[Yahoo-eng-team] [Bug 1669080] Re: "openstack role create" should support "--description"

2017-06-30 Thread Steve Martinelli
This sounds reasonable from a CLI point of view, but I don't recall if keystone roles have a description attribute for both v2 and v3. Adding keystone as a related project. ** Also affects: keystone Importance: Undecided Status: New -- You received this bug notification because you are

[Yahoo-eng-team] [Bug 1647800] Re: keystone-manage bootstrap isn't completely idempotent

2017-02-09 Thread Steve Martinelli
** Changed in: keystone/mitaka Assignee: Steve Martinelli (stevemar) => Lance Bragstad (lbragstad) ** Changed in: keystone/mitaka Status: Fix Committed => Fix Released ** Changed in: keystone/newton Status: Fix Committed => Fix Released -- You received this bug not

[Yahoo-eng-team] [Bug 1661802] [NEW] Allow project_id in catalog substitutions

2017-02-03 Thread Steve Martinelli
Public bug reported: We allowed 'tenant_id' in catalog substitutions. The 'tenant' term is deprecated in favor of 'project'. Also allow 'project_id' so that users can stop using the deprecated term in one more place. fixed, see I4bcfbda1b542f09172f5b53185f063c6bea27205 ** Affects: keystone

[Yahoo-eng-team] [Bug 1661803] [NEW] Enable LDAP connection pooling by default

2017-02-03 Thread Steve Martinelli
Public bug reported: There should be no reason to leave these settings disabled by default. By enabling them, keystones runs faster and consumes fewer resources. ** Affects: keystone Importance: Medium Assignee: Dolph Mathews (dolph) Status: Fix Released -- You received this

[Yahoo-eng-team] [Bug 1661604] [NEW] Integrate OSprofiler in Keystone

2017-02-03 Thread Steve Martinelli
Public bug reported: OSprofiler is an Oslo library dedicated to enable cross-service OpenStack profiling. This makes possible to trace the OpenStack request through all projects supporting the library, where the profiling is enabled, and generate JSON and HTML human-readable reports, describing wh

[Yahoo-eng-team] [Bug 1660436] Re: Federated users cannot log into horizon

2017-02-02 Thread Steve Martinelli
** Changed in: horizon Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1660436 Title: Federated users cannot log into hori

[Yahoo-eng-team] [Bug 1660436] Re: Federated users cannot log into horizon

2017-02-02 Thread Steve Martinelli
Marked as invalid for keystone projects and novaclient. The fix was centralized to Horizon and DOA. ** Changed in: keystone Status: New => Invalid ** Changed in: python-novaclient Status: New => Invalid ** Changed in: keystoneauth Status: New => Invalid ** Also affects: dja

[Yahoo-eng-team] [Bug 1660436] Re: Federated users cannot log into horizon

2017-01-31 Thread Steve Martinelli
This was discussed at the keystone meeting today, the thinking is that adding domain information to the fernet token formatter may help to resolve the issues -- adding keystone as an affected project. ** Also affects: keystone Importance: Undecided Status: New ** Changed in: keystone

[Yahoo-eng-team] [Bug 1659995] [NEW] stop using per-user id settings in security_compliance

2017-01-27 Thread Steve Martinelli
ed_user_ids` is another config option we should remove, but no need to deprecate it since it was introduced in ocata (and will be removed in ocata) ** Affects: keystone Importance: High Assignee: Steve Martinelli (stevemar) Status: In Progress ** Changed in: keystone Milestone: No

[Yahoo-eng-team] [Bug 1659730] [NEW] Invalid parameter name on interface

2017-01-26 Thread Steve Martinelli
Public bug reported: Invalid parameter name on interface There are several classes that inherit from the abstract method AuthMethodHandler.authenticate. In some cases those classes are not using matching parameter names. This patch changes all classes such that the signatures match. Prior to thi

[Yahoo-eng-team] [Bug 1657978] Re: Internal Server Error: KeyError: 'domain'

2017-01-26 Thread Steve Martinelli
Eric, per your comment in #7, i will mark this as fix released for Mitaka and Newton and invalid for Ocata. see https://review.openstack.org/#/q/I213876e30fc0521195848479278080bdac8387de,n,z for details. ** Also affects: keystone/newton Importance: Undecided Status: New ** Also affects:

[Yahoo-eng-team] [Bug 1659051] Re: Use CORS set_defaults

2017-01-24 Thread Steve Martinelli
** Also affects: oslo.middleware Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1659051 Title: Use CORS set_defaults St

[Yahoo-eng-team] [Bug 1402339] Re: Status code from HEAD requests must be consistent

2017-01-21 Thread Steve Martinelli
no movement in over a year, only patch is abandoned ** Changed in: keystone Status: Triaged => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1402339

[Yahoo-eng-team] [Bug 1211586] Re: Disable user lists without a filter

2017-01-21 Thread Steve Martinelli
So, i believe the origin of this bug was a way to make horizon fall on the floor when a user navigates to the user panel, when keystone is backed by ldap. This has been addressed by the horizon team here: https://review.openstack.org/#/c/419133/ Changing behaviour based on a configuration option s

[Yahoo-eng-team] [Bug 1550127] Re: Wrong IP Address for error message in keystone.log

2017-01-21 Thread Steve Martinelli
Looks like this was resolved in oslo.middleware in this commit: https://github.com/openstack/oslo.middleware/commit/df01234bd864062a1071b1d265153867f4b1 I'm marking it as WONTFIX for keystone and opening it up against oslo.middleware as fix-released ** Also affects: oslo.middleware Importa

[Yahoo-eng-team] [Bug 1476213] Re: Adding users from different domain to a group

2017-01-17 Thread Steve Martinelli
This should have expired ages ago ** Changed in: keystone Status: Incomplete => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1476213 Title: Adding

[Yahoo-eng-team] [Bug 1600366] Re: Federated users cannot use heat

2017-01-17 Thread Steve Martinelli
*** This bug is a duplicate of bug 1642687 *** https://bugs.launchpad.net/bugs/1642687 ** This bug is no longer a duplicate of bug 1589993 Murano cannot deploy with federated user ** This bug has been marked a duplicate of bug 1642687 Missing domain for federated users -- You received

[Yahoo-eng-team] [Bug 1546441] Re: db sync command should give user friendly message for invalid 'version' specified

2017-01-17 Thread Steve Martinelli
** Changed in: keystone Status: Incomplete => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1546441 Title: db sync command should give user friendly mess

[Yahoo-eng-team] [Bug 1613901] Re: String "..%c0%af" causes 500 errors in multiple locations

2017-01-17 Thread Steve Martinelli
** Changed in: keystone Status: Incomplete => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1613901 Title: String "..%c0%af" causes 500 errors in multiple locations St

[Yahoo-eng-team] [Bug 1653316] Re: ldap doesn't work

2017-01-17 Thread Steve Martinelli
** Changed in: keystone Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1653316 Title: ldap doesn't work Status in OpenStack Id

[Yahoo-eng-team] [Bug 1629446] Re: federated login fails after user is removed from group

2017-01-17 Thread Steve Martinelli
** Also affects: keystone/newton Importance: Undecided Status: New ** Also affects: keystone/mitaka Importance: Undecided Status: New ** Changed in: keystone Importance: Undecided => Medium ** Changed in: keystone/mitaka Importance: Undecided => Medium ** Changed in: k

[Yahoo-eng-team] [Bug 1644175] Re: create project command mentioned in Installation guide for Newton throwing error

2017-01-17 Thread Steve Martinelli
We do that here: http://docs.openstack.org/developer/python- openstackclient/command-objects/project.html#project-create -- --domain Domain owning the project (name or ID) *New in version 3.* ** Changed in: keystone Status: Incomplete => Invalid ** Changed

[Yahoo-eng-team] [Bug 1580053] Re: Configure Apache HTTPD for mod_shibboleth(WSGIScriptAliasMatch): steps for creating hard links are missing

2017-01-17 Thread Steve Martinelli
The federation docs were improved greatly over here: https://github.com/openstack/keystone/commit/38f79a8edf624a12c06558d97602f54f8e4bd83a ** Changed in: keystone Status: Triaged => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1564110] Re: OpenStack should support MySQL Cluster (NDB)

2017-01-17 Thread Steve Martinelli
** Changed in: keystone Status: Incomplete => Opinion ** Changed in: keystone Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.launchpad.net/bugs/1564110 Title: O

[Yahoo-eng-team] [Bug 1656349] Re: Incompatiblilty with webob 1.7.0

2017-01-13 Thread Steve Martinelli
*** This bug is a duplicate of bug 1653646 *** https://bugs.launchpad.net/bugs/1653646 fixed in https://review.openstack.org/#/c/416198/ dupe of https://bugs.launchpad.net/keystonemiddleware/+bug/1653646 ** Also affects: keystonemiddleware Importance: Undecided Status: New ** Chang

