[Yahoo-eng-team] [Bug 1363289] Re: Typos in base64utils.py file

2014-09-09 Thread Dolph Mathews
Fixed in https://review.openstack.org/#/c/118913/1/keystone/common/base64utils.py ** Changed in: keystone Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/b

[Yahoo-eng-team] [Bug 1366649] Re: Typo in keystone/common/base64utils.py

2014-09-08 Thread Dolph Mathews
This isn't a useful bug report, especially given that there's no useful information here about the actual typo you're referring to. Happy to see typos fixed without a bug report. ** Changed in: keystone Importance: Undecided => Low ** Changed in: keystone Status: In Progress => Invalid

[Yahoo-eng-team] [Bug 1320140] Re: Federation documentation is not clear about mapping.rules.local.user.name

2014-09-08 Thread Dolph Mathews
*** This bug is a duplicate of bug 1312221 *** https://bugs.launchpad.net/bugs/1312221 ** This bug has been marked a duplicate of bug 1312221 Add user objects to mapping rules examples in OS-FEDERATION docs -- You received this bug notification because you are a member of Yahoo! Engineeri

[Yahoo-eng-team] [Bug 1360362] Re: Prevent deletion of currently scoped tenant

2014-09-04 Thread Dolph Mathews
We'd also have to not allow the current user to delete themselves, nor the user to remove their last role assignment from the current scope, etc. I'm all in favor of UX, but I also prefer the power to shoot myself in the foot if I so choose. If we "fixed" this, I guarantee we'd get a subsequent bug

[Yahoo-eng-team] [Bug 1361378] Re: "MySQL server has gone away" again

2014-09-04 Thread Dolph Mathews
** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1361378 Title: "MySQL server has gone away" again Status in OpenStack Identity (Key

[Yahoo-eng-team] [Bug 1365458] Re: Keystone auth needs a way to propogate some error message based on some kind of configuration

2014-09-04 Thread Dolph Mathews
** Project changed: keystone => horizon -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/1365458 Title: Keystone auth needs a way to propogate some error message base

[Yahoo-eng-team] [Bug 1347862] Re: keystone will not auth users if there is a bad endpoint

2014-09-04 Thread Dolph Mathews
*** This bug is a duplicate of bug 1230279 *** https://bugs.launchpad.net/bugs/1230279 ** This bug has been marked a duplicate of bug 1230279 malformed endpoint URLs are destroying the API -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1362245] Re: Update Endpoint Filter APIs

2014-09-04 Thread Dolph Mathews
** Changed in: keystone Importance: Undecided => Low ** Changed in: keystone Status: New => Triaged ** Also affects: openstack-api-site Importance: Undecided Status: New ** Tags added: low-hanging-fruit -- You received this bug notification because you are a member of Yahoo

[Yahoo-eng-team] [Bug 1361307] Re: Certificate apis need to be ported to V3

2014-09-04 Thread Dolph Mathews
PKI is optional, hence it's an extension. Albeit, they are basically only used for PKI, so a PKI namespace would have been preferable. ** Changed in: keystone Status: New => Invalid ** Tags added: pki -- You received this bug notification because you are a member of Yahoo! Engineering Te

[Yahoo-eng-team] [Bug 1361337] Re: keystone.tests.test_serializer.XmlSerializerTestCase.test_collection_member random fails; lxml hashseed?

2014-09-04 Thread Dolph Mathews
*** This bug is a duplicate of bug 1347891 *** https://bugs.launchpad.net/bugs/1347891 ** This bug has been marked a duplicate of bug 1347891 mis-use of XML canonicalization in keystone tests -- You received this bug notification because you are a member of Yahoo! Engineering Team, which

[Yahoo-eng-team] [Bug 1365678] [NEW] Sync with openstack/requirements

2014-09-04 Thread Dolph Mathews
Public bug reported: Our last sync with openstack/requirements was around the beginning of August. We haven't been able to sync because we have unit test failures on the sync job since around August 20th: https://review.openstack.org/#/c/111620/ Likely, our tests need to be fixed to support wh

[Yahoo-eng-team] [Bug 1361125] Re: keystone install failed, meet error 'got an unexpected keyword argument 'namedtuple_as_object''

2014-09-04 Thread Dolph Mathews
I stand corrected. Keystone has the fix above in master as of 94efafd6 https://review.openstack.org/#/c/114863/ ** Changed in: keystone Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone.

