[Yahoo-eng-team] [Bug 1910419] Re: Sphinx 3.4.2 breaks documentation builds with Flask

2022-02-22 Thread Gage Hugo
This appears to have been fixed in upstream Sphinx. ** Changed in: keystone Status: New => Won't Fix -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1910419

[Yahoo-eng-team] [Bug 1877393] Re: train release notes link to explicit_domain_id spec wrong

2021-12-07 Thread Gage Hugo
** Changed in: keystone Status: In Progress => Fix Released ** Changed in: keystone Importance: Undecided => Low -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone).

[Yahoo-eng-team] [Bug 1901207] Re: Application credentials of other users can be deleted when knowing the ID

2021-12-07 Thread Gage Hugo
** Changed in: keystone Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1901207 Title: Application credentials of other

[Yahoo-eng-team] [Bug 1936425] Re: Install and configure in keystone: problem when bootstraping the identity service

2021-07-15 Thread Gage Hugo
** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1936425 Title: Install and configure in keystone: problem when

[Yahoo-eng-team] [Bug 1901902] Re: Authtoken not used when changing password through CLI

2020-10-28 Thread Gage Hugo
This is by design. The change user password API does not require a token, mostly due to a user requiring an administrator to reset their password if it expires since they cannot authenticate for a token. If an attacker gets a username and password, having a token required to change a password

[Yahoo-eng-team] [Bug 1866614] Re: CSV Injection in instance edit form in the name field

2020-10-26 Thread Gage Hugo
*** This bug is a duplicate of bug 1842749 *** https://bugs.launchpad.net/bugs/1842749 Since there hasn't been an update to Jeremy's question, we are going to mark this as a duplicate of bug 1842749 since this appears to be the same issue. ** This bug has been marked a duplicate of bug

[Yahoo-eng-team] [Bug 1895723] Re: Keystone is restarting due to stale primary key

2020-09-15 Thread Gage Hugo
** Also affects: kolla-ansible Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1895723 Title: Keystone is restarting due

[Yahoo-eng-team] [Bug 1883659] Re: keystonemiddleware connections to memcached from neutron-server grow beyond configured values

2020-06-16 Thread Gage Hugo
Added oslo.cache, not 100% sure which is affected yet. ** Also affects: oslo.cache Importance: Undecided Status: New ** No longer affects: keystone -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity

[Yahoo-eng-team] [Bug 1883659] Re: keystonemiddleware connections to memcached from neutron-server grow beyond configured values

2020-06-16 Thread Gage Hugo
Added keystonemiddleware ** Also affects: keystonemiddleware Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1883659

[Yahoo-eng-team] [Bug 1855080] Re: Credentials API allows listing and retrieving of all users credentials

2020-01-02 Thread Gage Hugo
OSSA Report: https://review.opendev.org/#/c/698045/ ** Changed in: ossa Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone).

[Yahoo-eng-team] [Bug 1856904] [NEW] CADF Notifications are missing user name in initiator object

2019-12-18 Thread Gage Hugo
Public bug reported: When enabling CADF notifications, each event notification contains an initiator object, this object contains an id, typeuri, project_id, etc. This notification is useful for auditors to determine who has authenticated and/or what action a user has performed. The various

[Yahoo-eng-team] [Bug 1840288] Re: Trusts GET API leaks existence information to unauthorized users

2019-08-15 Thread Gage Hugo
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions. ** Also affects: ossa

[Yahoo-eng-team] [Bug 1781536] Re: Wrong port number in Queens install guide

2018-11-27 Thread Gage Hugo
Fixed here: https://review.openstack.org/#/c/616286/ ** Changed in: keystone Assignee: (unassigned) => Gage Hugo (gagehugo) ** Changed in: keystone Status: Confirmed => Fix Committed ** Changed in: keystone Status: Fix Committed => Fix Released -- You received

[Yahoo-eng-team] [Bug 1796077] Re: policy.json doesn't allow user to change password

2018-10-04 Thread Gage Hugo
Users have their own self-service API[0] they can call to change their own password. This is separate from the update_user one, and is currently not covered by any policy. There are ways to enforce security regulations (PCI-DSS) on users, which is more defined here[1]. [0]

