[Yahoo-eng-team] [Bug 1617361] [NEW] Federation mapping schema docs out of date

2016-08-26 Thread Marek Denis
Importance: Low Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: documentation ** Changed in: keystone Assignee: (unassigned) => Marek Denis (marek-denis) ** Changed in: keystone Importance: Undecided => Low ** Description changed: Federation mapping

[Yahoo-eng-team] [Bug 1559022] [NEW] Remove SP filering documentation

2016-03-18 Thread Marek Denis
Public bug reported: SP filetering should be removed as the code didn't land in Mitaka (so avoid user confusion and code-docs dissynchronisation) ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: documentation

[Yahoo-eng-team] [Bug 1532745] [NEW] Wrong links in Service Providers filtering API docs

2016-01-11 Thread Marek Denis
Public bug reported: Some of the links in the Service Providers filtering API docs are incorrect. ** Affects: keystone Importance: Low Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: documentation -- You received this bug notification because you

[Yahoo-eng-team] [Bug 1505298] [NEW] No JSONSchema validation on some of federation API calls

2015-10-12 Thread Marek Denis
Public bug reported: Identity providers, Mapping and Protocols CRUD requests should be validated with JSONSchema. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New ** Tags: federation -- You received this bug notification because

[Yahoo-eng-team] [Bug 1489474] [NEW] Lack of federated token user object validation

2015-08-27 Thread Marek Denis
Importance: Wishlist Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: federation test-improvement -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1489474 Title

[Yahoo-eng-team] [Bug 1487115] [NEW] Ephemeral user's id is not always urlsafe

2015-08-20 Thread Marek Denis
with six.moves.urllib.parse.quote() function. ** Affects: keystone Importance: Medium Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: federation -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https

[Yahoo-eng-team] [Bug 1482701] [NEW] Federation: user's name in rules not respected

2015-08-07 Thread Marek Denis
and Fernet tokens. ** Affects: keystone Importance: Medium Assignee: Marek Denis (marek-denis) Status: New ** Tags: federation ** Changed in: keystone Importance: Undecided = Medium -- You received this bug notification because you are a member of Yahoo! Engineering Team, which

[Yahoo-eng-team] [Bug 1474997] [NEW] Federated tests don't check group existence in federated tokens

2015-07-15 Thread Marek Denis
Importance: Low Assignee: Marek Denis (marek-denis) Status: New ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek-denis) ** Changed in: keystone Importance: Undecided = Low -- You received this bug notification because you are a member of Yahoo

[Yahoo-eng-team] [Bug 1210141] Re: Document howto config LDAP identity with non-DN based ids.

2015-07-06 Thread Marek Denis
** Changed in: keystone Status: In Progress = Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1210141 Title: Document howto config LDAP identity with non-DN based ids.

[Yahoo-eng-team] [Bug 1468501] [NEW] keystone-manage should accept both formats of mapping rules

2015-06-24 Thread Marek Denis
. ** Affects: keystone Importance: Wishlist Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: federation -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs

[Yahoo-eng-team] [Bug 1466092] [NEW] Docs say OS-FEDERATION is an extension

2015-06-17 Thread Marek Denis
://docs.openstack.org/developer/keystone/configure_federation.html ** Affects: keystone Importance: Low Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: documentation federation -- You received this bug notification because you are a member of Yahoo! Engineering Team

[Yahoo-eng-team] [Bug 1466093] [NEW] Docs say K2K is experimental

2015-06-17 Thread Marek Denis
/configure_federation.html#keystone-as-an-identity-provider-idp ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: Invalid ** Tags: documentation federation ** Changed in: keystone Status: New = Invalid -- You received this bug

[Yahoo-eng-team] [Bug 1461031] [NEW] Federation docs say domain is identified by name not id

2015-06-02 Thread Marek Denis
://github.com/openstack/keystone/blob/master/keystone/contrib/federation/utils.py#L529-L533 ** Affects: keystone Importance: Low Assignee: Marek Denis (marek-denis) Status: In Progress ** Tags: documentation ** Changed in: keystone Importance: Undecided = Low ** Changed

[Yahoo-eng-team] [Bug 1434653] [NEW] Empty mappring engine white/black lists should be treated differently than lack of them.

2015-03-20 Thread Marek Denis
: Low Assignee: Marek Denis (marek-denis) Status: In Progress ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek-denis) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https

[Yahoo-eng-team] [Bug 1416459] [NEW] Disabling identity providers doesn't work

2015-01-30 Thread Marek Denis
Public bug reported: During federated authentication we don't check if the identity provider is disabled or not. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek

[Yahoo-eng-team] [Bug 1401057] [NEW] Direct mapping in mapping rules don't work with keywords

2014-12-10 Thread Marek Denis
Public bug reported: Federation mapping engine doesn't work correctly when a rule to be directly mapped has special keywords (any_one_of or not_any_of). For instance: rules = [ { local: [ { user: { name: {0} } }, {

[Yahoo-eng-team] [Bug 1373961] [NEW] Missing version attribute while generating K2K SAML assertion

2014-09-25 Thread Marek Denis
Denis (marek-denis) Status: New ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek-denis) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1373961 Title

[Yahoo-eng-team] [Bug 1374033] [NEW] wsgi generating wrong entity_id values when issuing saml assertions.