[Yahoo-eng-team] [Bug 1252341] Re: Horizon crashes when removing logged user from project

2014-09-04 Thread Dolph Mathews
** Changed in: keystone Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1252341 Title: Horizon crashes when removing logged user from project Statu

[Yahoo-eng-team] [Bug 1358908] Re: CENTOS 6.5 : starting keystone service

2014-09-04 Thread Dolph Mathews
This looks like it was a packaging issue. If it's still a problem, I'd suggest filing it against centos / RDO. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https:/

[Yahoo-eng-team] [Bug 1365169] [NEW] Endpoint grouping extension does handle deletion callbacks

2014-09-03 Thread Dolph Mathews
Public bug reported: If a project or endpoint group is deleted, the endpoint grouping extension should respond by deleting associated data. Instead, stale data remains in the backend. ** Affects: keystone Importance: Medium Assignee: Bob Thyne (bob-thyne) Status: In Progress -

[Yahoo-eng-team] [Bug 1329737] Re: Valid tokens may remain after token's user was deleted

2014-09-03 Thread Dolph Mathews
This has been addressed on the Keystone side with the above BP. ** Changed in: keystone Status: Triaged => Invalid ** Changed in: keystone Milestone: juno-3 => None -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keyst

[Yahoo-eng-team] [Bug 1365061] Re: Warn against sorting requirements

2014-09-03 Thread Dolph Mathews
** Also affects: neutron Importance: Undecided Status: New ** Also affects: horizon Importance: Undecided Status: New ** Also affects: swift Importance: Undecided Status: New ** Changed in: horizon Status: New => Fix Committed ** No longer affects: horizon

[Yahoo-eng-team] [Bug 1365061] Re: Warn against sorting requirements

2014-09-03 Thread Dolph Mathews
** Also affects: python-keystoneclient Importance: Undecided Status: New ** Also affects: keystonemiddleware Importance: Undecided Status: New ** Changed in: keystone Assignee: (unassigned) => Dolph Mathews (dolph) ** Changed in: python-keystoneclient Assig

[Yahoo-eng-team] [Bug 1285478] Re: Enforce alphabetical ordering in requirements file

2014-09-03 Thread Dolph Mathews
See bug 1365061 instead. ** Changed in: blazar Status: Triaged => Invalid ** Changed in: glance Status: In Progress => Invalid ** Changed in: keystone Status: In Progress => Invalid ** Changed in: trove Status: In Progress => Invalid ** Changed in: python-cinderclie

[Yahoo-eng-team] [Bug 1365061] [NEW] Warn against sorting requirements

2014-09-03 Thread Dolph Mathews
Public bug reported: Contrary to bug 1285478, requirements files should not be sorted alphabetically. Given that requirements files can contain comments, I'd suggest a header in all requirements files along the lines of: # The order of packages is significant, because pip processes them in the or

[Yahoo-eng-team] [Bug 1364463] Re: Incorrect key in endpoint dictionary

2014-09-03 Thread Dolph Mathews
** Also affects: python-keystoneclient Importance: Undecided Status: New ** Changed in: python-keystoneclient Assignee: (unassigned) => Sergey Kraynev (skraynev) ** Changed in: python-keystoneclient Status: New => In Progress -- You received this bug notification because y

[Yahoo-eng-team] [Bug 1361378] [NEW] "MySQL server has gone away" again

2014-08-25 Thread Dolph Mathews
Public bug reported: This is a regression of an old issue, which I thought was resolved by the "SELECT 1;" hack, but perhaps recently reintroduced with oslo.db? [Mon Aug 25 14:30:54.403538 2014] [:error] [pid 25778:tid 139886259214080] 25778 ERROR keystone.common.wsgi [-] (OperationalError) (200

[Yahoo-eng-team] [Bug 1347891] Re: mis-use of XML canonicalization in keystone tests

2014-08-15 Thread Dolph Mathews
** Also affects: keystone/icehouse Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1347891 Title: mis-use of XML canonicalization in keystone

[Yahoo-eng-team] [Bug 1356925] Re: keystone-all unexpected crash

2014-08-14 Thread Dolph Mathews
*** This bug is a duplicate of bug 871822 *** https://bugs.launchpad.net/bugs/871822 This is identical to bug 871822, regardless of the project consuming eventlet. ** This bug has been marked a duplicate of bug 871822 nova-api crashed with input/output error -- You received this bug noti

