Tuesday, 2019-05-14

*** dklyle has quit IRC00:11
*** itlinux has joined #openstack-keystone00:14
*** itlinux has quit IRC00:22
*** itlinux has joined #openstack-keystone00:24
*** itlinux has quit IRC00:25
*** itlinux has joined #openstack-keystone00:26
openstackgerritMerged openstack/oslo.policy master: Cap Bandit below 1.6.0 and update Sphinx requirement  https://review.opendev.org/65890600:39
*** itlinux has quit IRC00:41
*** itlinux has joined #openstack-keystone00:44
*** itlinux has quit IRC00:47
openstackgerritcaoyuan proposed openstack/keystoneauth master: Replace git.openstack.org URLs with opendev.org URLs  https://review.opendev.org/65501601:22
*** ileixe has joined #openstack-keystone01:30
*** dklyle has joined #openstack-keystone01:37
*** dklyle has quit IRC01:54
*** mvkr has quit IRC02:41
*** mvkr has joined #openstack-keystone02:55
*** whoami-rajat has joined #openstack-keystone02:59
*** jdennis has quit IRC03:48
*** mvkr has quit IRC04:03
*** pcaruana|afk| has joined #openstack-keystone04:25
*** pcaruana|afk| has quit IRC04:35
*** shyamb has joined #openstack-keystone05:20
*** vishalmanchanda has joined #openstack-keystone05:35
*** shyamb has quit IRC06:14
*** shyamb has joined #openstack-keystone06:17
*** xek has joined #openstack-keystone06:35
*** shyamb has quit IRC06:45
*** shyamb has joined #openstack-keystone06:56
*** awalende has joined #openstack-keystone07:03
openstackgerritJose Castro Leon proposed openstack/keystone master: Allow to filter endpoint groups by name  https://review.opendev.org/65835907:05
*** tesseract has joined #openstack-keystone07:05
*** rcernin has quit IRC07:06
*** pcaruana has joined #openstack-keystone07:12
*** shyamb has quit IRC07:54
*** vishakha has joined #openstack-keystone08:10
*** tkajinam has quit IRC08:14
*** jaosorior has quit IRC08:25
*** shyamb has joined #openstack-keystone08:34
*** jaosorior has joined #openstack-keystone09:41
*** raildo has joined #openstack-keystone09:53
*** shyamb has quit IRC10:22
*** jaosorior has quit IRC10:24
*** shyamb has joined #openstack-keystone10:46
*** jaosorior has joined #openstack-keystone11:03
*** josecastroleon has quit IRC11:35
*** shyamb has quit IRC11:42
*** shyamb has joined #openstack-keystone11:49
*** shyamb has quit IRC12:25
*** shyamb has joined #openstack-keystone12:25
*** jdennis has joined #openstack-keystone12:29
*** shyamb has quit IRC12:34
*** mchlumsky has joined #openstack-keystone12:41
*** mchlumsky has quit IRC12:46
*** jamesmcarthur has joined #openstack-keystone12:46
*** mchlumsky has joined #openstack-keystone12:50
*** jistr is now known as jistr|call12:59
openstackgerritcaoyuan proposed openstack/oslo.policy master: Replace git.openstack.org URLs with opendev.org URLs  https://review.opendev.org/65472713:14
*** lbragstad has joined #openstack-keystone13:15
*** ChanServ sets mode: +o lbragstad13:15
*** dmellado has quit IRC13:24
*** dmellado has joined #openstack-keystone13:24
*** jistr|call is now known as jistr13:30
*** jamesmcarthur has quit IRC13:36
*** awalende has quit IRC13:53
*** awalende has joined #openstack-keystone13:53
*** jamesmcarthur has joined #openstack-keystone13:56
*** vishakha has quit IRC13:56
*** jamesmcarthur has quit IRC13:57
*** awalende has quit IRC13:58
*** jamesmcarthur has joined #openstack-keystone13:58
*** awalende has joined #openstack-keystone13:59
*** awalende has quit IRC14:03
*** dklyle has joined #openstack-keystone14:13
gagehugoo/14:51
cmurphy\o14:52
knikolla\o/15:03
kmalloczzzzz \o/15:03
*** ayoung has quit IRC15:10
*** mchlumsky has quit IRC15:13
*** mchlumsky has joined #openstack-keystone15:15
*** mchlumsky has quit IRC15:28
*** mchlumsky has joined #openstack-keystone15:30
*** ayoung has joined #openstack-keystone15:39
*** vishakha has joined #openstack-keystone15:46
*** dklyle has quit IRC15:50
*** dklyle has joined #openstack-keystone15:52
cmurphykeystone meeting in 7 minutes in #openstack-meeting-alt15:53
