Bug 1335991
| Summary: | Keystone fails to issue tokens when fernet tokens are enabled, as a result of key repo validation | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Ken Savich <ksavich> |
| Component: | openstack-keystone | Assignee: | Adam Young <ayoung> |
| Status: | CLOSED ERRATA | QA Contact: | Rodrigo Duarte <rduartes> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 8.0 (Liberty) | CC: | david.costakos, jdennis, nkinder, rduartes, srevivo |
| Target Milestone: | beta | Keywords: | Triaged |
| Target Release: | 10.0 (Newton) | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | openstack-keystone-10.0.0-0.20160823153130.a445165.el7ost | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-12-14 15:33:35 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Ken Savich
2016-05-13 18:27:42 UTC
Fernet is not supported in OSP8. It is expected to be supported (and the default token provider) in OSP10. Removed external bug tracker since it was pointing to a "inkscape" bug. verified for openstack-keystone-10.0.0-0.20160928144040.6520523.el7ost.noarch (single controller setup - no HA) [root@controller-0 ~]# keystone-manage fernet_setup --keystone-user keystone --keystone-group keystone [root@controller-0 ~]# vi /etc/keystone/keystone.conf # set [token] provider to fernet [root@controller-0 ~]# systemctl restart httpd in the undercloud: [stack@undercloud-0 ~]$ source overcloudrc [stack@undercloud-0 ~]$ openstack token issue +------------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ | Field | Value | +------------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ | expires | 2016-10-07 18:18:37+00:00 | | id | gAAAAABX99jtDum2H2oRccqN855TZFBnHgQqCiwO9eSrBqEKWw-X6839IZBmN14lJv6Ii1JD0dQ5eszfFIJynnVSegetyIkzdAMjaatiMcea697JPUMklSekhRAOqEMrwmi0dclW6E7Pyk9dttqgATwg3jN9fM65VnQP6DQY2vZWUVUraZ4yC_o | | project_id | 1301b4f18bef494d971a416bf52de1b5 | | user_id | e4bb01b557054eeca41ee0aec32db730 | +------------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+ Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2016-2948.html |