[Yahoo-eng-team] [Bug 1356925] Re: keystone-all unexpected crash

2014-08-14 Thread Dolph Mathews
*** This bug is a duplicate of bug 871822 *** https://bugs.launchpad.net/bugs/871822 This almost looks like a bug in Eventlet, or perhaps just poor feedback from eventlet about the state of the machine it's running on? In Keystone's case, you could avoid this by deploying to Apache httpd inste

[Yahoo-eng-team] [Bug 1356682] Re: GET /v3/users lists users in all domains

2014-08-14 Thread Dolph Mathews
This is certainly expected behavior - Henry's explanation looks spot on, and (2) explains the justification for the current behavior. ** Changed in: keystone Status: New => Opinion -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscrib

[Yahoo-eng-team] [Bug 1324610] Re: tools/config/generate_sample.sh has no effect on OS X

2014-08-13 Thread Dolph Mathews
Adding keystone here then, so we can switch from the shell version (which does not work on OS X) to the python version (which does work on OS X). ** Also affects: keystone Importance: Undecided Status: New ** Changed in: keystone Status: New => Triaged ** Changed in: keystone

[Yahoo-eng-team] [Bug 1355715] Re: Adding a role "member" gives duplicate entry error whereas assigning role "member" to an user gives role not found error.

2014-08-12 Thread Dolph Mathews
In one request, you're referencing a role by name ("member", which is valid), and in another request, you're trying to get a role by ID - and there's certainly no role with id=member (id's are generally UUIDs). GET /v3/roles?name=member should allow you to find the role ID by name. ** Changed in:

[Yahoo-eng-team] [Bug 1355655] Re: Attempt to assign a role to a non existent user should fail

2014-08-12 Thread Dolph Mathews
Leaving this as Opinion for the moment, because this was actually by design (although, I personally disagree with the behavior illustrated above). Going to mention this at the Keystone meeting today. ** Changed in: keystone Status: New => Opinion -- You received this bug notification beca

[Yahoo-eng-team] [Bug 1355009] Re: Client for test Federation on Icehouse Keystone

2014-08-12 Thread Dolph Mathews
Closing this because it's not a bug (there's nothing to reproduce), but subscribing Marek and Steve who should be able to help you out. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscr

[Yahoo-eng-team] [Bug 1334368] Re: HEAD and GET inconsistencies in Keystone

2014-08-11 Thread Dolph Mathews
** Also affects: openstack-api-site Importance: Undecided Status: New ** Tags added: identity-api -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1334368 Title: HEAD and GET i

[Yahoo-eng-team] [Bug 1172106] Re: Live LDAP tests fail on unicode names

2014-08-08 Thread Dolph Mathews
** Changed in: keystone/icehouse Importance: Undecided => Medium ** Also affects: keystone/grizzly Importance: Undecided Status: New ** Changed in: keystone/grizzly Status: New => Fix Committed ** Changed in: keystone/grizzly Importance: Undecided => Medium ** Changed in:

[Yahoo-eng-team] [Bug 1354408] Re: Role list in tokens does not match identity-api spec

2014-08-08 Thread Dolph Mathews
I agree, the documentation should be fixed for this. ** Tags added: identity-api ** Project changed: keystone => openstack-api-site ** Changed in: openstack-api-site Status: New => Confirmed -- You received this bug notification because you are a member of Yahoo! Engineering Team, which

[Yahoo-eng-team] [Bug 1352314] Re: Meaningless replacing of slashes with dashes in PKI tokens

2014-08-08 Thread Dolph Mathews
+1 for documenting the behavior, along with pretty much everything else in keystoneclient.common.cms ** Project changed: keystone => python-keystoneclient -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.laun

[Yahoo-eng-team] [Bug 1353111] Re: Deleting a tenant leaves the network orphoned

2014-08-08 Thread Dolph Mathews
*** This bug is a duplicate of bug 967832 *** https://bugs.launchpad.net/bugs/967832 ** This bug has been marked a duplicate of bug 967832 Resources owned by a project/tenant are not cleaned up after that project is deleted from keystone -- You received this bug notification because you

[Yahoo-eng-team] [Bug 1353487] Re: Code in keystone.credential.backends has no test coverage

2014-08-08 Thread Dolph Mathews
The functional tests here exercise the SQL backend, which is the only backend we have: https://github.com/openstack/keystone/blob/master/keystone/tests/test_v3_credential.py ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Y

[Yahoo-eng-team] [Bug 1350792] Re: In case of HTTP 40x error on HEAD method, the Content-Length will be set incorrectly.

