[Yahoo-eng-team] [Bug 1634568] Re: [api] Inconsistency between v3 API and keystone token timestamps

2017-01-03 Thread Brant Knudson
https://review.openstack.org/#/c/413878/ didn't fix the problem. The timestamps in the v3 token issue response still doesn't match the spec as described in the bug description. ** Changed in: keystone Status: Fix Released => New ** Changed in: keystone Milestone: ocata-3 => None -- Y

[Yahoo-eng-team] [Bug 1634568] Re: Inconsistency between v3 API and keystone token timestamps

2016-12-13 Thread Brant Knudson
The v3 documentation is still incorrect. ** Changed in: keystone Status: Invalid => New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1634568 Title: Incons

[Yahoo-eng-team] [Bug 1634568] [NEW] Inconsistency between v3 API and keystone token timestamps

2016-10-18 Thread Brant Knudson
Public bug reported: The v3 API spec for tokens documents the format of timestamps[1]. It says the format is like "CCYY-MM-DDThh:mm:ss±hh:mm". By this, the timestamps returned by keystone should be like 2016-10-17T15:17:03+00:00. But they actually show up like this: V3: "issued_at": "2016-10-17T

[Yahoo-eng-team] [Bug 1615111] [NEW] Useless log message about encryption key loading.

2016-08-19 Thread Brant Knudson
Public bug reported: When running keystone with fernet enabled I get a lot of log messages like this: 2016-08-16 19:54:28.782 2417 INFO keystone.token.providers.fernet.utils [req-1bbe529c-2513-487b-ac4e-e7ee42fe397a - - - - -] Loaded 2 encryption keys (max_active_keys=3) from: /etc/keystone/fer

[Yahoo-eng-team] [Bug 1610409] Re: s.u.p.p.o.r.t @.1800, 6817 208 @ HUSHMAIL s.u.p.p.o.r.t P.h.o.n.e N.u.m.b.e.r HUSHMAIL t.e.c.hnical s.u.p.p.o.rt n.u.m.b.e.r HUSHMAIL c.u.s.t.o.m.e.r s.u.p.p.o.r.t p

2016-08-05 Thread Brant Knudson
** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1610409 Title: s.u.p.p.o.r.t @.1800,6817 208 @ HUSHMAIL s.u.p.p

[Yahoo-eng-team] [Bug 1609566] [NEW] 500 error from revocation event deserialize

2016-08-03 Thread Brant Knudson
File "msgpack/_unpacker.pyx", line 139, in msgpack._unpacker.unpackb (msgpack/_unpacker.cpp:139) File "keystone/local/lib/python2.7/site-packages/oslo_serialization/msgpackutils.py", line 401, in _unserializer return handler.deserialize(data) File "keystone

[Yahoo-eng-team] [Bug 1590179] [NEW] fernet memcache performance regression

2016-06-07 Thread Brant Knudson
Public bug reported: Fernet token validation performance got worse in mitaka vs in liberty. This is because it's not using memcache to cache the token anymore. ** Affects: keystone Importance: Undecided Status: New ** Tags: fernet -- You received this bug notification because

[Yahoo-eng-team] [Bug 1563101] Re: Remove backend dependency on core

2016-03-29 Thread Brant Knudson
The core shouldn't know about the backends. Each backend is optional so the backend might not even be available. ** Changed in: keystone Status: In Progress => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenSta

[Yahoo-eng-team] [Bug 1550017] [NEW] keystone eventlet using session is in 'prepared' state

2016-02-25 Thread Brant Knudson
Public bug reported: http://logs.openstack.org/58/257458/5/check/gate-tempest-dsvm-keystone-eventlet-full/2441200/logs/screen-key.txt.gz#_2016-02-24_17_26_26_453 Many operations are failing with an exception: This session is in 'prepared' state; no further SQL can be emitted within this transac

[Yahoo-eng-team] [Bug 1549371] [NEW] Deprecation message when using default keystone-paste.ini

2016-02-24 Thread Brant Knudson
tance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1549371 Title: Deprecation message