[Yahoo-eng-team] [Bug 1655014] Re: Job gate-keystone-dsvm-functional-ubuntu-xenial is broken for stable/newton

2017-01-12 Thread Steve Martinelli
** Changed in: keystone Status: Fix Committed => Fix Released ** Changed in: keystone Importance: Undecided => High ** Changed in: keystone Assignee: (unassigned) => Steve Martinelli (stevemar) -- You received this bug notification because you are a member of Yahoo! En

[Yahoo-eng-team] [Bug 1645553] Re: [api] relationship links result in 404

2017-01-12 Thread Steve Martinelli
** Changed in: keystone Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1645553 Title: [api] relationship links result in 404

[Yahoo-eng-team] [Bug 1654084] Re: Listing users with non-existent filter returns all users

2017-01-04 Thread Steve Martinelli
According to the HTTP spec the query args are part of the URL, these are invalid and should result in a 4xx error. However, even the great google doesn't adhere to that, try the following: https://www.google.com/#q=search+for+something&invalid=param&more=stuff With that said, I tried looking up w

[Yahoo-eng-team] [Bug 1653480] Re: Unable to perform role assignments for an ldap user with special characters in the name

2017-01-04 Thread Steve Martinelli
I agree that this is likely a python-openstackclient problem (if it were to be one). Can you provide more detail about the environment? and what version of OSC you are using? There are some tips documented for working with languages here: http://docs.openstack.org/developer/python- openstackclien

[Yahoo-eng-team] [Bug 1653472] [NEW] remove the CONF.domain_id_immutable option

2017-01-01 Thread Steve Martinelli
Public bug reported: The option was deprecated in Mitaka and can be removed in Ocata or newer: https://github.com/openstack/keystone/blob/7871fbcab1d86604e258151a660fed1edc9ae501/keystone/conf/default.py#L150-L163 ** Affects: keystone Importance: Medium Status: Triaged ** Changed i

[Yahoo-eng-team] [Bug 1614069] Re: API v2.0 responds with HTTP 200 when trying to add a non-existent user to a project

2016-12-27 Thread Steve Martinelli
** Changed in: keystone Status: In Progress => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1614069 Title: API v2.0 responds with HTTP 200 when t

[Yahoo-eng-team] [Bug 1652458] Re: Tests unnecessarily use pep8 internals, don't work with pycodestyle

2016-12-25 Thread Steve Martinelli
** Also affects: keystone Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1652458 Title: Tests unnecessarily use pep8 int

[Yahoo-eng-team] [Bug 1649245] Re: Identity Liberty version does not return 'description' if not passed while create domain

2016-12-19 Thread Steve Martinelli
Thanks for confirming Ghanshyam, marking as invalid since Liberty is EOL. ** Changed in: keystone Status: New => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpa

[Yahoo-eng-team] [Bug 1641621] Re: keystone-manage doctor needs tests

2016-12-15 Thread Steve Martinelli
** Changed in: keystone Milestone: None => ocata-2 ** Changed in: keystone Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bu

[Yahoo-eng-team] [Bug 1547684] Re: Attribute error on Token object when using domain scoped token

2016-12-15 Thread Steve Martinelli
This is an improperly written keystone rule. Marking oslo.policy as Invalid. The fix is to change: token.is_admin_project:True to: is_admin_project:True Note to affected users, we typically do not backport changes to config files, so please update the policy files accordingly. ** Also aff

[Yahoo-eng-team] [Bug 1634568] Re: Inconsistency between v3 API and keystone token timestamps

2016-12-13 Thread Steve Martinelli
this looks OK to me now... stevemar@ubuntu:/opt/stack$ source ~/devstack/openrc admin admin WARNING: setting legacy OS_TENANT_NAME to support cli tools. <> stevemar@ubuntu:/opt/stack$ openstack token issue ++---+ | Field | Value +

[Yahoo-eng-team] [Bug 1649466] Re: contrail analyticks api status stuck in "contrail-analytics-api initializing (UvePartitions:UVE-Aggregation[None] connection down)"

2016-12-13 Thread Steve Martinelli
I have no idea what the issue here is, please update the description with a stacktrace or how to recreate the problem. The bug title also references a file that is not in the Keystone project. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you

