Tuesday, 2020-10-27

*** gyee has quit IRC00:21
*** spatel has joined #openstack-keystone00:36
*** mugsie has quit IRC01:00
*** mugsie has joined #openstack-keystone01:04
*** raildo has quit IRC01:06
*** dave-mccowan has quit IRC01:20
cmurphybbezak: i'm not sure what's wrong but it might actually be a problem with the catalog, as it says? when i try to reproduce (federated user with an app cred running osc server list) the catalog appears in the debug output01:27
cmurphyif you're able to access it as a regular user i would try that and see if it's working properly that way01:28
*** brinzhang_ has joined #openstack-keystone02:25
brinzhang_hi, who can send the wallaby PTG plan? thanks02:25
*** rcernin has quit IRC02:38
*** ayoung has quit IRC03:03
*** rcernin has joined #openstack-keystone03:06
*** spatel has quit IRC03:15
*** rcernin has quit IRC03:26
*** rcernin has joined #openstack-keystone03:47
*** rcernin has quit IRC03:47
*** rcernin has joined #openstack-keystone03:47
*** vishalmanchanda has joined #openstack-keystone05:28
*** evrardjp has quit IRC05:33
*** evrardjp has joined #openstack-keystone05:33
openstackgerritKeigo Noha proposed openstack/keystone master: Support bytes type in generate_public_ID()  https://review.opendev.org/75981206:17
*** abdysn has joined #openstack-keystone06:51
*** bengates has joined #openstack-keystone07:56
*** bengates has quit IRC07:56
*** bengates has joined #openstack-keystone07:56
openstackgerritKeigo Noha proposed openstack/keystone master: Support bytes type in generate_public_ID()  https://review.opendev.org/75981208:04
bbezakcmurphy: non-federated users' app credentials works fine. both in default domain and federated users' one. Will try to debug this mode, thx08:13
*** rcernin has quit IRC08:23
*** spatel has joined #openstack-keystone10:05
*** spatel has quit IRC10:10
*** takamatsu is now known as mauro|call10:37
*** mauro|call is now known as takamatsu10:37
*** gshippey has joined #openstack-keystone10:55
*** abdysn has quit IRC12:21
*** raildo has joined #openstack-keystone12:23
*** wey_gu has joined #openstack-keystone12:28
*** Luzi has joined #openstack-keystone12:55
*** wey_gu has quit IRC12:59
*** dave-mccowan has joined #openstack-keystone13:07
*** Luzi has quit IRC13:31
*** brinzhang_ has quit IRC13:37
*** sapd1 has quit IRC13:44
*** sapd1 has joined #openstack-keystone13:44
*** dave-mccowan has quit IRC13:46
*** dave-mccowan has joined #openstack-keystone13:49
*** oklhost has joined #openstack-keystone14:11
bbezakcmurphy: I've found several things during investigation issues of mine with application credentials for federated users:14:41
bbezak- https://bugs.launchpad.net/keystone/+bug/1832092 still affects keystone 17.0, even after fixes from https://bugs.launchpad.net/keystone/+bug/1809116 - I am not able to create application credential via horizon when group membership coming from federation only14:41
openstackLaunchpad bug 1809116 in OpenStack Identity (keystone) "duplicate for #1832092 [rfe] Expiring User Group Memberships" [High,Fix released] - Assigned to Kristi Nikolla (knikolla)14:41
bbezak- I was able to find correct IDP mapping to create working application credential - mapping to existing project, instead of group - http://paste.openstack.org/raw/LxCnfTQ7Uuqk6bPQz80l/14:41
bbezak- Application credential that was not working has "None" Project ID field.14:41
bbezak- For group mapping, I tested also "default_authorization_ttl" configuration value. However with that enabled - application credenitals where also made with "None" Project ID field - giving "The service catalog is empty" as before14:41
openstackLaunchpad bug 1809116 in OpenStack Identity (keystone) "[rfe] Expiring User Group Memberships" [High,Fix released] - Assigned to Kristi Nikolla (knikolla)14:41
*** Luzi has joined #openstack-keystone14:44
*** bengates_ has joined #openstack-keystone15:18
*** bengates has quit IRC15:19
*** gyee has joined #openstack-keystone15:34
*** Luzi has quit IRC16:50
*** bengates has joined #openstack-keystone16:56
*** bengates_ has quit IRC16:59
*** bengates has quit IRC17:01
*** ricolin has quit IRC17:10
cmurphybbezak: ah interesting, i was going to blame #1809116 but i thought that was fixed in ussuri17:11
cmurphyi feel like i saw the "None" project ID problem before but I don't see a bug report for it17:11
cmurphywonder if knikolla knows more ^17:12
*** vishalmanchanda has quit IRC17:30
*** legochen has quit IRC19:20
*** melwitt has joined #openstack-keystone20:07
openstackgerritGage Hugo proposed openstack/keystone master: Hide AccountLocked exception from end users  https://review.opendev.org/75994020:24
bbezakcmurphy: I guess mr Knikolla will be around during PTG :). I can raise a bug as well though20:41
*** gouthamr has quit IRC20:58
*** gouthamr has joined #openstack-keystone20:59
*** gouthamr has quit IRC20:59
*** gouthamr has joined #openstack-keystone20:59
*** raildo has quit IRC21:05
*** rcernin has joined #openstack-keystone23:02
*** gshippey has quit IRC23:32

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!