*** awalende has joined #openstack-keystone15:54
*** openstackgerrit has quit IRC15:54
*** awalende has quit IRC15:59
*** gyee has joined #openstack-keystone16:01
*** dklyle has quit IRC16:11
*** dklyle has joined #openstack-keystone16:16
*** dklyle has quit IRC16:21
*** dklyle has joined #openstack-keystone16:23
*** openstackgerrit has joined #openstack-keystone16:33
*** vishalmanchanda has quit IRC16:33
openstackgerritDouglas Mendizábal proposed openstack/keystone master: Fix documentation typo  https://review.opendev.org/65911816:33
*** jamesmcarthur has quit IRC16:50
* knikolla goes to get a quick lunch before office hours16:53
* kmalloc needs breakfast.16:55
*** jamesmcarthur has joined #openstack-keystone16:56
openstackgerritRaildo Mascena proposed openstack/keystone master: Fixing dn_to_id function for cases were id is not in the DN  https://review.opendev.org/64917716:56
ayoungraildo, um....I thought that case was covered by lookup?16:58
*** dklyle has quit IRC16:59
cmurphyi'll wait for knikolla and kmalloc to get back before opening office hours17:00
kmalloci haven't left yet17:00
kmalloc:P17:00
raildoayoung, hum... This code works fine when we have the id in the DN, if not, Keystone can't find the user, so we need to do the ldap search17:00
ayoungI thought that there was already a code path to do that17:01
kmallocsooooooo... you might need to let me pop in and out while getting breakfast.17:01
*** dklyle has joined #openstack-keystone17:01
raildoayoung, but this patch still WIP, since I'm working with the unit tests to mock the ldap search for that case17:01
*** jamesmcarthur has quit IRC17:01
ayoungI thought this code was only called IF we needed the ID to be extracted from the DN.  Maybe it is the search-the-tree code that does it, I forget17:02
raildoayoung, unfortunately, it's not called yet for that scenario, it only does a string manipulation to grab the id from the DN17:03
ayoungNah, there is a hack around it, I'm sure17:03
raildoayoung, great, can you point me for this link?17:04
ayoungits called from res_to_model17:05
ayoungthe logic is in there17:06
ayoungthat path is only called if there is an id attribute, but it is multi-value17:06
ayoungothewise it does the lookup17:06
ayounghttps://opendev.org/openstack/keystone/src/branch/master/keystone/identity/backends/ldap/common.py#L1314  raildo17:07
*** jamesmcarthur has joined #openstack-keystone17:08
ayoungI'm pretty sure you could inline that function.  It should not be called from anywhere else17:09
raildoayoung, I see your point, so on that case, iiuc, it'll return the first id, in the cased that the DN is multivalued, but in the case were we found this issue, it was using AD as backend for LDAP17:09
raildoSo, when we have something like, 'tree_dn': 'cn=users,dc=example,dc=com','id_attr': 'sAMAccountName', 'sAMAccountName': user_id, This user_id not returned17:10
ayoungOpen the bug first17:11
*** jamesmcarthur has quit IRC17:11
ayoungI don't think you need this code.  I mean, the code I wrote sucks, but you are stuck with it.17:11
ayoungthe "pull the ID out of the DN" approach was an artifact of me making it work with FreeIPA first, and building a solution based on the faster lookups using the DN.17:12
ayoungAnd not having a SQL shadow table, and all the things that were true in 201117:12
raildoayoung, sure, agreed and makes sense keep doing on this way17:13
raildoayoung, but, what I didn't understand yet is how to deal with that function when the id is not the DN, without performing an LDAP search query17:15
ayoungif you inline that function, you will see that it is only ever executed in the case where the ID IS in the DN17:16
cmurphy#startmeeting keystone-office-hours17:20
openstackMeeting started Tue May 14 17:20:30 2019 UTC and is due to finish in 60 minutes.  The chair is cmurphy. Information about MeetBot at http://wiki.debian.org/MeetBot.17:20
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.17:20
*** openstack changes topic to " (Meeting topic: keystone-office-hours)"17:20
*** ChanServ changes topic to "Stein release schedule: https://releases.openstack.org/stein/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/rj0ECz2c/keystone-stein-roadmap !!NOTE!! This Channel is Logged ( https://tinyurl.com/OpenStackKeystone )"17:20
openstackThe meeting name has been set to 'keystone_office_hours'17:20
cmurphyis anyone back for office hours?17:20
raildoayoung, we found that issue calling this function: https://github.com/openstack/keystone/blob/master/keystone/identity/backends/ldap/core.py#L123-L13717:20
gagehugoo/17:21
*** ayoung has quit IRC17:22
*** canori01 has joined #openstack-keystone17:24
canori01Hello, when configuring keystone to authenticate against ldap, is it possible to specify multiple  user_tree_dn ?17:25
cmurphyokay i'm going to close office hours so we can just have regular discussion, we'll do liaison review asynchronously and finalize at next week's meeting17:27
cmurphy#endmeeting17:27
*** openstack changes topic to "Stein release schedule: https://releases.openstack.org/stein/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/rj0ECz2c/keystone-stein-roadmap !!NOTE!! This Channel is Logged ( https://tinyurl.com/OpenStackKeystone )"17:27
openstackMeeting ended Tue May 14 17:27:21 2019 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)17:27
openstackMinutes:        http://eavesdrop.openstack.org/meetings/keystone_office_hours/2019/keystone_office_hours.2019-05-14-17.20.html17:27
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/keystone_office_hours/2019/keystone_office_hours.2019-05-14-17.20.txt17:27
openstackLog:            http://eavesdrop.openstack.org/meetings/keystone_office_hours/2019/keystone_office_hours.2019-05-14-17.20.log.html17:27
cmurphycanori01: i don't think it is possible to set multiiple user_tree_dn's17:27
canori01ok, thanks17:28
kmallocok back.17:28
kmallocsorry, took longer to get things.17:28
*** jamesmcarthur has joined #openstack-keystone17:31
*** itlinux has joined #openstack-keystone17:42
knikollaback from lunch.17:44
kmallocmmmm coffee #217:44
kmalloclbragstad: mind if i remove the automatic +o from you?17:46
lbragstadkmalloc yes please17:46
lbragstader - no i don't mind, yes please remove it :)17:46
*** itlinux has quit IRC17:48
*** ChanServ sets mode: -o lbragstad17:48
kmalloclbragstad: ^ there we go, done.17:49
kmallocyou should still be able to op yourself manually17:49
lbragstad++ thanks17:49
kmallocinteracting with chanserv, etc17:49
*** dklyle has quit IRC17:52
*** itlinux has joined #openstack-keystone17:54
*** ayoung has joined #openstack-keystone17:54
*** jamesmcarthur has quit IRC17:55
*** jamesmcarthur has joined #openstack-keystone17:56
*** mvkr has joined #openstack-keystone17:58
*** jamesmcarthur has quit IRC18:01
*** jamesmcarthur has joined #openstack-keystone18:28
*** vishalmanchanda has joined #openstack-keystone18:34
*** jamesmcarthur has quit IRC18:48
*** schaney_ has joined #openstack-keystone18:50
openstackgerritLance Bragstad proposed openstack/keystone master: Update the meaning of low-hanging-fruit  https://review.opendev.org/65914118:57
*** itlinux has quit IRC19:16
*** dklyle has joined #openstack-keystone19:16
*** dklyle has quit IRC19:19
*** david-lyle has joined #openstack-keystone19:19
*** pcaruana has quit IRC19:19
*** jamesmcarthur has joined #openstack-keystone19:20
*** awalende has joined #openstack-keystone19:25
cmurphyteam photos are up https://www.dropbox.com/sh/fydqjehy9h5y728/AADgMGvOMBaVIOUh3IvRfa_Xa/Keystone?dl=0&subfolder_nav_tracking=119:25
*** jamesmcarthur has quit IRC19:27
*** jamesmcarthur_ has joined #openstack-keystone19:28
*** jamesmcarthur has joined #openstack-keystone19:29
*** jamesmcarthur_ has quit IRC19:33
*** cwright has joined #openstack-keystone19:38
*** david-lyle has quit IRC19:42
rodrigodsnice!19:45
knikollacool!19:59
*** vishakha has quit IRC20:05
*** tesseract has quit IRC20:06
*** jmlowe has joined #openstack-keystone20:06
cmurphylbragstad: we went through the spec backlog at the end of the ptg and came to http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/policy-goals.html and http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ongoing/policy-security-roadmap.html , given that they're pretty closely related what do you think about combining them?20:15