[Yahoo-eng-team] [Bug 1641642] Re: users that are blacklisted for PCI support should not have failed login attempts counted

2016-12-08 Thread Steve Martinelli
*** This bug is a duplicate of bug 1642348 *** https://bugs.launchpad.net/bugs/1642348 ** This bug has been marked a duplicate of bug 1642348 Attack could lockout a service account -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscrib

[Yahoo-eng-team] [Bug 1640504] Re: release notes and config guide missing new settings for Newton

2016-12-05 Thread Steve Martinelli
Closing this one from the keystone side, as it's fixed from our point of view. Thanks for the bug report Matt, and thank you guoshan for fixing it! ** Changed in: keystone Status: Confirmed => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Tea

[Yahoo-eng-team] [Bug 1641823] Re: Config reference: add PCI options

2016-12-05 Thread Steve Martinelli
*** This bug is a duplicate of bug 1640504 *** https://bugs.launchpad.net/bugs/1640504 ** This bug has been marked a duplicate of bug 1640504 release notes and config guide missing new settings for Newton ** Changed in: keystone Milestone: ocata-2 => None -- You received this bug not

[Yahoo-eng-team] [Bug 1645554] Re: [api-ref] incorrect title for role-assignment

2016-12-01 Thread Steve Martinelli
** Summary changed: - un appropriate title for role-assignment identity v3 api-ref + [api-ref] incorrect title for role-assignment ** Changed in: openstack-api-site Status: New => Invalid ** Also affects: keystone Importance: Undecided Status: New ** Tags added: api-ref ** Cha

[Yahoo-eng-team] [Bug 1645213] Re: Error API call in Create user operation

2016-11-28 Thread Steve Martinelli
This was a choice performed by the CLI, they are choosing to call those API in that order. ** Also affects: python-openstackclient Importance: Undecided Status: New ** Changed in: keystone Status: Confirmed => Invalid ** Changed in: keystone Assignee: Kalaswan Datta (kalasw

[Yahoo-eng-team] [Bug 1645215] Re: Error API call in Delete user operation

2016-11-28 Thread Steve Martinelli
This was a choice performed by the CLI, they are choosing to call those API in that order. ** Also affects: python-openstackclient Importance: Undecided Status: New ** Changed in: keystone Status: Confirmed => Invalid ** Changed in: keystone Assignee: Kalaswan Datta (kalasw

[Yahoo-eng-team] [Bug 1641822] Re: admin guide: create a PCI section

2016-11-21 Thread Steve Martinelli
https://review.openstack.org/#/c/399337/ merged ** Changed in: keystone Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1641

[Yahoo-eng-team] [Bug 1555137] Re: Transition from UUID/PKI to Fernet without dumping all tokens

2016-11-15 Thread Steve Martinelli
Fernet was the recommended token in Newton and the default in Ocata. Only in Ocata do we actually support zero downtime upgrades, so you'll have to restart keystone and have downtime between upgrades anyway. This should be done as part of a maintenance window. I'm marking this as WONTFIX because i

[Yahoo-eng-team] [Bug 1545736] Re: keystone role create failed when 4 byte unicode character is provided in name field

2016-11-15 Thread Steve Martinelli
This should be fixed centrally with oslo.db. There is also no movement on this patch in a long time, and I'm not convinced it's a realistic problem (we handle UTF8 characters well enough in the database, just not 4byte ones). ** Changed in: keystone Status: Confirmed => Won't Fix -- You r

[Yahoo-eng-team] [Bug 1582493] Re: Move validate_non_persistent_token() method from base to fernet

2016-11-15 Thread Steve Martinelli
Lance is correct. ** Changed in: keystone Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1582493 Title: Move validate_no

[Yahoo-eng-team] [Bug 1553324] Re: potential DOS with revoke by id or audit_id

2016-11-15 Thread Steve Martinelli
https://review.openstack.org/#/q/topic:bug/1524030 should fix this, time to determine revocation events is now flat once there are 80 revocation events. ** Changed in: keystone Status: New => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering

[Yahoo-eng-team] [Bug 1528676] Re: OpenLDAP password policy not enforced for password changes

2016-11-15 Thread Steve Martinelli
Write support is being removed, this will not be fixed. ** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/152

[Yahoo-eng-team] [Bug 1240625] Re: User cannot set their own default project

2016-11-15 Thread Steve Martinelli
See previous comments ** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1240625 Title: User cannot set the