2014-09-25 Thread Marek Denis
Public bug reported: Attribute issuer should always be set to CONF.saml.idp_entity_id, otherwise entityID from the IdP metadata and the generated assertion can differ and hence make Service Provider reject the assertion. ** Affects: keystone Importance: Undecided Assignee: Marek Denis

[Yahoo-eng-team] [Bug 1372956] [NEW] Wrong idp_metadata_path parameter group

2014-09-23 Thread Marek Denis
Denis (marek-denis) Status: New ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek-denis) -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1372956 Title: Wrong

[Yahoo-eng-team] [Bug 1350713] [NEW] Store configuration error in sheepdog

2014-07-31 Thread Marek Denis
Public bug reported: I have found following errors along with the deprecated warning 2014-07-30 21:05:14.971 9608 ERROR glance.store.sheepdog [-] Error in store configuration: [Errno 2] No such file or directory 2014-07-30 21:05:14.972 9608 WARNING glance.store [-] Deprecated:

[Yahoo-eng-team] [Bug 1336258] [NEW] Section 'links' misplaced in OS-FEDERATION identity API

2014-07-01 Thread Marek Denis
] } ] } ] } } whereas 'links' section should be inside 'mappings' section. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New ** Changed in: keystone

[Yahoo-eng-team] [Bug 1336265] [NEW] Wrong HTTP examples in OS-FEDERATION Trusted Attributes API docs

2014-07-01 Thread Marek Denis
Public bug reported: OS-FEDERATION IDentity API's trusted attribute's HTTP requests and responses are not correct: For instance (https://github.com/openstack/identity- api/blob/master/v3/src/markdown/identity-api-v3-os-federation-ext.md

[Yahoo-eng-team] [Bug 1275695] Re: Enabling Federation extension causes Unregistered dependency: federation_api

2014-06-02 Thread Marek Denis
** Changed in: keystone Status: In Progress = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to Keystone. https://bugs.launchpad.net/bugs/1275695 Title: Enabling Federation extension causes Unregistered

[Yahoo-eng-team] [Bug 1312221] [NEW] Add user objects to mapping rules examples in OS-FEDERATION docs

2014-04-24 Thread Marek Denis
-FEDERATION extension include. This should be fixed, as well as docs should clearly state that all the rules should map the user name. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New ** Changed in: keystone Assignee: (unassigned) = Marek

[Yahoo-eng-team] [Bug 1296348] [NEW] /v3/auth/tokens cannot be used for issuing unscoped tokens during federated authn

2014-03-23 Thread Marek Denis
data used by the client is lost (due to many HTTP redirections between SP and IdP) it's advised for clients to access URL with IdP and protocol specified in the URL. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New ** Changed in: keystone

[Yahoo-eng-team] [Bug 1294150] [NEW] Keystone fails when returning unscoped federated token as XML

2014-03-18 Thread Marek Denis
keystone.middleware.core ValueError: Invalid tag name u'OS-FEDERATION:groups' ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: In Progress ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek-denis) -- You received this bug

[Yahoo-eng-team] [Bug 1293436] [NEW] Allow filtering variables passed to the RuleProcessor

2014-03-17 Thread Marek Denis
Public bug reported: During SAML2 authentication the whole environment dictionary is passed to the RuleProcessor object (this dictionary will only contain basestring inheriting values after the bug #1290258 is fixed). It'd be much better to additionally let users filter what can be passed to

[Yahoo-eng-team] [Bug 1290258] [NEW] Group ids are not validated after SAML2-groups mapping and federated token scoping

2014-03-10 Thread Marek Denis
nonexisting groups from the list. The same policy should be applied when scoping federated unsoped token. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New ** Changed in: keystone Assignee: (unassigned) = Marek Denis (marek-denis

[Yahoo-eng-team] [Bug 1288124] [NEW] Update docstrings in auth/tokens/plugins/saml2.py and contrib/federation/routers.py

2014-03-05 Thread Marek Denis
Public bug reported: Files keystone/auth/tokens/plugins/saml2.py and keystone/contrib/federation/routers.py have outdated docstrings. They should be fixed to match the current code. ** Affects: keystone Importance: Undecided Assignee: Marek Denis (marek-denis) Status: New