[Yahoo-eng-team] [Bug 1795415] Re: Verify operation in keystone

2018-10-01 Thread Gage Hugo
*** This bug is a duplicate of bug 1790148 *** https://bugs.launchpad.net/bugs/1790148 ** This bug has been marked a duplicate of bug 1790148 Verify operation in keystone (Documentation fault) -- You received this bug notification because you are a member of Yahoo! Engineering Team,

[Yahoo-eng-team] [Bug 1794112] Re: Install and configure in keystone connection mysql

2018-09-25 Thread Gage Hugo
Closing out then. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1794112 Title: Install and configure in

[Yahoo-eng-team] [Bug 1793816] Re: Verify operation in keystone

2018-09-21 Thread Gage Hugo
*** This bug is a duplicate of bug 1790148 *** https://bugs.launchpad.net/bugs/1790148 ** This bug has been marked a duplicate of bug 1790148 Verify operation in keystone (Documentation fault) -- You received this bug notification because you are a member of Yahoo! Engineering Team,

[Yahoo-eng-team] [Bug 1780503] [NEW] identity.authenticate CADF initiator id is random

2018-07-06 Thread Gage Hugo
quot;oslo.message": "{\"priority\": \"INFO\", \"_unique_id\": \"e13c4eb09440496cb80b2297a61c12b8\", \"event_type\": \"identity.authenticate\", \"timestamp\": \"2018-07-06 22:56:45.572963\", \"publish

[Yahoo-eng-team] [Bug 1775295] Re: Queen keystone installation instructions outdated, keystone-managed credential_setup invalid choice

2018-06-06 Thread Gage Hugo
Seems like ubuntu 16.04 ships with Mitaka, and I think "credential_setup" was added in Newton so that would explain why the command is missing. The docs seem to be correct though in terms of setting up the queens repo. ** Changed in: keystone Status: New => Invalid -- You received this

[Yahoo-eng-team] [Bug 1761538] Re: Cookie hash value displayed in rabbitmq logs

2018-04-05 Thread Gage Hugo
This likely is more related to RabbitMQ (and as fungi pointed out, should probably be noted in OSSN) if it has a security impact on OpenStack as a whole, rather than specifically keystone. ** Also affects: ossn Importance: Undecided Status: New ** Changed in: keystone Status:

[Yahoo-eng-team] [Bug 1756190] Re: Project tags is too restrictive

2018-03-20 Thread Gage Hugo
This may affect KSC as well, see [0]. [0] https://review.openstack.org/#/c/553108/3/keystone/resource/backends/sql.py@182 ** Also affects: python-keystoneclient Importance: Undecided Status: New -- You received this bug notification because you are a member of Yahoo! Engineering

[Yahoo-eng-team] [Bug 1738372] Re: Install and configure in keystone

2018-03-16 Thread Gage Hugo
I was able to duplicate this, it seems like there may be an issue with the heat devstack plugin, when running devstack (stable/ocata) it originally checks out stable/ocata heat, but once it hits the devstack plugin it will checkout master heat, and then hit: 2018-02-04 15:56:12.694 | from

[Yahoo-eng-team] [Bug 1756140] [NEW] Project Tags Documentation Wrong - Create Tag

2018-03-15 Thread Gage Hugo
** Affects: keystone Importance: Low Assignee: Gage Hugo (gagehugo) Status: In Progress ** Changed in: keystone Status: New => Triaged -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Ident

[Yahoo-eng-team] [Bug 1755511] Re: Install and configure in keystone

2018-03-13 Thread Gage Hugo
With Queens most of the v2 API was removed (minus ec2 related) and port 35357 is a leftover relic from v2 when the admin APIs relied on using it, vs 5000 for public. With V3 the separation of ports is not necessary, admin is fine on 5000. ** Changed in: keystone Status: New => Invalid --

[Yahoo-eng-team] [Bug 1752301] [NEW] Project tags treats entire collection as a single tag

2018-02-28 Thread Gage Hugo
:32:42 [2] http://eavesdrop.openstack.org/irclogs/%23openstack-keystone /%23openstack-keystone.2018-02-27.log.html#t2018-02-27T21:24:34 ** Affects: keystone Importance: High Assignee: Gage Hugo (gagehugo) Status: In Progress -- You received this bug notification because you

[Yahoo-eng-team] [Bug 1749397] Re: In Verify operation of the Identity service 1st step is not required as the file /etc/keystone/keystone-paste.ini doesn't contain admin_auth_token