[Yahoo-eng-team] [Bug 1244423] Re: Inconsistency in the keystone api "enabled" field

2016-11-15 Thread Steve Martinelli
Patches https://review.openstack.org/#/c/32758/ and https://review.openstack.org/#/c/27176/ resolved the issue ** Changed in: keystone Status: Triaged => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStac

[Yahoo-eng-team] [Bug 1259425] Re: service-create allows 2 services with the same name

2016-11-15 Thread Steve Martinelli
This is a limitation that we cannot fix without causing a backwards incompatible change. It is very rare to have 2 service names that are the same. ** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Tea

[Yahoo-eng-team] [Bug 1515825] Re: Logging out of horizon does not invalidate IdP session

2016-11-15 Thread Steve Martinelli
As noted by many on this bug, this is the expected behaviour when using a federated identity provider. ** Summary changed: - Horizon allows login without credential when configured to use WebSSO + Logging out of horizon does not invalidate IdP session ** Changed in: keystone Status: Confi

[Yahoo-eng-team] [Bug 1471665] Re: Successive runs of identity tempest tests take more and more time to finish

2016-11-15 Thread Steve Martinelli
The root cause of this was too many revocation events, with the working being done here: https://review.openstack.org/#/q/topic:bug/1524030 it should be resolved. ** Changed in: keystone Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ya

[Yahoo-eng-team] [Bug 1593875] Re: keystone auth silently fails if Rabbit is unavailable

2016-11-15 Thread Steve Martinelli
See previous comment ** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1593875 Title: keystone auth silent

[Yahoo-eng-team] [Bug 1637484] Re: Update user is working not properly

2016-11-15 Thread Steve Martinelli
*** This bug is a duplicate of bug 1637530 *** https://bugs.launchpad.net/bugs/1637530 ** This bug has been marked a duplicate of bug 1637530 Python keystone client `users` method get() is not working -- You received this bug notification because you are a member of Yahoo! Engineering Tea

[Yahoo-eng-team] [Bug 1641821] [NEW] admin guide: Cleanup LDAP

2016-11-14 Thread Steve Martinelli
Public bug reported: There exist three different documents [1] related to LDAP in the admin- guide [2]. They should be collapsed into one. Further, they recommend deploying a single backend LDAP, which is not what the keystone team recommends. [1] 1) identity-integrate-with-ldap.rst 2) identi

[Yahoo-eng-team] [Bug 1641822] [NEW] admin guide: create a PCI section

2016-11-14 Thread Steve Martinelli
Public bug reported: A section dedicated to PCI should be created in the admin guide [1]. The content can largely come from our developer docs [2], but should be modified for a deployer in mind. [1] https://github.com/openstack/openstack-manuals/tree/master/doc/admin-guide/source [2] http://docs

[Yahoo-eng-team] [Bug 1641823] [NEW] Config reference: add PCI options

2016-11-14 Thread Steve Martinelli
Public bug reported: Add configuration options to the config reference [1]. [1] https://github.com/openstack/openstack-manuals/tree/master/doc/config-reference/source/identity ** Affects: keystone Importance: Low Status: New ** Tags: documentation -- You received this bug not

[Yahoo-eng-team] [Bug 1641818] [NEW] admin guide: update caching document

2016-11-14 Thread Steve Martinelli
Public bug reported: The caching document in the admin guide is sorely out of date by at least 2 releases. Update it to reflect current status. http://docs.openstack.org/admin-guide/identity-caching-layer.html ** Affects: keystone Importance: Low Assignee: Eric Brown (ericwb) S

[Yahoo-eng-team] [Bug 1641816] [NEW] enable ``cache_on_issue`` by default

2016-11-14 Thread Steve Martinelli
Public bug reported: keystone provides a configuration option to "pre-cache" a token, it is cached upon issue. In the Newton release this was disabled by default, we should enable it in Ocata. ** Affects: keystone Importance: Medium Assignee: Matt Fischer (mfisch) Status: In Pr

[Yahoo-eng-team] [Bug 1621200] Re: password created_at does not honor timezones

2016-11-14 Thread Steve Martinelli
** Changed in: keystone/newton Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1621200 Title: password created_at does n