lbragstadyeah - that's probably a good idea20:15
*** jamesmcarthur has quit IRC20:15
lbragstadat the time i think i was a little cautious about bloating specs20:16
cmurphyalright i will take a stab at that20:17
*** awalende has quit IRC20:19
lbragstadthanks cmurphy20:19
*** awalende has joined #openstack-keystone20:20
*** awalende has quit IRC20:24
*** itlinux has joined #openstack-keystone20:27
*** jamesmcarthur has joined #openstack-keystone20:31
*** jamesmcarthur_ has joined #openstack-keystone20:37
*** jamesmcarthur has quit IRC20:40
openstackgerritColleen Murphy proposed openstack/keystone-specs master: Combine policy roadmap documents  https://review.opendev.org/65915920:41
*** jamesmcarthur_ has quit IRC20:41
*** vishalmanchanda has quit IRC20:44
*** jamesmcarthur has joined #openstack-keystone20:47
*** jamesmcarthur has quit IRC20:50
*** jamesmcarthur has joined #openstack-keystone20:55
*** jamesmcarthur has quit IRC20:55
*** jamesmcarthur has joined #openstack-keystone20:55
*** jamesmcarthur has quit IRC20:59
*** raildo has quit IRC21:05
*** itlinux has quit IRC21:07
openstackgerritJim Rollenhagen proposed openstack/keystone master: Revert "Blacklist bandit 1.6.0"  https://review.opendev.org/65916421:10
jroll^ this is a much cleaner fix, when folks have time21:10
*** jamesmcarthur has joined #openstack-keystone21:20
*** joshualyle has joined #openstack-keystone21:23
*** dklyle has joined #openstack-keystone21:27
joshualyleI'm trying to configure LDAP on keystone at the moment and I've set driver=sql, domain_config_dir=/etc/keystone/domains, and domain_specific_drivers_enabled=True in the [identity] section and created a /etc/keystone/domains/blah.conf for my LDAP. How do I indicate that I want to login with LDAP vs the default SQL-based auth on the login page or do I need to set the multi-domain setting on horizon to make that distinction?21:28
cmurphyjoshualyle: you need to use the multi-domain setting in horizon to let the user type or select the domain21:29
joshualyleso you can have EITHER the default SQL creds or LDAP?21:29
joshualylefor the default style login21:29
*** jamesmcarthur has quit IRC21:30
*** jamesmcarthur has joined #openstack-keystone21:31
cmurphyfor the default login without setting up multidomain in horizon it would just default to the Default domain and ldap users wouldn't be able to log in21:32
*** jamesmcarthur has quit IRC21:36
*** jamesmcarthur has joined #openstack-keystone21:40
*** jamesmcarthur has quit IRC21:44
*** dklyle has quit IRC21:44
*** dklyle has joined #openstack-keystone21:44
*** mchlumsky has quit IRC21:47
*** dklyle has quit IRC21:50
*** rcernin has joined #openstack-keystone22:00
*** whoami-rajat has quit IRC22:18
*** tkajinam has joined #openstack-keystone22:52
joshualyleI'm trying to figure out ldap auth but cannot get it for the life of me. I can see the record just fine with the ldapsearch command but keystone is using (objectClass=xxxx) as a filter and it seems like that's throwing everything off. Is there a way to get it to just search by cn?23:07
joshualylethe ldap record has 4 definitions for objectClass23:07
*** jamesmcarthur has joined #openstack-keystone23:17
joshualyleis there a way to disable keystone from trying to filter by user_id_attribute or user_objectclass? I can find the record just fine with just wildcarding them with ldapsearch but whatever keystone does with them prevents the record from being found23:26
openstackgerritMerged openstack/keystone master: Fix documentation typo  https://review.opendev.org/65911823:44
*** irclogbot_0 has quit IRC23:45
*** lbragstad has quit IRC23:47
*** irclogbot_2 has joined #openstack-keystone23:48
*** jamesmcarthur has quit IRC23:49
*** itlinux has joined #openstack-keystone23:49
*** jamesmcarthur has joined #openstack-keystone23:49
*** jamesmcarthur has quit IRC23:54

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!