Re: [openstack-dev] [Horizon][Keystone] Failed to set up keystone v3 api for horizon

2015-03-12 Thread Ali, Haneef
Horizon needs to support domain scoped token for this to work. I don’t think it is yet there. https://review.openstack.org/#/c/148082/39 https://review.openstack.org/#/c/141153/ Thanks Haneef From: Lei Zhang [mailto:zhang.lei@gmail.com] Sent: Wednesday, March 11, 2015 7:33 PM To:

[openstack-dev] How does the role stuff work in real production deployment?

2014-03-20 Thread Ali, Haneef
Hi How does the keystone role stuff work in real production deployment? Every service team considers the user who has role with the name admin as admin. So basically I can't have a separate admin user for keystone, nova, swift. Isn't this a security issue? Given a project how to

Re: [openstack-dev] FW: [Keystone][Folsom] Token re-use

2013-06-20 Thread Ali, Haneef
, 2013 at 1:42 AM, Ali, Haneef haneef@hp.commailto:haneef@hp.com wrote: 1) Token Caching is not always going to help. It depends on the application.E.g A user writes a cron job to check the health of swift by listing a predefined container every 1 minute