Back to bug 2210030

Who When What Removed Added
Red Hat One Jira (issues.redhat.com) 2023-05-25 14:10:59 UTC Link ID Red Hat Issue Tracker OSP-25387
Candido Campos 2023-05-25 14:28:31 UTC Keywords AutomationBlocker, Triaged
QA Contact ekuris ccamposr
Assignee rhos-maint skaplons
Status NEW ASSIGNED
Slawek Kaplonski 2023-05-25 14:36:51 UTC Summary [NEUTRON][SRBAC]Custom poliies don't work properly with shared security groups [NEUTRON][SRBAC]Custom policies don't work properly with shared security groups
Eran Kuris 2023-05-29 08:05:09 UTC Severity unspecified high
CC ekuris
Target Milestone --- ga
RHEL Program Management 2023-05-29 08:05:17 UTC Target Release --- 17.1
Yatin Karel 2023-05-29 14:09:30 UTC Priority unspecified high
CC ykarel
Paul Grist 2023-05-30 14:58:40 UTC CC pgrist
Slawek Kaplonski 2023-06-02 09:31:06 UTC Status ASSIGNED ON_DEV
Link ID OpenStack gerrit 812617 OpenStack gerrit 811242
Rodolfo Alonso 2023-06-05 10:41:36 UTC CC ralonsoh
Rodolfo Alonso 2023-06-06 11:00:38 UTC Status ON_DEV MODIFIED
Fixed In Version python-neutron-lib-2.10.2-1.20230606093758.6bbae46.el8osttrunk openstack-neutron-18.6.1-1.20230606090757.a26b5ea.el9osttrunk
James Smith 2023-06-14 20:30:21 UTC Flags needinfo?(ccamposr)
CC jamsmith
Greg Rakauskas 2023-06-14 21:10:30 UTC CC gregraka
Candido Campos 2023-06-15 12:52:07 UTC Doc Text Shared security rules between users can not be listed for the non owners user that were being used them (at least they have an admin rule) if srbac custom rules are enable. No W/A
Candido Campos 2023-06-15 12:59:39 UTC Doc Text Shared security rules between users can not be listed for the non owners user that were being used them (at least they have an admin rule) if srbac custom rules are enable. No W/A Cause:
Custom srbac rules don't permit list shared security groups to non admin users, not rule owners
Consequence:
Shared security groups/rules cannot be managed properly by non admin users, not rule owners

Workaround (if any): Disable custom srbac. Or to modify the srbac custom rule to permit to any this action.

Result:
Doc Type If docs needed, set a value Known Issue
Candido Campos 2023-06-15 13:00:12 UTC Flags needinfo?(ccamposr)
Erin Peterson 2023-06-15 13:39:57 UTC Doc Text Cause:
Custom srbac rules don't permit list shared security groups to non admin users, not rule owners
Consequence:
Shared security groups/rules cannot be managed properly by non admin users, not rule owners

Workaround (if any): Disable custom srbac. Or to modify the srbac custom rule to permit to any this action.

Result:
There is currently a known issue where custom SRBAC rules do not permit list shared security groups to non-administrative users that are not rule owners. This causes shared security groups and rules to not be managed properly by non-administrative users that are not rule owners. Workaround: Disable custom SRBAC rules or modify the custom rules to permit any user to manage the rules.
CC erpeters
errata-xmlrpc 2023-06-20 22:17:19 UTC Status MODIFIED ON_QA
Jon Schlueter 2023-06-21 12:21:52 UTC Fixed In Version python-neutron-lib-2.10.2-1.20230606093758.6bbae46.el8osttrunk openstack-neutron-18.6.1-1.20230606090757.a26b5ea.el9osttrunk python-neutron-lib-2.10.2-1.20230510080958.el9ost openstack-neutron-18.6.1-1.20230518200969.el9ost
CC jschluet
Paul Grist 2023-06-21 22:27:13 UTC Target Milestone ga ---
Target Release 17.1 ---
Candido Campos 2023-06-22 10:31:16 UTC Status ON_QA VERIFIED
James E. LaBarre 2023-07-31 14:38:08 UTC CC jlabarre
Ian Frangs 2023-08-03 15:46:23 UTC CC skaplons
Flags needinfo?(skaplons)
Slawek Kaplonski 2023-08-09 06:42:45 UTC Flags needinfo?(skaplons)
Jenny-Anne Lynch 2023-08-15 17:19:33 UTC Flags needinfo?(skaplons) needinfo?(ccamposr)
CC jelynch
errata-xmlrpc 2023-08-16 00:03:16 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2023-08-16 01:15:24 UTC Resolution --- ERRATA
Status RELEASE_PENDING CLOSED
Last Closed 2023-08-16 01:15:24 UTC
errata-xmlrpc 2023-08-16 01:15:47 UTC Link ID Red Hat Product Errata RHEA-2023:4577
Candido Campos 2023-08-16 10:38:40 UTC Flags needinfo?(ccamposr)

Back to bug 2210030