[Yahoo-eng-team] [Bug 1641660] [NEW] enable CADF notification format by default

2016-11-14 Thread Steve Martinelli
Public bug reported: The current default notification format is the home-brewed openstack- styled format, that provides minimal information about the user. For a few releases now, all new notifications have adhered to the CADF format. We should switch over to the CADF format, which provides compat

[Yahoo-eng-team] [Bug 1641654] [NEW] include healthcheck middleware by default

2016-11-14 Thread Steve Martinelli
Public bug reported: The healthcheck middleware is published by oslo, used in glance and magnum, and one less thing for deployers to add to keystone. Let's add it in. Patch: https://review.openstack.org/#/c/387731/ ** Affects: keystone Importance: Medium Assignee: Jesse Keating (jesse-

[Yahoo-eng-team] [Bug 1641652] [NEW] cache invalidation should be wrapped to local context

2016-11-14 Thread Steve Martinelli
Public bug reported: When [1] merged, it fixed many caching issues and bug, but created another. The region invalidation should be wrapped to the local context. Patch: https://review.openstack.org/#/c/380376/ ** Affects: keystone Importance: High Assignee: Boris Bobrov (bbobrov)

[Yahoo-eng-team] [Bug 1641642] [NEW] users that are blacklisted for PCI support should not have failed login attempts counted

2016-11-14 Thread Steve Martinelli
Public bug reported: The main idea behind the user ID blacklist for PCI was to allow service accounts to not have to change their password. As noted in [1], a by- product of any PCI implementation is a vulnerability to a DoS (a malicious user attempting to login X times and locking out a user). Th

[Yahoo-eng-team] [Bug 1641645] [NEW] PCI: a locked out user must ask an admin to unlock their account

2016-11-14 Thread Steve Martinelli
Public bug reported: As noted in the bug title, this is a cumbersome process, a user should be able to reset their password if it expired. (and potentially if locked out -- that's up for debate). ** Affects: keystone Importance: Medium Status: New ** Tags: pci -- You received th

[Yahoo-eng-team] [Bug 1641639] [NEW] use mapping_id for shadow users

2016-11-14 Thread Steve Martinelli
Public bug reported: Currently, shadow users are created for users that log in through federation. New "local_user" accounts are created with a new UUID. Rather than creating a new UUID, we should re-use the mapping_id backend that was employed with LDAP users. ** Affects: keystone Importanc

[Yahoo-eng-team] [Bug 1641621] [NEW] keystone-manage doctor needs tests

2016-11-14 Thread Steve Martinelli
Public bug reported: there are no tests for any keystone-manage doctor commands. they should be created here: https://github.com/openstack/keystone/blob/master/keystone/tests/unit/test_cli.py ** Affects: keystone Importance: Low Status: Triaged ** Tags: test-improvement -- You r

[Yahoo-eng-team] [Bug 1641623] [NEW] keystone-manage doctor needs developer docs

2016-11-14 Thread Steve Martinelli
Public bug reported: There are no developer docs on how to create a new doctor check, or how the existing ones work. They should be added to a new section in the "developer docs" here: http://docs.openstack.org/developer/keystone /#developers-documentation ** Affects: keystone Importance: Me

[Yahoo-eng-team] [Bug 1641625] [NEW] RFE: add more info in the k2k assertion

2016-11-14 Thread Steve Martinelli
Public bug reported: Currently, the user's name (and domain name), their roles, the project they authenticated with (and project's domain name) are supplied in the k2k assertion that keystone generates. There has been a request that the user's groups also be included in the assertion. ** Affects

[Yahoo-eng-team] [Bug 1591916] Re: Named arguments should be used for assertValidUserResponse() in unittest case

2016-11-11 Thread Steve Martinelli
No movement in months, there is no direct user impact here so I'm marking as invalid. ** Changed in: keystone Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). htt

[Yahoo-eng-team] [Bug 1637850] Re: newton openstack-keystone service not created on Centos7

2016-11-11 Thread Steve Martinelli
Hi Scott, I manage the keystone queue for launchpad, it's meant for keystone bugs, the issue you're having (IIUC) is related to the RPM package. I don't want to simply mark the bug as invalid and leave you in a lurch. So I'll provide some pointers: The red hat published install guide can be seen h

[Yahoo-eng-team] [Bug 1638603] Re: Identity LDAP does not support AD nested groups

2016-11-10 Thread Steve Martinelli
** Changed in: keystone Status: In Progress => Fix Released ** Also affects: keystone/newton Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https:/

