Wednesday, 2023-08-16

*** blarnath is now known as d34dh0r5313:31
vishalmanchandahello Keystone team, Is there any detailed blog or document which I can refer to enable Time-based One-time Password (TOTP) in my devstack env.?14:07
vishalmanchandathanks14:07
dmendiza[m]🙋15:01
d34dh0r53vishalmanchanda: not that I'm aware of, that's kind of a choose your own adventure at this point15:01
d34dh0r53#startmeeting keystone15:01
opendevmeetMeeting started Wed Aug 16 15:01:42 2023 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:01
opendevmeetThe meeting name has been set to 'keystone'15:01
d34dh0r53#topic roll call15:01
noonedeadpunko/15:01
hiromuo/15:02
dmendiza[m]🙋15:02
d34dh0r53admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla[m], lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m]15:02
d34dh0r53o/15:02
knikollao/15:02
d34dh0r53#topic review past meeting work items15:02
d34dh0r53d34dh0r53 Look into adding/restoring a known issues section to our documentation15:03
d34dh0r53I've started looking into this, we don't have a section and I'm investigating adding one15:03
d34dh0r53so I'll carry it forward15:03
d34dh0r53#action d34dh0r53 Look into adding/restoring a known issues section to our documentation15:03
d34dh0r53the next item as well15:04
noonedeadpunkisn't that part of release notes?15:04
noonedeadpunkexcept - you'd need to move renos between releases to keep known issues there15:04
d34dh0r53#action d34dh0r53 add https://bugs.launchpad.net/keystone/+bug/1305950 to the known issues section of our documentation15:05
d34dh0r53yeah, I think it's for more long lived known issues, stuff that is idiosyncratic to keystone, and issues that are likely not to be fixed with well known workarounds15:06
d34dh0r53d34dh0r53 investigate switching the default hashing algo to scrypt in 2024.x15:06
d34dh0r53is next up, noonedeadpunk I know you did some work related to this AI this past week, I haven't had a chance to look at anything15:07
noonedeadpunkyeah, patch for https://bugs.launchpad.net/keystone/+bug/2029134 proposed and needs to be reviewed15:08
noonedeadpunkit also needs to be backported to 2023.115:08
noonedeadpunkFix for https://bugs.launchpad.net/openstack-ansible/+bug/2028809 has merged on master and backports proposed to affected stable branches15:09
noonedeadpunk#link https://review.opendev.org/q/Iea95a3c2df041a0046647b3d3dadead1a6d054d115:10
noonedeadpunkI didn't look into this one though15:10
noonedeadpunk#link https://bugs.launchpad.net/keystone/+bug/203006115:10
d34dh0r53ack15:11
d34dh0r53I think maybe a good first step to the hashing algo is to get https://review.opendev.org/c/openstack/keystone/+/891024/3 tested and merged15:13
d34dh0r53We can then look into perhaps making that the default in 2024.x15:13
d34dh0r53Since there is no length limitation with the additional hash and we're still using bcrypt I'm thinking that is a good way to go.15:14
d34dh0r53#action d34dh0r53 test https://review.opendev.org/c/openstack/keystone/+/891024/315:15
d34dh0r53next up15:15
d34dh0r53noonedeadpunk and d34dh0r53 are looking for a workaround/fix for https://bugs.launchpad.net/keystone/+bug/202880915:15
d34dh0r53I think this has been resolved in https://review.opendev.org/c/openstack/keystone/+/89093615:16
noonedeadpunkyup15:16
d34dh0r53thank you for the patch noonedeadpunk 15:16
d34dh0r53next up we have hiromu is going to look at https://bugs.launchpad.net/keystone/+bug/202913415:16
d34dh0r53this has a patch up https://review.opendev.org/c/openstack/keystone/+/89152115:17
d34dh0r53hiromu: were you able to look at this patch?15:17
hiromusure15:17
d34dh0r53thank you!15:18
hiromu:)15:18
d34dh0r53#action hiromu test and review https://review.opendev.org/c/openstack/keystone/+/89152115:18
d34dh0r53ok, that does it for the past week action items15:18
d34dh0r53next up15:18
d34dh0r53#topic liaison updates15:18
d34dh0r53nothing from VMT15:18
d34dh0r53cool, moving on15:21
d34dh0r53#topic specification OAuth 2.0 (hiromu)15:21
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:22
d34dh0r53External OAuth 2.0 Specification15:22
