Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-22365

Application credentials with custom access rules broken by default

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhos-17.1.z, rhos-18.0.z
    • keystone-operator
    • None
    • Moderate

      To Reproduce Steps to reproduce the behavior:

      1. Deploy RHOSP 17.1
      2. Create an application credential with custom access rules
      3. Test the application credential by issuing a command that requires one of the rules defined above
      4. The command fails with an error like this:
      $ openstack server list
      The request you have made requires authentication. (HTTP 401) (Request-ID: req-1d0e98cd-86d6-4723-ab81-7dda35051450) 

      Expected behavior

      • Application credentials with custom access rules should work out-of-the-box

       

      Bug impact

      • Users can not use application credentials with custom rules 

      Known workaround

      • Customers need to run through the process described in this article [0]

      Additional context

      • Custom access rules are allowed both through the web interface as well as the CLI
      • This gives the impression that this feature is fully functional without any custom configuration of openstack services
      • Customers need to  have a better understanding of what the consequences are when changing the `[keystone_authtoken]/service_type` for one or multiple services.
      • If changing these parameters has no negative consequence, then that should be the default configuration instead of being undefined.

       

      [0] https://access.redhat.com/solutions/6965564

       

              Unassigned Unassigned
              rhn-support-enothen Eric Nothen
              rhos-dfg-security
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: