
aningcmurphy: I think so ... I'm using devstack master, so I would think it pulled in the master.14:54
aningcmurphy: things seem to be working from the point where Apache shibboleth is contact (this is the URL:identity/v3/auth/OS-FEDERATION/websso/saml2)14:56
cmurphyaning: if it's what i was seeing, it seems to be new on master and rocky is not broken. you can try checking out stable/rocky in /opt/stack/horizon, then you'll also have to run some django commands to reinit horizon and then restart apache http://git.openstack.org/cgit/openstack-dev/devstack/tree/lib/horizon#n15414:58
aningcmurphy: thx, I'm trying this. Will report back.15:05
openstackgerritGage Hugo proposed openstack/keystone master: [WIP] Add functional testing gate  https://review.openstack.org/53101415:10
*** dave-mccowan has joined #openstack-keystone15:12
*** dave-mccowan has quit IRC15:17
*** dave-mccowan has joined #openstack-keystone15:22
cmurphymordred: so much for green https://review.openstack.org/60463515:28
*** gagehugo has quit IRC15:29
*** gagehugo has joined #openstack-keystone15:33
mordredcmurphy: ugh. that's a timeout issue in the openstacksdk test suite I've been fighting15:33
mordredcmurphy: hopefully https://review.openstack.org/#/c/604628/ will stop the flapping15:45
*** lbragstad has quit IRC16:10
*** lbragstad has joined #openstack-keystone16:18
*** ChanServ sets mode: +o lbragstad16:18
*** spotz is now known as spotz_16:25
*** spotz_ is now known as spotz16:25
*** dave-mccowan has quit IRC16:38
*** belmoreira has quit IRC17:04
openstackgerritMerged openstack/keystone master: Implement Trust Flush via keystone-manage.  https://review.openstack.org/58937817:06
hrybackikmalloc: you around?17:16
*** mattgo has quit IRC17:16
*** mvkr has quit IRC17:25
errrkmalloc: ah ok, well I opened a bug report about it https://bugs.launchpad.net/keystone/+bug/1793845 because in openstack-ansible we used the method I describe in our keystone playbook if we setup federation17:27
openstackLaunchpad bug 1793845 in OpenStack Identity (keystone) "Federation Protocol saml2 fails on Rocky" [Undecided,New]17:27
errrand I feel like it worked still in Queens and changed in Rocky. I know it worked like I described in Pike for sure17:28
hrybackigagehugo: should https://github.com/openstack/keystone/blob/master/keystone/resource/controllers.py#L34-L40 be removed as well?17:32
*** dave-mccowan has joined #openstack-keystone17:35
lbragstadis it just me or does the new chrome update on osx seems *way* too much like safari?17:51
gagehugoit is very safari-ish17:55
gagehugohrybacki: iirc another api was calling that for something17:56
gagehugohttps://github.com/openstack/keystone/blob/master/keystone/auth/controllers.py#L36217:57
gagehugoso I just left the class in17:57
*** mvkr has joined #openstack-keystone18:15
hrybackigagehugo: ah I see. I wonder if we can point that at a newer helper function18:20
openstackgerritAndreas Jaeger proposed openstack/python-keystoneclient master: Use templates for cover and lower-constraints  https://review.openstack.org/60069218:22
openstackgerritAndreas Jaeger proposed openstack/python-keystoneclient master: Import legacy keystoneclient-dsvm-functional  https://review.openstack.org/60486818:22
gagehugohrybacki: yeah, I figured it could be done in a separate change18:31
gagehugo(or wait until auth gets moved over and just avoid it lol)18:31
gagehugo>.>18:31
aningcmurphy: andy idea how to turn Apache Shibboleth Mod ECP on?18:43
aningcmurphy: I remember that you mentioned ECP on SP is off by default.18:44
errrits off by default?18:46
aningerrr: to me?18:47
cmurphyaning: in shibboleth2.xml in the SSO tag i think it's just ECP="true" or something like that18:47
aningcmurphy: k, trying ...18:48
aning            <SSO entityID="https://idp.testshib.org/idp/shibboleth">18:51
aning                SAML2 SAML1 ECP18:51
aning            </SSO>18:51
aningFound this:18:55
aning<SSO discoveryProtocol="SAMLDS" ECP="true" discoveryURL="https://examplefederation.org/DS">18:55
aning  SAML2 SAML118:55
aning</SSO>18:55
*** aojea has joined #openstack-keystone19:05
*** pcaruana has quit IRC19:17
aningcmurphy: update ... minimum config like this works:19:17
aning            <SSO discoveryProtocol="SAMLDS" ECP="true">19:17
aning                SAML2 SAML119:17
aning            </SSO>19:17
*** aojea has quit IRC19:23
aningcmurphy: but the WESSO support for Horizon is broken :(19:23
openstackgerritHarry Rybacki proposed openstack/keystone master: WIP: Convert projects API to Flask  https://review.openstack.org/60345119:23
*** aojea has joined #openstack-keystone19:24
errraning: in which release?19:24
aningerrr: I'm using Devstack with master.19:24
errrah19:25
errrhavented tested that yet19:25
errr-ed19:25
aningI think I may to try another installation with Rocky.19:25
errrit for sure works in rocky. I just did an install Friday19:26
errrI was using mellon, but that wont matter at the horizon side of things19:26
aningerrr: what's your SSO section like?19:27
errrin the horizon config?19:28
aningerrr: never mind, you are not using shibboleth ...19:28
errrwell I use both all the time19:28
errrif Im working on rhel I have to use mellon, when Im on ubuntu our stuff uses shibboleth19:28
aningerrr: you made both WEBSSO and ECP work at the same time?19:28
errrso I may have some missunderstanding of what ECP is, but I thought that was something on the IDP side of things, not the SP19:29
aningerrr: so far, I kind of made WEBSSO works with Horizon, and ECP works with openstack CLI, but not wit the same config in shibboleth2.xml19:30
errrah so to use cli apps I use a work around which kind of sucks19:30
errrthere is a plugin from pf9 that I use19:30
aningI don't think it's the client19:31
errrhttps://github.com/michaelrice/openrc_maker I made this to get cli working with sso19:31
aningerrr: that's nice.19:32
errrits ugly but it works19:33
aningerrr: but the openstack CLI does work.19:33
errryep19:33
errrI worked with the pf9 fols to get their plugin into pip so I need to update my code to pip install their plugin rather than pull my fork of it from github19:34
aningerrr: In production, we definitely need WEBSSO with Horizon and ECP with openstack CLI work.19:34
errrfolks*19:34
errryeah we have to have web sso and cli for those users too19:35
aningerrr: and both need to work at the same time without any change to configuration.19:35
errrwe dont use sso for service accounts, just users19:35
errrwith the solution I came up with its 1 extra step for people to generate their openrc file before they can start using the cli19:36
aningerrr: What does the openrc maker generate, other than these OS environment varibles?19:39
aningerrr: this is the openstack CLI is used (copied from cmurphy's blog)19:41
aning$ openstack \19:41
aning--os-auth-type v3samlpassword \19:41
aning--os-identity-provider testidp \19:41
aning--os-identity-provider-url https://idp.testshib.org/idp/profile/SAML2/SOAP/ECP \19:41
aning--os-protocol saml2 \19:41
aning--os-username myself \19:41
aning--os-password myself \19:41
aning--os-auth-url http://devstack-sp.wrs.com/identity/v3 \19:41
aning--os-project-name demo \19:41
aning--os-project-domain-name Default \19:41
aning--os-identity-api-version 3 \19:41
aningtoken issue19:41
errrit just makes a valid openrc file. but it uses v3token instead of v3samlpassword19:41
aningerrr: you are using this with k2k?19:42
errrI have not tested it with that. We normally use okta as an idp and also adfs19:42
errrfor k2k there may be something else better.. I just havent had that come in yet so I have never set it up19:43
aningerrr: It's just the v3token remind me of k2k, since in k2k federated setup, client get a token from the Idp Keystone, and with that token start the SAML procedure.19:50
*** raildo_ has joined #openstack-keystone20:11
*** raildo_ has quit IRC20:12
*** raildo has quit IRC20:13
openstackgerritBen Nemec proposed openstack/oslo.limit master: Fix doc grammar/spelling nits  https://review.openstack.org/60490720:49
openstackgerritColleen Murphy proposed openstack/keystone master: Convert legacy functional jobs to Zuul-v3-native  https://review.openstack.org/60245220:57
lbragstadis anyone here familiar with tempest auth clients?21:28
rodrigodslbragstad, i kinda was, but i'm pretty sure my memory will fail me21:35
lbragstadrodrigods yeah... it's kinda complicated21:35
lbragstadi spent most of friday and today trying to find a way to add system-scoping to tempest clients21:36
lbragstadcurious if anyone anyone had pointers https://review.openstack.org/#/c/604909/21:36
lbragstads/anyone anyone/anyone/21:36
rodrigodslet me take a look21:37
lbragstadhttps://review.openstack.org/#/c/604909/1/tempest/api/identity/admin/v3/test_credentials.py is ultimately what i want to do21:37
lbragstadsince it's needed for https://review.openstack.org/#/c/594547/11 to pass21:37
rodrigodsi have 0 memories of them :/21:41
lbragstad:)21:43
*** aojea has quit IRC21:47
*** Emine has quit IRC22:03
openstackgerritMerged openstack/oslo.limit master: Render API reference documentation  https://review.openstack.org/60026422:32
openstackgerritMerged openstack/oslo.limit master: Add a conceptual overview to docs  https://review.openstack.org/60026522:32
*** rcernin has joined #openstack-keystone22:45
*** pooja-jadhav has joined #openstack-keystone22:51
*** kukacz_ has joined #openstack-keystone22:55
*** dims_ has joined #openstack-keystone22:59
*** jamiec_ has joined #openstack-keystone22:59
*** _d34dh0r53_ has joined #openstack-keystone23:00
*** kukacz has quit IRC23:00
*** pooja_jadhav has quit IRC23:00
*** dims has quit IRC23:00
*** d34dh0r53 has quit IRC23:00
*** jlvillal has quit IRC23:00
*** jamiec has quit IRC23:00
*** cburgess has quit IRC23:00
*** eglute has quit IRC23:00
*** andreykurilin has quit IRC23:03
*** andreykurilin has joined #openstack-keystone23:05
openstackgerritMerged openstack/oslo.limit master: Fix doc grammar/spelling nits  https://review.openstack.org/60490723:54

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!