2018-02-21 Thread Gage Hugo
*** This bug is a duplicate of bug 1716797 *** https://bugs.launchpad.net/bugs/1716797 Looks like this was reported right after https://bugs.launchpad.net/keystone/+bug/1716797 was committed. ** This bug has been marked a duplicate of bug 1716797 Verify operation in keystone: step 1 has

[Yahoo-eng-team] [Bug 1742648] Re: Doc build(both html and man) failing with sphinx 1.6.6

2018-01-17 Thread Gage Hugo
This is probably more of an issue with sphinx then, as the current solution is to block it on upper constraints[0]. [0] https://review.openstack.org/#/c/534779/ ** Changed in: keystone Status: Confirmed => Invalid -- You received this bug notification because you are a member of Yahoo!

[Yahoo-eng-team] [Bug 1738946] Re: so many Relationship links in api-ref documentation are userless

2017-12-19 Thread Gage Hugo
The links aren't useless, but it has come up multiple times where users are confused what their purpose is for. The best explanation we have for them is here[0]. [0] https://bugs.launchpad.net/keystone/+bug/1674676/comments/3 ** Changed in: keystone Status: New => Opinion -- You

[Yahoo-eng-team] [Bug 1719492] Re: admin_token_auth not found

2017-11-01 Thread Gage Hugo
Yeah this looks like it's a duplicate of the bug that Craig posted. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone).

[Yahoo-eng-team] [Bug 1717312] Re: Keystone Installation Tutorial for Ubuntu in keystone

2017-09-14 Thread Gage Hugo
This is a duplicate of https://bugs.launchpad.net/keystone/+bug/1716899 and already has a fix in review. ** Changed in: keystone Status: New => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity

[Yahoo-eng-team] [Bug 1714179] Re: keystone project can not update or search extra filed

2017-09-07 Thread Gage Hugo
I think the idea for extras was to add custom fields, but not allow the entire "extras" json blob to be searchable so that resources in keystone wouldn't become data stores. You can already update these fields by their attribute name (I know "email" is a popular one for Users), but searching would

[Yahoo-eng-team] [Bug 1689468] Re: odd keystone behavior when X-Auth-Token ends with carriage return

2017-07-12 Thread Gage Hugo
** Also affects: keystonemiddleware Importance: Undecided Status: New ** Changed in: keystonemiddleware Status: New => In Progress -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone).

[Yahoo-eng-team] [Bug 1436957] Re: assertRaisesRegexp has been deprecated for assertRaisesRegex

2017-06-02 Thread Gage Hugo
Keystone has custom test tools [0] for this (which are named the same and slightly confusing). The one assertRaisesRegexp test tool was added [1] as a fix for py26 and is not the same as the function from python 2. It might be useful to change the name of [0] to avoid any future confusion, but for

[Yahoo-eng-team] [Bug 1668173] Re: Update release notes bp link

2017-05-19 Thread Gage Hugo
This was fixed and merged, the commit message had "Clouse-Bug:#1668173" which probably caused the bot to miss it. ** Changed in: keystone Status: Triaged => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to

[Yahoo-eng-team] [Bug 1659053] Re: use uuids with pycadf

2017-02-02 Thread Gage Hugo
** Also affects: pycadf Importance: Undecided Status: New ** Changed in: pycadf Status: New => In Progress ** Changed in: pycadf Assignee: (unassigned) => Gage Hugo (gagehugo) -- You received this bug notification because you are a member of Yahoo! Engineering Team,

[Yahoo-eng-team] [Bug 1608653] [NEW] Installing reqs from test-requirements.txt using pip fails due to missing lib package for psycopg2

2016-08-01 Thread Gage Hugo
bpg-dev (Ubuntu/Debian) along with other package managers to the list of dependencies to install before using pip: http://docs.openstack.org/developer/keystone/devref/development.environment.html #installing-dependencies ** Affects: keystone Importance: Undecided Assignee: Gage Hugo (gagehugo)

[Yahoo-eng-team] [Bug 1533322] Re: "extra_resources" is hidden in ComputeNode

2016-04-13 Thread Gage Hugo
blueprint and come on to IRC Freenode #openstack-nova channel to discuss how to implement this functionality. Going to abandon the change for now. ** Changed in: nova Status: In Progress => Invalid ** Changed in: nova Assignee: Gage Hugo (gh159m) => (unassigned) -- You received th