Bug 1438015
| Summary: | Heat doesn't renew token leading to authorization failure in deployments going past default 240 min timeout | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Sai Sindhur Malleni <smalleni> |
| Component: | instack-undercloud | Assignee: | Rabi Mishra <ramishra> |
| Status: | CLOSED ERRATA | QA Contact: | Ronnie Rasouli <rrasouli> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 10.0 (Newton) | CC: | mburns, ramishra, rhel-osp-director-maint, sbaker, shardy, srevivo, tvignaud, zbitter |
| Target Milestone: | rc | Keywords: | Triaged, ZStream |
| Target Release: | 12.0 (Pike) | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | instack-undercloud-7.1.1-0.20170616135935.el7ost | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-12-13 21:22:29 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Sai Sindhur Malleni
2017-03-31 15:55:35 UTC
To allow re-authentication on token expiry, such that long-running tasks may complete, heat has a flag 'reauthentication_auth_method', which can be set to 'trusts' in heat.conf. This would allow for trust to be used in place of user token. Do we need to change something in TripleO to make that the default? Fixed upstream, but backports are not feasible due to reliance on new features as well as bug fixes in other projects. Retargeting for OSP12. fixed landed on downstream Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2017:3462 |