2014-08-04 Thread Dolph Mathews
Comparing just the method difference with curl, I'm not able to reproduce this. Further, this behavior matches our understanding of HEAD. The non-zero Content-Length basically indicates to the client how large the response body would be in a normal GET request. $ curl http://localhost:35357/v3/gro

[Yahoo-eng-team] [Bug 1211582] Re: Filter user list by partial attributes

2014-08-04 Thread Dolph Mathews
I'm going to ignore the mentions of "firstname" and "lastname", since the patch above ignores them as well. Up until now, a user's email address has been considered metadata on the user that Keystone itself makes no guarantees or assumptions about. If email is to be a first class attribute, I'd li

[Yahoo-eng-team] [Bug 1339107] Re: Kyestone: Auth token not in the request header

2014-08-04 Thread Dolph Mathews
Actually, I totally overlooked that the request was in the logs, to POST /v2.0/tokens. There should not be an X-Auth-Token in a request to POST /v2.0/tokens anyway, so that's completely normal. The rest of the logs in the problem description are also completely normal, so far as I can tell. Withou

[Yahoo-eng-team] [Bug 1351339] Re: Thousands of "[:error]" in keystone debug logs makes it hard to debug

2014-08-04 Thread Dolph Mathews
There's not a single ERROR level log there from Keystone - this looks to be coming from apache's log config in devstack? ** Project changed: keystone => devstack -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bu

[Yahoo-eng-team] [Bug 1347862] Re: keystone will not auth users if there is a bad endpoint

2014-08-04 Thread Dolph Mathews
** Also affects: keystone/icehouse Importance: Undecided Status: New ** Changed in: keystone/icehouse Status: New => In Progress ** Changed in: keystone/icehouse Importance: Undecided => Medium ** Changed in: keystone Importance: Undecided => Medium ** Changed in: keyston

[Yahoo-eng-team] [Bug 1309430] Re: openstack role add RHEL error

2014-08-04 Thread Dolph Mathews
This looks like it's an issue between devstack and openstackclient. This was filed months ago though, is it still an issue? ** Project changed: keystone => devstack ** Changed in: devstack Status: New => Incomplete ** Also affects: python-openstackclient Importance: Undecided St

[Yahoo-eng-team] [Bug 1349792] Re: nova-client return Unauthorized (HTTP 401) when provider is pki

2014-08-04 Thread Dolph Mathews
** Changed in: keystone Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1349792 Title: nova-client return Unauthorized (HTTP 401) when provider is

[Yahoo-eng-team] [Bug 1337089] Re: Pip temporarily diseappeared?

2014-08-04 Thread Dolph Mathews
https://review.openstack.org/#/c/108406/ ** Also affects: keystone Importance: Undecided Status: New ** Changed in: keystone Status: New => Triaged ** Changed in: keystone Importance: Undecided => Medium ** Changed in: keystone Status: Triaged => Fix Committed ** Cha

[Yahoo-eng-team] [Bug 1208425] Re: ImportError: No module named migrate.versioning

2014-07-30 Thread Dolph Mathews
This must have been fixed elsewhere. ** Changed in: devstack Status: New => Invalid ** Changed in: keystone Status: Confirmed => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchp

[Yahoo-eng-team] [Bug 1348844] Re: Keystone logs auth tokens in URLs at log level info

2014-07-30 Thread Dolph Mathews
I'd say this is Won't Fix for v2.0. You can use custom logging levels in eventlet.wsgi.server to suppress this class of logs altogether, but our solution to the "tokens in URLs" problem was solved by introducing v3 which does not do that - we can't change the v2 API, and I'm not sure it's a good id

[Yahoo-eng-team] [Bug 1348143] Re: error when create a new user with its role is _member_

2014-07-30 Thread Dolph Mathews
I'm not sure if Keystone or Horizon is at fault here, so I've added both as Incomplete. The user may have been created successfully, but keystone will also attempt to assign the _member_ role to the user in the user's default tenant (the user.tenant_id attribute in v2, or user.default_project_id i

[Yahoo-eng-team] [Bug 1346820] Re: Middeware auth_token fails with scoped federated saml token

2014-07-30 Thread Dolph Mathews
** No longer affects: keystone ** Changed in: keystonemiddleware Importance: Undecided => Wishlist ** Changed in: keystonemiddleware Status: New => Triaged -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https

[Yahoo-eng-team] [Bug 1350000] [NEW] UUID is a more friendly default token provider than PKI

2014-07-29 Thread Dolph Mathews
fault token provider for Juno. ** Affects: keystone Importance: Wishlist Assignee: Dolph Mathews (dolph) Status: Triaged -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/13

[Yahoo-eng-team] [Bug 1346210] Re: keystone v2.0 API docs reported with invalid information

2014-07-29 Thread Dolph Mathews
** Project changed: keystone => openstack-api-site -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1346210 Title: keystone v2.0 API docs reported with invalid information Status in Open

[Yahoo-eng-team] [Bug 1004114] Re: Password logging

2014-07-24 Thread Dolph Mathews
** Changed in: python-keystoneclient Milestone: None => 0.10.1 ** Changed in: python-keystoneclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.