[Yahoo-eng-team] [Bug 1548562] [NEW] Misleading response when try to delete project with children

2016-02-22 Thread Brant Knudson
in the hierarchy. This is misleading since the problem has nothing to do with authority and granting more authority isn't going to allow the operation to work. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received

[Yahoo-eng-team] [Bug 1547214] [NEW] Domain created by keystone-manage bootstrap has no description

2016-02-18 Thread Brant Knudson
tone- manage db_sync, which it normally is. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identi

[Yahoo-eng-team] [Bug 1488208] Re: Revoking a role assignment revokes unscoped tokens too

2016-02-15 Thread Brant Knudson
** Changed in: keystone/kilo Status: Fix Released => In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1488208 Title: Revoking a role assignment rev

[Yahoo-eng-team] [Bug 1317302] Re: pki_setup shouldn't be required to check revocations

2016-02-05 Thread Brant Knudson
The revocation list is signed by the PKI certificates for some reason. The revocation list is used for UUID tokens in addition to PKI tokens. This fix is making it so that the revocation list is not signed by the PKI certificates. ** Changed in: keystone Status: Won't Fix => In Progress -

[Yahoo-eng-team] [Bug 1529193] Re: ec2 credentials create broken in python3

2016-01-20 Thread Brant Knudson
We've got a blueprint for this, since keystone doesn't claim to support python 3. https://blueprints.launchpad.net/keystone/+spec/python3 ** Changed in: keystone Status: New => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is su

[Yahoo-eng-team] [Bug 1532345] [NEW] enabled emulation query must filter tree dn

2016-01-08 Thread Brant Knudson
might as well fix it. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1525275] Re: Loading configuration items from keystoneauth is causing warnings

2015-12-11 Thread Brant Knudson
** Also affects: keystoneauth Importance: Undecided Status: New ** No longer affects: keystone -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1525275 Title

[Yahoo-eng-team] [Bug 1513102] [NEW] Useless deprecation message for driver import

2015-11-04 Thread Brant Knudson
driver is deprecated as of Liberty in favor of entrypoints and may be removed in N. The deprecation warning is pretty useless. It should at least include the string that was used so that I can figure out what to change. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk

[Yahoo-eng-team] [Bug 1453419] Re: Remove workaround for db2 dialect primary key issue

2015-10-15 Thread Brant Knudson
Marking this as invalid since we didn't provide migration 73 with the problem, it was only in review. ** Changed in: keystone Status: In Progress => Fix Released ** Changed in: keystone Status: Fix Released => Invalid -- You received this bug notification because you are a member

[Yahoo-eng-team] [Bug 1479962] Re: Use extras for deployment-specific package requirements

2015-10-15 Thread Brant Knudson
This was released in keystone liberty. ** Changed in: keystone Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1479962 Title: Use extras for d

[Yahoo-eng-team] [Bug 1505326] Re: Unit tests failing with requests 2.8.0

2015-10-14 Thread Brant Knudson
here's new releases. That's bug 1505996 . ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) ** Changed in: keystone Status: Confirmed => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is sub

[Yahoo-eng-team] [Bug 1505374] [NEW] Unit tests failing with oslo.policy 0.12.0

2015-10-12 Thread Brant Knudson
d and they have their own tests. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engin

[Yahoo-eng-team] [Bug 1505326] [NEW] Unit tests failing with requests 2.8.0

2015-10-12 Thread Brant Knudson
Public bug reported: When the tests are run, a bunch of them fail: pkg_resources.ContextualVersionConflict: (requests 2.8.0 (/home/jenkins/workspace/gate-keystone-python27/.tox/py27/lib/python2.7 /site-packages), Requirement.parse('requests!=2.8.0,>=2.5.2'), set(['oslo.policy'])) global-require

[Yahoo-eng-team] [Bug 1500509] [NEW] Define paste entrypoints

2015-09-28 Thread Brant Knudson
Public bug reported: oslo.middleware middlewares should define the entry points for the factories. In setup.cfg: [entry_points] paste.filter_factory = request_id = oslo_middleware:RequestId.factory (Or whatever you want to call the entrypoint) Then we can use it in keystone instead of defi

[Yahoo-eng-team] [Bug 1500459] [NEW] Validating federated fernet token loses user domain info

2015-09-28 Thread Brant Knudson
en/providers/common.py?id=3d989e8815c5fe932bb6e7a3e0541e8c75046225#n589 [2] http://git.openstack.org/cgit/openstack/keystone/tree/keystone/models/token_model.py?id=3d989e8815c5fe932bb6e7a3e0541e8c75046225#n112 ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress

[Yahoo-eng-team] [Bug 1500222] [NEW] Request info in logs

2015-09-27 Thread Brant Knudson
ant=self.tenant or '-', domain=self.domain or '-', user_domain=self.user_domain or '-', p_domain=self.project_domain or '-')) ** Affects: k

[Yahoo-eng-team] [Bug 1496998] [NEW] fernet token provider is experimental

2015-09-17 Thread Brant Knudson
rning message should be logged ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/14

[Yahoo-eng-team] [Bug 1496530] [NEW] debug note in error response inaccurate

2015-09-16 Thread Brant Knudson
e requires authentication.", "code": 401, "title": "Unauthorized"}} No details have been suppressed. The only difference is that the note about disabling debug mode has been removed. The message shouldn't be saying to disable debug mode to suppress

[Yahoo-eng-team] [Bug 1496041] [NEW] Document accept requests on base paths rather than separate ports

2015-09-15 Thread Brant Knudson
5000 and 35357 and instead use :443/identity and /identity_admin. ** Affects: keystone Importance: Wishlist Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keysto

[Yahoo-eng-team] [Bug 1494330] [NEW] Requirements update is failing

2015-09-10 Thread Brant Knudson
strip comments when updating setup.cfg. ** Affects: keystone Importance: Critical Assignee: Brant Knudson (blk-u) Status: Confirmed -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net

[Yahoo-eng-team] [Bug 1490160] [NEW] Unit tests are super slow

2015-08-29 Thread Brant Knudson
;t be initializing the paste pipeline for tests that only need to validate driver / backend / controller behavior. This affects developer productivity since it takes too long to validate changes locally. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Statu

[Yahoo-eng-team] [Bug 1489118] [NEW] Tests fail with local keystone.conf modifications

2015-08-26 Thread Brant Knudson
config file. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which

[Yahoo-eng-team] [Bug 1485604] [NEW] Logs must contain the request ID

2015-08-17 Thread Brant Knudson
Public bug reported: The keystone log file doesn't have the request ID like the other projects. The log file should contain the request ID so that it's easier to debug. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progres

[Yahoo-eng-team] [Bug 1484735] [NEW] Assertion signing error causes TypeError for Message objects do not support addition

2015-08-13 Thread Brant Knudson
n, which the code is attempting to do. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net

[Yahoo-eng-team] [Bug 1474069] Re: DeprecatedDecorators test does not setup fixtures correctly

2015-08-07 Thread Brant Knudson
** Also affects: oslo.log Importance: Undecided Status: New ** Changed in: oslo.log Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. ht

[Yahoo-eng-team] [Bug 1482687] [NEW] enabled emulation query should request no attributes

2015-08-07 Thread Brant Knudson
be slightly more efficient to request no attributes instead since there's less data for the LDAP server to return. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knud

[Yahoo-eng-team] [Bug 1482662] [NEW] Remove deprecated methods from assignment manager

2015-08-07 Thread Brant Knudson
** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1482660] [NEW] Stop using deprecated methods in assignment manager

2015-08-07 Thread Brant Knudson
keystone/assignment/core.py and running the tests. The tests should all work (except for the ones to verify that the deprecated methods are there). ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification

[Yahoo-eng-team] [Bug 1481048] [NEW] Sample httpd config should have LimitRequestBody

2015-08-03 Thread Brant Knudson
crashing the server by sending large requests, causing a DoS. As such, keystone's sample httpd file should specify LimitRequestBody so that deployers know to set it. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You rec

[Yahoo-eng-team] [Bug 1479962] [NEW] Use extras for deployment-specific package requirements

2015-07-30 Thread Brant Knudson
Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1479962 Title: Use extras for deployment-specific package re

[Yahoo-eng-team] [Bug 1479523] [NEW] Stop using debug for insecure responses

2015-07-29 Thread Brant Knudson
ed to improve security a bit. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Tags: security -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpa

[Yahoo-eng-team] [Bug 1468000] Re: Group lookup by name in LDAP via v3 fails

2015-07-24 Thread Brant Knudson
** Also affects: keystone/kilo Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1468000 Title: Group lookup by name in LDAP via v3 fails Statu

[Yahoo-eng-team] [Bug 1424496] Re: Documentation lacking for mapping of operation policy target

2015-07-19 Thread Brant Knudson
Reopening since the previous fix was reverted. ** Changed in: keystone Status: Fix Released => In Progress ** Changed in: keystone Milestone: 2015.1.0 => liberty-2 -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keysto

[Yahoo-eng-team] [Bug 1473553] [NEW] AuthContextMiddleware re-implements AdminToken

2015-07-10 Thread Brant Knudson
tMiddleware decided to re-implement AdminTokenAuthMiddleware rather than using its output (the setting of is_admin in the context. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned

[Yahoo-eng-team] [Bug 1459828] Re: keystone-all crashes when ca_certs is not defined in conf

2015-07-10 Thread Brant Knudson
icehouse is now eol, so I don't see any need to spend more time on this. ** Changed in: keystone/icehouse Status: Incomplete => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/

[Yahoo-eng-team] [Bug 1469867] Re: Stop using deprecated oslo_utils.timeutils.strtime

2015-06-29 Thread Brant Knudson
** Also affects: keystonemiddleware Importance: Undecided Status: New ** Changed in: keystonemiddleware Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keyst

[Yahoo-eng-team] [Bug 1469867] Re: Stop using deprecated oslo_utils.timeutils.strtime

2015-06-29 Thread Brant Knudson
** Also affects: python-keystoneclient Importance: Undecided Status: New ** Changed in: python-keystoneclient Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keyst

[Yahoo-eng-team] [Bug 1469867] [NEW] Stop using deprecated oslo_utils.timeutils.strtime

2015-06-29 Thread Brant Knudson
x27;1.6' and will be removed in a future version: use either datetime.datetime.isoformat() or datetime.datetime.strftime() instead ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Br

[Yahoo-eng-team] [Bug 1469517] [NEW] Federation get_mapping_from_idp_and_protocol should return object

2015-06-28 Thread Brant Knudson
Public bug reported: The Federation manager's get_mapping_from_idp_and_protocol method is returning a dict where the 'rules' value is a JSON string. That 'rules' is stored as a JSON string is an implementation detail that shouldn't be exposed to callers. The 'rules' value of the dict returned

[Yahoo-eng-team] [Bug 1467008] Re: Unit tests fail with sqlalchemy 1.1.0

2015-06-26 Thread Brant Knudson
** Also affects: oslo.db Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1467008 Title: Unit tests fail with sqlalchemy 1.1.0 Status in OpenS

[Yahoo-eng-team] [Bug 1467008] Re: Unit tests fail with sqlalchemy 1.1.0

2015-06-26 Thread Brant Knudson
** Also affects: glance Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1467008 Title: Unit tests fail with sqlalchemy 1.1.0 Status in OpenSt

[Yahoo-eng-team] [Bug 1467008] [NEW] Unit tests fail with sqlalchemy 1.1.0

2015-06-19 Thread Brant Knudson
x27;ALTER TABLE "group" DROP CONSTRAINT fk_group_domain_id'] ** Affects: keystone Importance: High Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) ** Changed in: keystone Importance: U

