marking this as invalid. based on the latest keystone meeting it was decided that the behaviour is correct
** Changed in: keystone Status: In Progress => Invalid ** Changed in: keystone Milestone: mitaka-3 => None -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Identity (keystone). https://bugs.launchpad.net/bugs/1534834 Title: Policy check forces impersonation for redelgation of trust Status in OpenStack Identity (keystone): Invalid Bug description: When redelegating a trust, the API specifies that the trustor_id is the original trustor_id. However, the policy check for create_trust enforces that user_id = trust.trustor_user_id. Effectily limiting the redelgation ofr trusts to trusts which provide impersonation. To manage notifications about this bug go to: https://bugs.launchpad.net/keystone/+bug/1534834/+subscriptions -- Mailing list: https://launchpad.net/~yahoo-eng-team Post to : yahoo-eng-team@lists.launchpad.net Unsubscribe : https://launchpad.net/~yahoo-eng-team More help : https://help.launchpad.net/ListHelp