[Yahoo-eng-team] [Bug 1348262] [NEW] PKI and PKIZ tokens contain unnecessary whitespace

2014-07-24 Thread Dolph Mathews
as compared to what we're producing today: {"key":"value"} ... as compared to all unnecessary whitespace removed: {"key":"value"} This optimization would save us a few bytes in both PKI and PKIZ tokens. ** Affects: keystone Importance: Wish

[Yahoo-eng-team] [Bug 1233365] Re: LDAP backend fails when connecting to Active Directory root DN

2014-07-23 Thread Dolph Mathews
** Also affects: keystone/havana Importance: Undecided Status: New ** Tags removed: activedirectory havana-backport-potential ** Tags added: ldap ** Changed in: keystone/havana Status: New => In Progress ** Changed in: keystone/havana Assignee: (unassigned) => Adam Young (a

[Yahoo-eng-team] [Bug 1273988] Re: keystoneclient requires --pass to create user while keystone doesn't

2014-07-22 Thread Dolph Mathews
** Changed in: python-keystoneclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1273988 Title: keystoneclient requires --pass to create

[Yahoo-eng-team] [Bug 1342925] [NEW] Invalid input received: Invalid volume: Volume status must be available or error, but current status is: creating

2014-07-16 Thread Dolph Mathews
Public bug reported: A transient ERROR from a tempest run: 2014-07-07 04:48:43.757 ERROR nova.api.ec2 [req-6705e757-dc7c-4d8c-9b0d- f0a4e2ea363c EC2VolumesTest-1498681827 EC2VolumesTest-1461531536] Unexpected InvalidInput raised: Invalid input received: Invalid volume: Volume status must be avail

[Yahoo-eng-team] [Bug 1342909] [NEW] libvirtError: monitor socket did not show up: No such file or directory

2014-07-16 Thread Dolph Mathews
Public bug reported: In a tempest run, I got a: BuildErrorException: Server cb9b9996-13dd-4f95-9e54-53598723f695 failed to build and is in ERROR status Which appears to have been caused by this from TRACE nova.compute.manager: Traceback (most recent call last): File "/opt/stack/new/nova/nov

[Yahoo-eng-team] [Bug 1342274] Re: auth_token middleware in keystoneclient is deprecated

2014-07-15 Thread Dolph Mathews
Added keystoneclient so we can have it emit a deprecation warning on startup. ** Also affects: python-keystoneclient Importance: Undecided Status: New ** Changed in: python-keystoneclient Assignee: (unassigned) => Dolph Mathews (dolph) ** Changed in: python-keystonecli

[Yahoo-eng-team] [Bug 1079154] Re: limit users not working

2014-07-15 Thread Dolph Mathews
** Changed in: keystone Status: In Progress => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1079154 Title: limit users not working Status in OpenStack Identity (Keys

[Yahoo-eng-team] [Bug 1188202] Re: add_user_to_group should return 409 if conflict

2014-07-15 Thread Dolph Mathews
** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1188202 Title: add_user_to_group should return 409 if conflict Status in Open

[Yahoo-eng-team] [Bug 1258575] Re: Unused index on token table

2014-07-15 Thread Dolph Mathews
** Changed in: keystone Assignee: Dolph Mathews (dolph) => (unassigned) ** Changed in: keystone Status: In Progress => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.ne

[Yahoo-eng-team] [Bug 1337768] Re: keystone v2 api change_password authz require also update_user authz

2014-07-08 Thread Dolph Mathews
This is by design in v2 - that password update call is intended for administrators. In v3, we support a self-service password change that requires the user's existing password: https://github.com/openstack/identity-api/blob/master/v3/src/markdown /identity-api-v3.md#change-user-password-post-use

[Yahoo-eng-team] [Bug 1338550] Re: V3 API project/user/group list only work with domain scoped token