[Yahoo-eng-team] [Bug 1465922] Re: Password visible in clear text in keystone.log when user created and keystone debug logging is enabled

2015-06-19 Thread Brant Knudson
Was able to recreate locally on master. ** Changed in: keystone Status: Won't Fix => Confirmed ** Changed in: keystone Importance: Undecided => Medium ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification bec

[Yahoo-eng-team] [Bug 1464366] [NEW] unit tests fail based on wall clock time

2015-06-11 Thread Brant Knudson
ue : 2015-06-11 13:34:46+00:00 != 2015-06-11 13:34:50+00:00 within 3 delta It took 4 seconds rather than 3. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New -- You received this bug notification because you are a member of Yahoo! Engineer

[Yahoo-eng-team] [Bug 1461251] Re: Stop using deprecated oslo_utils.timeutils.isotime

2015-06-07 Thread Brant Knudson
** Also affects: python-keystoneclient Importance: Undecided Status: New ** Changed in: python-keystoneclient Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keyst

[Yahoo-eng-team] [Bug 1461251] [NEW] Stop using deprecated oslo_utils.timeutils.isotime

2015-06-02 Thread Brant Knudson
Public bug reported: oslo_utils.timeutils.isotime() is deprecated as of 1.6 so we need to stop using it. This breaks unit tests in keystone since we've got a check for calling deprecated functions. ** Affects: keystone Importance: Critical Assignee: Brant Knudson (

[Yahoo-eng-team] [Bug 1449260] Re: Sanitation of metadata label

2015-05-09 Thread Brant Knudson
** Changed in: horizon Status: Fix Released => Fix Committed ** Tags added: icehouse-backport-potential juno-backport-potential kilo- backport-potential -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (H

[Yahoo-eng-team] [Bug 1453419] [NEW] Remove workaround for db2 dialect primary key issue

2015-05-09 Thread Brant Knudson
Public bug reported: Migration 73 has a workaround for ibm_db_sa issue 173 ( https://code.google.com/p/ibm-db/issues/detail?id=173 ). Once that issue is fixed we can remove the workaround. ** Affects: keystone Importance: Undecided Status: New -- You received this bug notificat

[Yahoo-eng-team] [Bug 1449850] Re: Join multiple criteria together

2015-04-30 Thread Brant Knudson
** Changed in: keystone Status: In Progress => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1449850 Title: Join multiple criteria together Status in OpenStack Identity

[Yahoo-eng-team] [Bug 1346778] Re: Neutron does not work by default without a keystone admin user

2015-04-24 Thread Brant Knudson
There appears to be a similar issue for ceilometer -- it needs admin role when it should not. ** Also affects: ceilometer Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https:/

[Yahoo-eng-team] [Bug 1445199] Re: Nova user should not have admin role

2015-04-17 Thread Brant Knudson
I think the reason the 'nova' user needs the 'admin' role is because neutron uses it to send a network allocation event back to nova. Nova should be configured by default to allow users with the 'service' role to do this operation and not require the 'admin' role. ** Information type changed from

[Yahoo-eng-team] [Bug 1445475] [NEW] neutron service user should not require admin

2015-04-17 Thread Brant Knudson
*** This bug is a security vulnerability *** Public security bug reported: The typical config has nova using the 'neutron' user in the 'service' project to do operations against Neutron. The 'neutron' user should not require the 'admin' role on the 'service' project to do all the operations it

[Yahoo-eng-team] [Bug 1441393] [NEW] keystone unit tests fail with pymongo 3.0

2015-04-07 Thread Brant Knudson
Public bug reported: pymongo 3.0 was released 2015-04-07. This causes keystone tests to fail: Traceback (most recent call last): File "keystone/tests/unit/test_cache_backend_mongo.py", line 357, in test_correct_read_preference region.set(random_key, "dummyValue10")

[Yahoo-eng-team] [Bug 1441300] [NEW] keystone-manage man page updates

2015-04-07 Thread Brant Knudson
Public bug reported: The keystone-manage man page doesn't show any of the new fernet commands, so it's out of date. ** Affects: keystone Importance: Medium Status: Confirmed ** Tags: documentation -- You received this bug notification because you are a member of Yahoo! Enginee

[Yahoo-eng-team] [Bug 1440123] [NEW] keystone-manage fails if optional fernet packages not installed

2015-04-03 Thread Brant Knudson
fernet-related should work when the non-fernet packages are not installed. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notifi

[Yahoo-eng-team] [Bug 1434103] Re: SQL schema downgrades are no longer supported

2015-03-24 Thread Brant Knudson
** Also affects: keystone Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1434103 Title: SQL schema downgrades are no longer supported Status

[Yahoo-eng-team] [Bug 1435396] [NEW] No notifications for role grants using v2

2015-03-23 Thread Brant Knudson
T_ID/users/$USER_ID/roles/$ROLE_ID ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineeri

[Yahoo-eng-team] [Bug 1434011] Re: Keystoneclient can't handle Unicode objects

2015-03-19 Thread Brant Knudson
The s3_token middleware in keystoneclient is deprecated and will only get security updates. Try this with the s3_token middleware in the keystonemiddleware package. https://github.com/openstack/python- keystoneclient/blob/master/keystoneclient/middleware/s3_token.py#L105 ** Changed in: keystone

[Yahoo-eng-team] [Bug 1432191] [NEW] Logs useless debugging issue with external auth

2015-03-14 Thread Brant Knudson
de several mistakes). This would have been easy to figure out if only the logs had mentioned that there wasn't an 'external' auth plugin registered. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed i

[Yahoo-eng-team] [Bug 1431088] [NEW] eventlet_server options reporting as deprecated

2015-03-11 Thread Brant Knudson
ns in the DEFAULT section were deprecated. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Y

[Yahoo-eng-team] [Bug 1430515] [NEW] fernet tokens tests using pending deprecation methods

2015-03-10 Thread Brant Knudson
Public bug reported: When running unit tests, a bunch of pending deprecation warnings are logged. Here's an example: /opt/stack/keystone/.tox/py27/local/lib/python2.7/site- packages/cryptography/hazmat/backends/openssl/dsa.py:177: PendingDeprecationWarning: The DSAPublicKeyWithNumbers interface

[Yahoo-eng-team] [Bug 1429663] [NEW] local tests failing in test_time_string_to_int_conversions

2015-03-08 Thread Brant Knudson
atchError: '2015-03-08T22:13:49Z' != '2015-03-08T23:13:49Z' It's off by an hour for some reason. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification because you are a me

[Yahoo-eng-team] [Bug 1408423] Re: Requirements are out of date

2015-03-08 Thread Brant Knudson
I think these fixes were released some time ago. ** Changed in: keystone Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1408423 Title: Requir

[Yahoo-eng-team] [Bug 1424061] Re: keystone server should default to localhost-only

2015-03-04 Thread Brant Knudson
** Changed in: keystone Status: In Progress => Won't Fix ** Changed in: keystone Assignee: Brant Knudson (blk-u) => (unassigned) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.la

[Yahoo-eng-team] [Bug 1424496] [NEW] Documentation lacking for mapping of operation policy target

2015-02-22 Thread Brant Knudson
x27;s no way to tell this without reading the code because there's no documentation for it. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u

[Yahoo-eng-team] [Bug 1424089] [NEW] Use SystemRandom rather than random

2015-02-20 Thread Brant Knudson
*** This bug is a security vulnerability *** Public security bug reported: SystemRandom should be preferred over direct use of random. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification

[Yahoo-eng-team] [Bug 1424061] [NEW] keystone server should default to localhost-only

2015-02-20 Thread Brant Knudson
*** This bug is a security vulnerability *** Public security bug reported: By default keystone will listen on all interfaces. Keystone should use secure defaults. In this case, listen on localhost-only by default. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson

[Yahoo-eng-team] [Bug 1421971] [NEW] get_endpoint_group_in_project missing from sample policy files

2015-02-14 Thread Brant Knudson
file so admins know what's available. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Ya