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/86155415:23
d34dh0r53OAuth 2.0 Implementation15:23
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Fsupport-oauth2-mtls15:23
d34dh0r53OAuth 2.0 Documentation15:23
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/83810815:23
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/83810415:23
hiromuno update this week. I hope topic https://review.opendev.org/q/topic:bp%252Fenhance-oauth2-interoperability will be reviwered within this cycle if possible15:23
d34dh0r53I will add it to the reviewathon15:24
d34dh0r53thank you hiromu 15:24
d34dh0r53next up15:24
d34dh0r53#topic Secure RBAC (dmendiza[m])15:25
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:25
d34dh0r53Manager Role Implementation15:25
dmendiza[m]Not a whole lot of progress15:25
d34dh0r53#link https://review.opendev.org/c/openstack/keystone/+/82260115:25
d34dh0r53ack, thanks dmendiza[m] 15:25
dmendiza[m]we had the pop-up meeting yesterday15:25
dmendiza[m]and I'll be helping gmann update an srbac patch15:25
d34dh0r53cool15:26
d34dh0r53#topic open discussion15:28
d34dh0r53(reqa) Add openstack cli support for OAuth 2.0 Device Authorization Grant with PKCE:15:28
d34dh0r53review request15:28
d34dh0r53#link https://review.opendev.org/c/openstack/keystoneauth/+/88385215:28
d34dh0r53Reasoning: When switching wsgi-keystone.conf to use PKCE for WebSSO, this also applies to the CLI (e.g. ForgeRock implemented the same)15:28
d34dh0r53this has merged, thanks all!15:28
d34dh0r53removing it from the doc15:29
d34dh0r53next up15:29
d34dh0r53OAuth2.0 External Authorization Server Support (hiromu)15:29
d34dh0r53Where is an appropriate place to put the user guide15:29
dmendiza[m]https://opendev.org/openstack/keystone/src/branch/master/doc/source/user ?15:30
hiromubut it's about keystonemiddleware15:31
d34dh0r53slightly off topic, is there a reason keystone isn't listed here: https://docs.openstack.org/2023.1/projects.html ?15:32
hiromuI think d34dh0r53 has given us the answer that https://docs.openstack.org/keystonemiddleware/latest/middlewarearchitecture.html can be appropriate last week.15:33
dmendiza[m]hiromu https://opendev.org/openstack/keystonemiddleware/src/branch/master/doc/source 15:33
dmendiza[m]d34dh0r53: seems like a doc site bug.  For some reason Identity doesn't show up in the stable branches15:33
d34dh0r53yes hiromu that is correct, I think that's where it should go and I should have moved that topic to the archive15:34
zaitcevindeed, this seems to contain Identity: https://docs.openstack.org/2023.2/projects.html15:34
d34dh0r53#action d34dh0r53 look into doc bug of missing Identity section on https://docs.openstack.org/2023.1/projects.html15:34
hiromuthanks d34dh0r53: and dmendiza:15:35
d34dh0r53ack, that does it for open discussion15:35
d34dh0r53#topic bug review15:36
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:36
d34dh0r53no new bugs for keystone15:36
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:36
d34dh0r53nor for python-keystoneclient15:37
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:37
d34dh0r53keystoneauth is good15:37
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:37
d34dh0r53as it keystonemiddleware15:37
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:37
d34dh0r53pycadf is clean15:38
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:38
d34dh0r53and ldappool is also clean15:38
d34dh0r53#topic conclusion15:38
d34dh0r53No reviewathon this week as it's a recharge day for Red Hat15:39
d34dh0r53anyone have anything else before we close?15:39
zaitcevGuess not.15:40
d34dh0r53guess not :)15:42
d34dh0r53thanks folks!15:42
d34dh0r53#endmeeting15:42
opendevmeetMeeting ended Wed Aug 16 15:42:39 2023 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:42
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-08-16-15.01.html15:42
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-08-16-15.01.txt15:42
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2023/keystone.2023-08-16-15.01.log.html15:42

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!