2014-07-08 Thread Dolph Mathews
This is by design. Project, user and group collections are owned by the domain, and therefore the policy requires domain-level authorization to administer those collections. ** Changed in: keystone Status: In Progress => Invalid -- You received this bug notification because you are a memb

[Yahoo-eng-team] [Bug 1338745] Re: Add healthcheck middleware

2014-07-07 Thread Dolph Mathews
It looks like swifts middleware could be moved to oslo, as there's nothing swift-specific about it. There's nothing stopping you from deploying that middleware in front of Keystone or swift, regardless of whether it lives in oslo or swift. ** Description changed: Would be useful for keystone to

[Yahoo-eng-team] [Bug 1336258] Re: Section 'links' misplaced in OS-FEDERATION identity API

2014-07-03 Thread Dolph Mathews
Addressed by https://review.openstack.org/#/c/103888/ ** Project changed: keystone => openstack-api-site ** Changed in: openstack-api-site Status: New => Confirmed ** Changed in: openstack-api-site Status: Confirmed => In Progress -- You received this bug notification because you

[Yahoo-eng-team] [Bug 1336265] Re: Wrong HTTP examples in OS-FEDERATION Trusted Attributes API docs

2014-07-01 Thread Dolph Mathews
Reverting the above API docs in https://review.openstack.org/#/c/103986/ (approved, but blocked by a gate bug atm) which will render this invalid. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, whic

[Yahoo-eng-team] [Bug 1335046] Re: project_additional_attribute_mapping not loaded on Havana

2014-06-27 Thread Dolph Mathews
It looks like this issue specifically affects havana, as Icehouse and master both generate the sample configuration dynamically. Given that keystone.conf.sample represents an important source of documentation, I'd love to see a fix included in stable/havana. ** Also affects: keystone/havana Imp

[Yahoo-eng-team] [Bug 1334739] Re: A bug for test(ignore it)

2014-06-26 Thread Dolph Mathews
** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1334739 Title: A bug for test(ignore it) Status in OpenStack Identity (Keystone):

[Yahoo-eng-team] [Bug 1317302] Re: pki_setup shouldn't be required to check revocations

2014-06-25 Thread Dolph Mathews
** Changed in: keystonemiddleware Assignee: (unassigned) => Brant Knudson (blk-u) ** Changed in: keystonemiddleware Status: New => Triaged ** No longer affects: python-keystoneclient ** Changed in: keystonemiddleware Importance: Undecided => Wishlist ** Changed in: keystone Im

[Yahoo-eng-team] [Bug 1259011] Re: Certificates cannot be retrieved from the V3 API

2014-06-25 Thread Dolph Mathews
** Changed in: keystonemiddleware Importance: Undecided => Wishlist ** Changed in: keystonemiddleware Status: New => Triaged ** No longer affects: python-keystoneclient -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Ke

[Yahoo-eng-team] [Bug 1287938] Re: Keystoneclient logs auth tokens

2014-06-23 Thread Dolph Mathews
Closes-Bug should actually work, but unfortunately the bug was targeted at keystone rather than python-keystoneclient. ** Project changed: keystone => python-keystoneclient -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone.

[Yahoo-eng-team] [Bug 1332601] Re: Refactor "Authenticates and generates a token" docs for Keystone v3

2014-06-23 Thread Dolph Mathews
Happy to see this improved, but we don't require a bug to track the work. Thanks! ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1332

[Yahoo-eng-team] [Bug 1332831] [NEW] order of user list appears inconsistent

2014-06-21 Thread Dolph Mathews
Public bug reported: This appeared as a transient failure in a doc change. I suspect the test shouldn't bother asserting the order of the results, only that the expected values appear in the list. == FAIL: keystone.tests.test_v2

[Yahoo-eng-team] [Bug 1331476] [NEW] ERROR nova.api.metadata.handler [-] Failed to get metadata for ip

2014-06-18 Thread Dolph Mathews
Public bug reported: In console.html, I got: Log: n-api-meta not allowed to have ERRORS or TRACES And in logs/screen-n-api-meta.txt.gz: 2014-06-18 02:51:38.284 DEBUG nova.openstack.common.policy [req-fe1ab254-c41e-41b0-8070-1b1bcc8ca41f None None] Rule network:get_fixed_ip_by_address will be

[Yahoo-eng-team] [Bug 1330771] Re: pbr as run time requirement conflicts with distro packaging