[Yahoo-eng-team] [Bug 1421966] [NEW] Getting role for trust is double-protected

2015-02-14 Thread Brant Knudson
Public bug reported: The function for getting or checking a role for trust (GET/HEAD /v3/OS-TRUST/trusts/{trust_id}/roles/{role_id}) winds up being protected first by `get_role_for_trust` and then by `check_role_for_trust`. This is because get_role_for_trust winds up calling self.check_role_fo

[Yahoo-eng-team] [Bug 1421968] [NEW] List Endpoint Groups Associated with project not routed

2015-02-14 Thread Brant Knudson
Public bug reported: I was looking through the sample policy.json file and noticed that the "identity:list_endpoint_groups_for_project" target doesn't have a corresponding mapping in the routers[1]. Looks like there's supposed to be a router mapping /v3/OS-EP-FILTER/endpoint_groups/projects/{p

[Yahoo-eng-team] [Bug 1421825] [NEW] Sample policy should allow user to validate and revoke own token

2015-02-13 Thread Brant Knudson
ken: $TOKEN" -H "X-Subject-Token: $TOKEN" http://localhost:35357/v3/auth/tokens {"error": {"message": "You are not authorized to perform the requested action: identity:revoke_token (Disable debug mode to suppress these details.)", "code": 403, &q

[Yahoo-eng-team] [Bug 1421668] [NEW] Tenant in v2 token response has parent_project_id

2015-02-13 Thread Brant Knudson
Public bug reported: When I get a token using the v2 API, the tenant now has "parent_project_id". The parent_project_id shouldn't be there in a v2 token, and probably not in a v3 token either. This is an unnecessary field and it makes the tokens larger than they need to be. RESP BODY: {"acces

[Yahoo-eng-team] [Bug 1420863] [NEW] Default setting should be secure

2015-02-11 Thread Brant Knudson
Public bug reported: Horizon has some instructions for setting it up in a secure way[1]. These settings should be the default. [1] http://docs.openstack.org/developer/horizon/topics/deployment.html #secure-site-recommendations ** Affects: horizon Importance: Undecided Status: New

[Yahoo-eng-team] [Bug 1401664] Re: Update role using LDAP backend requires name

2015-02-09 Thread Brant Knudson
This was fixed in master with https://review.openstack.org/#/c/141186/ and juno with https://review.openstack.org/#/c/142552/ . I put the wrong bug in the commit message. ** Changed in: keystone Status: New => Fix Released -- You received this bug notification because you are a member of

[Yahoo-eng-team] [Bug 1408658] [NEW] migration 61 downgrade fails using mysql

2015-01-08 Thread Brant Knudson
_constraints(meta)) 2015-01-08 08:29:56.494 TRACE keystone File "/opt/stack/keystone/keystone/common/sql/migrate_repo/versions/061_add_parent_project.py", line 24, in list_constraints 2015-01-08 08:29:56.494 TRACE keystone 'ref_column': project_table.c.id}] 2015-01-08 08:29:56.4

[Yahoo-eng-team] [Bug 1408423] [NEW] Requirements are out of date

2015-01-07 Thread Brant Knudson
s on their packages. Also, if the requirement isn't used by keystone or any of the other dependencies then it won't need to be installed in the tox venv and make testing faster. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Pro

[Yahoo-eng-team] [Bug 1408389] [NEW] Tests shouldn't rely on provider registration by import

2015-01-07 Thread Brant Knudson
t be using @dependency.requires to inject dependencies -- this is for use by keystone server parts. The tests have their own way of getting dependencies injected by loading the manager, which is similar to how the Keystone server works. ** Affects: keystone Importance: Undecided Assignee: Brant Knud

[Yahoo-eng-team] [Bug 1408384] [NEW] Providers must be created only once

2015-01-07 Thread Brant Knudson
fects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed

[Yahoo-eng-team] [Bug 1407273] [NEW] Unit tests failing with deprecation errors setuptools 10.2