[Yahoo-eng-team] [Bug 1082248] Re: Use uuidutils instead of uuid.uuid4()

2016-11-08 Thread Steve Martinelli
This is an implementation detail and we won't be fixing it in Keystone. There's no gain as far as I can tell. ** Changed in: keystone Status: New => Invalid ** No longer affects: keystone -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1635306] Re: After newton deployment _member_ role is missing in keystone

2016-10-31 Thread Steve Martinelli
** Also affects: keystone/newton Importance: Undecided Status: New ** Changed in: keystone/newton Status: New => In Progress ** Changed in: keystone/newton Importance: Undecided => High ** Changed in: keystone/newton Assignee: (unassigned) => Adam Young (ayoung) -- You

[Yahoo-eng-team] [Bug 1635306] Re: After newton deployment _member_ role is missing in keystone

2016-10-31 Thread Steve Martinelli
Patch https://review.openstack.org/#/c/389783/ closes the bug from the keystone side ** Also affects: keystone Importance: Undecided Status: New ** Changed in: keystone Status: New => In Progress ** Changed in: keystone Importance: Undecided => High ** Changed in: keystone

[Yahoo-eng-team] [Bug 1637682] Re: scoped string defined as 'unscope: {}'

2016-10-31 Thread Steve Martinelli
In this case, the API needs to be updated, it should include the "unscoped" option: https://github.com/openstack/keystone/blob/master /api-ref/source/v3/authenticate-v3.inc The issue here is that we moved our APIs from one repo to another and some content went missing in the transition. Informati

[Yahoo-eng-team] [Bug 1637850] Re: newton openstack-keystone service not created on Centos7

2016-10-31 Thread Steve Martinelli
** Also affects: ubuntu Importance: Undecided Status: New ** No longer affects: ubuntu -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1637850 Title: newt

[Yahoo-eng-team] [Bug 1637214] [NEW] [api-ref] include changelog from v3.0 -> 3.7

2016-10-27 Thread Steve Martinelli
Public bug reported: Include https://github.com/openstack/keystone-specs/blob/master/attic/v3 /identity-api-v3.rst in the file https://raw.githubusercontent.com/openstack/keystone/master/api- ref/source/v3/index.rst 3.7 == Newton, work your way back from there. -

[Yahoo-eng-team] [Bug 1636052] Re: multi-region ,servers with volume attachments

2016-10-24 Thread Steve Martinelli
Not a keystone bug, what tool did you use to perform the operation? ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bu

[Yahoo-eng-team] [Bug 1632981] Re: keystone delete role gives no output when operation is successful

2016-10-13 Thread Steve Martinelli
this is as-designed. no delete operations give feedback. just as in linux if something does not give you an error, you can assume it occurred just fine. https://www.quora.com/What-is-the-appropriate-HTTP-response-code-to-a -successful-DELETE-request ** Changed in: keystone Status: New => I

[Yahoo-eng-team] [Bug 1631319] Re: Can't deploy overcloud of Mitaka on CentOS

2016-10-12 Thread Steve Martinelli
Thanks for the quick analysis here Ben. Looking at newton and future releases, if you are using the "keystone-manage bootstrap" option to setup keystone, then the domain ID won't be "default" it'll be some UUID. Your best bet going forward is to use the domain name only, it'll always be "Default" (

[Yahoo-eng-team] [Bug 1592169] Re: cached tokens break Liberty to Mitaka upgrade

2016-10-11 Thread Steve Martinelli
** Changed in: keystone/mitaka Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1592169 Title: cached tokens break Libert

[Yahoo-eng-team] [Bug 1460492] Re: List credentials by type

2016-10-11 Thread Steve Martinelli
** Changed in: python-openstackclient Status: Fix Released => Triaged -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1460492 Title: List credentials by type

[Yahoo-eng-team] [Bug 1628135] Re: Integrate Identity back end with LDAP in Administrator Guide

2016-10-07 Thread Steve Martinelli
** Changed in: keystone Status: Triaged => Invalid ** Changed in: keystone Milestone: ocata-1 => None -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/162813

[Yahoo-eng-team] [Bug 1631092] Re: home-page url link need to change

2016-10-06 Thread Steve Martinelli
please don't open bugs for these issues, just submit a patch. there's no real end user issue here. ** Changed in: keystone Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (k

[Yahoo-eng-team] [Bug 1630259] Re: KeyError: 'is_domain' during mitaka -> newton rolling upgrade

2016-10-05 Thread Steve Martinelli
** Changed in: keystone/newton Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1630259 Title: KeyError: 'is_domain' duri

[Yahoo-eng-team] [Bug 1628597] Re: Support upper-constraints in tox.ini

2016-10-05 Thread Steve Martinelli
Isn't this just wrong now? Read http://lists.openstack.org/pipermail/openstack- dev/2016-August/101474.html AFAIK the more common tox jobs use upper-constraints ** No longer affects: python-keystoneclient -- You received this bug notification because you are a member of Yahoo! Engineering Team

[Yahoo-eng-team] [Bug 1630259] Re: KeyError: 'is_domain' during mitaka -> newton rolling upgrade

2016-10-05 Thread Steve Martinelli
Lance, I'm working the RC angle now; regardless, we should get it into Newton anyway, even if it's in a post-release fix ** Changed in: keystone/newton Status: Invalid => Fix Committed ** Changed in: keystone/newton Importance: Undecided => High ** Changed in: keystone/newton Assi

[Yahoo-eng-team] [Bug 1630435] [NEW] make the assignment backend default to sql

2016-10-04 Thread Steve Martinelli
Public bug reported: Currently, we do not provide a default for the assignment driver: https://github.com/openstack/keystone/blob/master/keystone/conf/assignment.py#L18-L28 Which results in a deprecation message: Deprecated: Use of the identity driver config to automatically configure the same

[Yahoo-eng-team] [Bug 1384377] Re: Policy rule position errors

2016-10-03 Thread Steve Martinelli
*** This bug is a duplicate of bug 1523030 *** https://bugs.launchpad.net/bugs/1523030 This is fixed by https://review.openstack.org/#/c/253763/ ** This bug has been marked a duplicate of bug 1523030 parser can't handle mixed conditions of 'or' and 'and' operators -- You received this bu

[Yahoo-eng-team] [Bug 1529721] Re: Attempting a RoleCheck when the credentials do not contain a roles list causes an exception

2016-10-03 Thread Steve Martinelli
** Changed in: oslo.policy Status: Fix Committed => Fix Released ** Changed in: oslo.policy Importance: Undecided => Medium -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.laun

[Yahoo-eng-team] [Bug 1259292] Re: Some tests use assertEqual(observed, expected) , the argument order is wrong

2016-10-03 Thread Steve Martinelli
Fixed in pycadf: https://review.openstack.org/#/c/338781/ ** Changed in: pycadf Importance: Undecided => Low ** Changed in: pycadf Status: New => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Co

[Yahoo-eng-team] [Bug 1577370] Re: Duplicate lines in /etc/nova/policy.json

2016-10-03 Thread Steve Martinelli
Not an oslo.policy bug, and it looks like this was fixed in nova. ** Changed in: oslo.policy Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1

[Yahoo-eng-team] [Bug 1628883] Re: Minimum requirements too low on oslo.log for keystone

2016-09-29 Thread Steve Martinelli
** Changed in: keystone Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1628883 Title: Minimum requirements too low on oslo.

[Yahoo-eng-team] [Bug 1623168] Re: referencing versionutils.deprecated.NEWTON in oslo.log <3.4.0

2016-09-29 Thread Steve Martinelli
Marking this as fix-released for keystone on the ocata branch, we depend on oslo.log>=3.11.0: https://github.com/openstack/keystone/blob/master/requirements.txt ** Changed in: keystone Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Yaho

[Yahoo-eng-team] [Bug 1621626] Re: Unauthenticated requests return information

2016-09-27 Thread Steve Martinelli
This is fixed in master (as stated in the bug report), we could backport the fix to Mitaka as it's a security issue, albeit a minor one. I'm OK with backporting the fix, but I'm also OK with not backporting it (IIRC there were one or two other patches that needed to land after https://review.openst

[Yahoo-eng-team] [Bug 1625619] Re: It is possible to download key pair for other user at the same project

2016-09-27 Thread Steve Martinelli
** Also affects: nova Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1625619 Title: It is possible to download key pair for o

[Yahoo-eng-team] [Bug 1609566] Re: 500 error from revocation event deserialize

2016-09-27 Thread Steve Martinelli
** Changed in: keystone Status: In Progress => Fix Released ** Changed in: keystone Assignee: Richard (csravelar) => Brant Knudson (blk-u) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone).

  1   2   3   4   5   6   >