2014-06-17 Thread Dolph Mathews
** Changed in: keystone Status: Incomplete => Invalid ** Changed in: pbr Status: Incomplete => New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1330771 Title: pbr as ru

[Yahoo-eng-team] [Bug 1329884] Re: Conflicting documention on V3 Identity roles route

2014-06-17 Thread Dolph Mathews
This shouldn't affect keystone, as we neither specify nor implement this resource. The apparently equivalent call that we do implement is: GET /v3/role_assignments?user.id={user_id} https://github.com/openstack/identity-api/blob/master/v3/src/markdown /identity-api-v3.md#list-effective-role-as

[Yahoo-eng-team] [Bug 1330771] Re: pbr as run time requirement conflicts with distro packaging

2014-06-17 Thread Dolph Mathews
Is this an issue with PBR or how we're using it? ** Changed in: keystone Status: New => Incomplete ** Also affects: pbr Importance: Undecided Status: New ** Changed in: pbr Status: New => Incomplete -- You received this bug notification because you are a member of Yahoo

[Yahoo-eng-team] [Bug 1330026] Re: API docs say POST token request returns 200

2014-06-14 Thread Dolph Mathews
** Tags removed: documentation ** Tags added: identity-api ** Project changed: keystone => openstack-api-site ** Changed in: openstack-api-site Status: New => Confirmed -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keyst

[Yahoo-eng-team] [Bug 1328359] Re: keystone uses incorrect OS_AUTH_URL

2014-06-13 Thread Dolph Mathews
** Project changed: keystone => python-keystoneclient ** Tags added: user-experience -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1328359 Title: keystone uses incorrect OS_AUTH_URL

[Yahoo-eng-team] [Bug 1328592] Re: Broken error message when no service endpoint exists

2014-06-13 Thread Dolph Mathews
If you find that it's not addressed in 0.9.0, please comment here so we can re-open this. Thanks! ** Changed in: keystone Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.

[Yahoo-eng-team] [Bug 1329864] Re: Owner role is broken in default v2 policy file

2014-06-13 Thread Dolph Mathews
That's originally by design, but I agree with the notion that users should be able to delete their own tokens, even though it's traditionally an administrative function (I see it as "logging out"). ** Changed in: keystone Importance: Undecided => Wishlist ** Changed in: keystone Status:

[Yahoo-eng-team] [Bug 1329385] Re: Keystone doesn't respect policy rules for "grants"

2014-06-12 Thread Dolph Mathews
The policy rules you're looking at apply to the v3 API, but the calls to assert_admin() you've cited are part of the v2 API. The v3 API supports fairly granular policy enforcement, but the v2 API is generally binary (you're either "admin" or not, and all that policy does is define what "admin" mean

[Yahoo-eng-team] [Bug 1328067] Re: Token with "placeholder" ID issued

2014-06-09 Thread Dolph Mathews
** Changed in: keystone Importance: Undecided => Critical ** Also affects: python-keystoneclient Importance: Undecided Status: New ** Changed in: python-keystoneclient Importance: Undecided => Critical -- You received this bug notification because you are a member of Yahoo! Engi

[Yahoo-eng-team] [Bug 1326811] Re: Client failing with six =>1.6 error

2014-06-05 Thread Dolph Mathews
** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Compute (nova). https://bugs.launchpad.net/bugs/1326811 Title: Client failing with six =>1.6 error Status in OpenSt

[Yahoo-eng-team] [Bug 1326421] [NEW] No endpoint ID in v3 KVS or templated catalog

2014-06-04 Thread Dolph Mathews
Public bug reported: The v3 API specifies that endpoints appearing in the service catalog should have an ID [1]. This patch finally introduced v3 support for the KVS and templated backends, but unfortunately does not address the lack of endpoint IDs. Even in the case of the KVS and templated impl

[Yahoo-eng-team] [Bug 1314125] Re: No errors when creating keystone tables when MySQL fails

2014-06-02 Thread Dolph Mathews
** Also affects: openstack-manuals Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1314125 Title: No errors when creating keystone tables when

[Yahoo-eng-team] [Bug 1320855] Re: sql: migration from 37 to 38 version fails

2014-06-02 Thread Dolph Mathews
** Also affects: keystone/icehouse Importance: Undecided Status: New ** Changed in: keystone/icehouse Importance: Undecided => Medium ** Changed in: keystone/icehouse Assignee: (unassigned) => Emilien Macchi (emilienm) ** Changed in: keystone/icehouse Status: New => In P

