Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-12 Thread Dolph Mathews
(not for usage questions) openstack-dev@lists.openstack.org Date: Friday, June 5, 2015 at 12:49 PM To: OpenStack Development Mailing List (not for usage questions) openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-10 Thread John Wood
@lists.openstack.org Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation The one proviso is that in single LDAP situations, the cloud provider can chose (for backward compatibility reasons) to allow the underlying LDAP user/group ID….so we might want to advise

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-10 Thread Dolph Mathews
at 12:49 PM To: OpenStack Development Mailing List (not for usage questions) openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation The one proviso is that in single LDAP situations, the cloud provider can

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-05 Thread Dolph Mathews
@lists.openstack.org Date: Thursday, June 4, 2015 at 6:01 PM To: OpenStack Development Mailing List (not for usage questions) openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation In Juno I tried adding a user

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-05 Thread Henry Nash
, Henry Nash hen...@linux.vnet.ibm.com mailto:hen...@linux.vnet.ibm.com, Henry Nash/UK/IBM@IBMGB Date: 05/06/2015 15:38 Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation On Thu, Jun 4, 2015 at 10:17 PM, John Wood john.w

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-05 Thread Dolph Mathews
@lists.openstack.org* openstack-dev@lists.openstack.org * Subject: *Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation In Juno I tried adding a user in Domain A to group in Domain B. That currently is not supported. Would be very handy though. We're getting a ways

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-05 Thread Henry Nash
(not for usage questions) openstack-dev@lists.openstack.org mailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation In Juno I tried adding a user in Domain A to group in Domain B. That currently is not supported

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-05 Thread Fox, Kevin M
Sent: Friday, June 05, 2015 7:37:54 AM To: OpenStack Development Mailing List (not for usage questions); Henry Nash; Henry Nash Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation On Thu, Jun 4, 2015 at 10:17 PM, John Wood john.w

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread John Wood
@lists.openstack.orgmailto:openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation In Juno I tried adding a user in Domain A to group in Domain B. That currently is not supported. Would be very handy though. We're getting

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Dolph Mathews
) * Subject:* Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation In general I am of the opinion with the move to Fernet there is no good reason we should avoid adding the group information into the token. --Morgan Sent via mobile On Jun 3, 2015

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Fox, Kevin M
From: Dolph Mathews [dolph.math...@gmail.com] Sent: Thursday, June 04, 2015 1:41 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation Problem! In writing a spec for this ( https

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Lance Bragstad
List (not for usage questions) openstack-dev@lists.openstack.org Date:06/03/2015 11:14 PM Subject:Re: [openstack-dev] [keystone][barbican] Regarding exposingX-Group- in token validation -- Will dozens to a hundred groups or so

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Morgan Fainberg
Mailing List (not for usage questions) openstack-dev@lists.openstack.org Date:06/03/2015 11:14 PM Subject:Re: [openstack-dev] [keystone][barbican] Regarding exposingX-Group- in token validation Will dozens to a hundred groups or so on one user cause

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Fox, Kevin M
questions) Subject: Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation Dozens to hundreds of roles or endpoints could cause an issue now :) But yeah, groups are much more likely to number in the dozens than roles or endpoints. But I think the Fernet token size

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Dolph Mathews
Development Mailing List (not for usage questions) * Subject:* Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group- in token validation In general I am of the opinion with the move to Fernet there is no good reason we should avoid adding the group information into the token

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-04 Thread Darren J Moffat
On 06/04/15 14:03, Fox, Kevin M wrote: Some kind of intermediate mapping might be better. With ldap, I dont have control over the groups users are assigned since thats an enterprise/AD thing. There can be a lot of them. Groups to Role relations I guess do that mapping. Though maybe passing

[openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-03 Thread John Wood
Hello folks, There has been discussion about adding user group support to the per-secret access control list (ACL) feature in Barbican. Hence secrets could be marked as accessible by a group on the ACL rather than an individual user as implemented now. Our understanding is that Keystone does

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-03 Thread Fox, Kevin M
] Regarding exposing X-Group- in token validation In general I am of the opinion with the move to Fernet there is no good reason we should avoid adding the group information into the token. --Morgan Sent via mobile On Jun 3, 2015, at 18:44, Dolph Mathews dolph.math

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-03 Thread Dolph Mathews
On Wed, Jun 3, 2015 at 5:58 PM, John Wood john.w...@rackspace.com wrote: Hello folks, There has been discussion about adding user group support to the per-secret access control list (ACL) feature in Barbican. Hence secrets could be marked as accessible by a group on the ACL rather than an

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-03 Thread Lance Bragstad
questions) openstack-dev@lists.openstack.org Date:06/03/2015 11:14 PM Subject:Re: [openstack-dev] [keystone][barbican] Regarding exposingX-Group- in token validation -- Will dozens to a hundred groups or so on one user cause issues

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-03 Thread Morgan Fainberg
In general I am of the opinion with the move to Fernet there is no good reason we should avoid adding the group information into the token. --Morgan Sent via mobile On Jun 3, 2015, at 18:44, Dolph Mathews dolph.math...@gmail.com wrote: On Wed, Jun 3, 2015 at 5:58 PM, John Wood

Re: [openstack-dev] [keystone][barbican] Regarding exposing X-Group-xxxx in token validation

2015-06-03 Thread Steve Martinelli
X-Group- in token validation Will dozens to a hundred groups or so on one user cause issues? :) Thanks, Kevin From: Morgan Fainberg Sent: Wednesday, June 03, 2015 7:23:22 PM To: OpenStack Development Mailing List (not for usage questions) Subject: Re: [openstack-dev] [keystone