Bug 1124589
| Summary: | python-kombu does not work with Qpid unless the user adjusts qpidd.conf | ||
|---|---|---|---|
| Product: | [Retired] Pulp | Reporter: | Brian Bouterse <bmbouter> |
| Component: | user-experience | Assignee: | Chris Duryee <cduryee> |
| Status: | CLOSED UPSTREAM | QA Contact: | Preethi Thomas <pthomas> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | high | ||
| Version: | 2.4 Beta | CC: | cduryee, pthomas, skarmark |
| Target Milestone: | --- | Keywords: | Triaged |
| Target Release: | 2.6.0 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-02-28 22:14:03 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Brian Bouterse
2014-07-29 21:01:52 UTC
Two users on the mailing list indicated they spent a lot of time as a result of this not being fixed. I'm moving it to 2.5.1 with high priority. After looking more into this, this should work today if the user makes no changes to the qpidd.conf and has cyrus-sasl-plain installed, except that Qpid doesn't create the SASL DB with guest/guest as it says it does. I've filed an upstream issue [0] with Qpid on this, but we should still enable ANONYMOUS auth. The reasons I have are these: 1) a SASL auth that uses guest/guest is no more secure than ANONYMOUS auth 2) ANONYMOUS achieves the out of the box experience we are looking for 3) upstream kombu doesn't have a mechanism to bundle cyrus-sasl-plain automatically so their unboxing experience will still require thought, reading, and effort Through discussion in IRC, upstream Qpid will likely remove the docs statements that claim that they configure a simple SASL DB for the users. That double-ly supports the idea of us allowing ANONYMOUS because Qpid literally only works with ANONYMOUS out of the box. merged to pulp/kombu and pulp/pulp (2.5-dev and master) The actual PR for this was made later, and is: https://github.com/pulp/pulp/pull/1165 fixed in pulp 2.6.0-0.2.beta verified pulp server works without having to make auth=no ins qpidd.conf Tested in el6 & el7 Moved to https://pulp.plan.io/issues/477 |