[Yahoo-eng-team] [Bug 1314129] Re: jsonutils should use simplejson on python 2.6 if available

2014-05-29 Thread Dolph Mathews
Removed python-keystoneclient from this bug due to launchpad issues - fix released in python-keystoneclient 0.9.0. ** No longer affects: python-keystoneclient -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to neutron. https://bugs.l

[Yahoo-eng-team] [Bug 1255321] Re: v3 token requests result in 500 error when run in apache

2014-05-29 Thread Dolph Mathews
** Changed in: python-keystoneclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1255321 Title: v3 token requests result in 500 error whe

[Yahoo-eng-team] [Bug 1174499] Re: Keystone token hashing is MD5

2014-05-29 Thread Dolph Mathews
** Changed in: python-keystoneclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1174499 Title: Keystone token hashing is MD5 Status in

[Yahoo-eng-team] [Bug 1250617] Re: Limited use trusts

2014-05-29 Thread Dolph Mathews
** Changed in: python-keystoneclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1250617 Title: Limited use trusts Status in OpenStack I

[Yahoo-eng-team] [Bug 1312858] Re: Keystone + Devstack fail when KEYSTONE_TOKEN_FORMAT=UUID

2014-05-29 Thread Dolph Mathews
** Changed in: python-keystoneclient Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1312858 Title: Keystone + Devstack fail when KEYSTONE_TO

[Yahoo-eng-team] [Bug 1241032] Re: test_static_translated_string_is_Message fails when building in Wheezy (with backports)

2014-05-28 Thread Dolph Mathews
** Also affects: keystone/icehouse Importance: Undecided Status: New ** Changed in: keystone/icehouse Status: New => Triaged ** Changed in: keystone/icehouse Importance: Undecided => Low -- You received this bug notification because you are a member of Yahoo! Engineering Tea

[Yahoo-eng-team] [Bug 1241032] Re: test_static_translated_string_is_Message fails when building in Wheezy (with backports)

2014-05-28 Thread Dolph Mathews
IIRC, this was actually being caused by an out-of-tree patch being carried by Debian. Please re-open if I'm mistaken. ** Changed in: keystone Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Key

[Yahoo-eng-team] [Bug 1065233] Re: Roles in XML response of v2 Validate Token Call not inline with Identity Service Documentation

2014-05-27 Thread Dolph Mathews
++ ** Changed in: keystone Status: Triaged => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1065233 Title: Roles in XML response of v2 Validate Token Call not inline

[Yahoo-eng-team] [Bug 948644] Re: Service users and service tenant show up in syspanel

2014-05-27 Thread Dolph Mathews
We now have containers for users (domains and external IdPs), which I think satisfies the requirement for certain users to carry a special designation (they could be owned by a service domain, for example). ** Changed in: keystone Importance: Medium => Wishlist ** Changed in: keystone S

[Yahoo-eng-team] [Bug 1322771] Re: keystone install from source docs missing required steps

2014-05-23 Thread Dolph Mathews
Most of the issues described here are resolved by following the dev docs [1] instead of the "install from source" docs. I think it would be best to merge these two documents, or just outright nuke the "install from packaging" [2] page since that should really be documented downstream, or in opensta

[Yahoo-eng-team] [Bug 1321797] Re: Tempest fails on backports to Icehouse

2014-05-23 Thread Dolph Mathews
Thanks, treinish! ** Changed in: keystone Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1321797 Title: Tempest fails on backports to Icehouse Sta

[Yahoo-eng-team] [Bug 1321797] Re: Tempest fails on backports to Icehouse

2014-05-23 Thread Dolph Mathews
I believe I saw this issue being discussed as either a tempest or grenade issue, but I'm unable to find the bug report... filing against those projects in hopes of seeing this marked as a dupe :) Otherwise, poke me if I'm mistaken. ** Also affects: tempest Importance: Undecided Status: N

[Yahoo-eng-team] [Bug 1322187] [NEW] Sensitive error messages are alarming

2014-05-22 Thread Dolph Mathews
avior. ** Affects: keystone Importance: Low Assignee: Dolph Mathews (dolph) Status: Triaged ** Tags: user-experience -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1322187

[Yahoo-eng-team] [Bug 1319425] Re: keystone link not created in /etc/init.d

2014-05-22 Thread Dolph Mathews
** Project changed: keystone => keystone (Ubuntu) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1319425 Title: keystone link not created in /etc/init.d Status in “keystone” package in

<    1   2   3   4   5   6   7   >