2015-01-03 Thread Brant Knudson
: `require` parameter is deprecated. Use EntryPoint._load instead. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to

[Yahoo-eng-team] [Bug 1213106] Re: TypeError: an integer is required

2015-01-01 Thread Brant Knudson
/ I ported the fix to oslo.middleware: https://review.openstack.org/#/c/144700/ ** Also affects: oslo.middleware Importance: Undecided Status: New ** Changed in: oslo.middleware Assignee: (unassigned) => Brant Knudson (blk-u) ** Changed in: oslo.middleware Status: New =&

[Yahoo-eng-team] [Bug 1401721] [NEW] Update role using LDAP backend with same name fails

2014-12-11 Thread Brant Knudson
{"name": "anotherrole"}}' \ http://localhost:35357/v3/roles/$ROLE_ID {"error": {"message": "Cannot duplicate name {'id': u'36a9eede308d41e8a92effce2e46cc4a', 'name': u'anotherrole'}", "code&quo

[Yahoo-eng-team] [Bug 1401664] [NEW] Update role using LDAP backend requires name

2014-12-11 Thread Brant Knudson
ate without a name. $ curl -X PATCH \ -H "X-Auth-Token: $TOKEN" \ -H "Content-Type: application/json" \ -d '{"role": {"enabled": false}}' \ http://localhost:35357/v3/roles/$ROLE_ID {"error": {"message": &

[Yahoo-eng-team] [Bug 1395368] Re: ExternalNetworksTest[JSON, XML].test_delete_external_networks_with_floating_ip failures

2014-11-29 Thread Brant Knudson
Since https://review.openstack.org/#/c/135903/ is merged things seem to be working again. ** No longer affects: keystonemiddleware -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1395368 T

[Yahoo-eng-team] [Bug 1374497] Re: change in oslo.db "ping" handling is causing issues in projects that are not using transactions

2014-11-25 Thread Brant Knudson
There's a fix in oslo.db. The work to update Keystone will be part of a spec or blueprint to use new features in oslo.db once they're ready. I don't think it's worth keeping a bug open. ** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you

[Yahoo-eng-team] [Bug 1387401] [NEW] token_flush can hang if lots of tokens

2014-10-29 Thread Brant Knudson
ystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. h

[Yahoo-eng-team] [Bug 1386773] [NEW] Project details request with long ID causes 500 error with DB2

2014-10-28 Thread Brant Knudson
gth in the SQL backend, although it's going to be a lot of changes. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) -- You received this bug notification

[Yahoo-eng-team] [Bug 1372422] Re: Glance exploding on configuration parsing

2014-09-22 Thread Brant Knudson
Sean - I didn't backport the change(s) to use keystonemiddleware... I can see reasons for backporting it or not backporting, so am not sure what the right thing to do is. I think it's best to look into what changed in keystoneclient.middleware recently... I'll try it with glance in devstack. ** A

[Yahoo-eng-team] [Bug 1200777] Re: No V3 extensions list

2014-09-21 Thread Brant Knudson
We won't have a v3 extensions like v2 extensions, since you can do extension discovery using the JSON Home document. ** Changed in: keystone Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to

[Yahoo-eng-team] [Bug 1366944] [NEW] Man pages out of date

2014-09-08 Thread Brant Knudson
Public bug reported: The man pages for keystone-all and keystone-manage are out of date. especially keystone-manage is missing new subcommands. ** Affects: keystone Importance: Undecided Assignee: Brant Knudson (blk-u) Status: New ** Changed in: keystone Assignee

[Yahoo-eng-team] [Bug 1366606] [NEW] oauth1 downgrade fail with sqlite

2014-09-07 Thread Brant Knudson
://www.sqlite.org/lang_altertable.html ** Affects: keystone Importance: Low Assignee: Brant Knudson (blk-u) Status: In Progress ** Changed in: keystone Assignee: (unassigned) => Brant Knudson (blk-u) ** Changed in: keystone Milestone: None => juno-rc1 ** Changed in: ke

  1   2   >