[Yahoo-eng-team] [Bug 1177526] [NEW] 1.7.4 keystone middleware allows operator_roles to delete accounts

2013-05-14 Thread Launchpad Bug Tracker
*** This bug is a security vulnerability *** You have been subscribed to a public security bug: Hi, we are using swift 1.7.4 with keystone auth, and we think we might found a bug. Our proxy-server.conf for kesytone is as follow : [filter:keystoneauth] use = egg:swift#keystoneauth

[Yahoo-eng-team] [Bug 1179778] Re: Option group name 'DATABASE' should be lowercase

2013-05-14 Thread Zhongyue Luo
** Changed in: quantum Status: In Progress = Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to quantum. https://bugs.launchpad.net/bugs/1179778 Title: Option group name 'DATABASE' should be lowercase Status in

[Yahoo-eng-team] [Bug 1178800] Re: dhcp unit tests prompt for sudo password

2013-05-14 Thread Jeremy Stanley
The switch from quantal to precise slaves took place yesterday without incident, so this regression is no longer present. ** Changed in: openstack-ci Status: In Progress = Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is

[Yahoo-eng-team] [Bug 1177526] Re: 1.7.4 keystone middleware allows operator_roles to delete accounts

2013-05-14 Thread Thierry Carrez
Agreed with Chmouel in comment 9 (not a vulnerability), will open this bug publicly tomorrow if nobody complains ** Also affects: swift Importance: Undecided Status: New ** Changed in: swift Status: New = Incomplete ** Changed in: keystone Status: Incomplete = Invalid

[Yahoo-eng-team] [Bug 1179846] Re: Wrong keystone port in admin-openrc.sh

2013-05-14 Thread Gabriel Hurley
What are you trying to do with the CLI? Port 5000 is correct for authentication, etc. but for performing User/Tenant CRUD you need to use the admin port. This should be handled by the client. I suspect your Keystone service catalog may have the wrong port in the adminURL identity service, or it

[Yahoo-eng-team] [Bug 1177241] Re: Cannot assign multiple tenants to a user when creating a user

2013-05-14 Thread Gabriel Hurley
Keystone has an explicit concept of a default tenant/primary project which by its nature is only a relationship to one project. That's what you're setting at creation time. Once the user is created you can add them to as many projects as you like, but that's a completely different operation from

[Yahoo-eng-team] [Bug 996166] Re: installs wrong package in cc_salt_minion.py

2013-05-14 Thread Scott Moser
if you want to get this SRU'd to precise (12.04) we have to follow StableReleaseProcess guidelines https://wiki.ubuntu.com/StableReleaseUpdates We need a template added to this bug. ** Changed in: cloud-init (Ubuntu Precise) Status: Fix Released = Confirmed -- You received this bug

[Yahoo-eng-team] [Bug 1177241] Re: Cannot assign multiple tenants to a user when creating a user

2013-05-14 Thread Dolph Mathews
Similar answer from the keystone side - we're getting further away from the default project thing. In v3, we're viewing a user's default project as simply a user-defined preference: the project which the user should authorize against if the user didn't request a specific project. User-Project

[Yahoo-eng-team] [Bug 1152876] Re: Can not remove router interface that without fixed ip

2013-05-14 Thread Alex Xu
@Roman, I can delete subnet directly in this commit '921f203f4906a3b566f5a58471a55a4eedfc939c', then the port will be without ip. But now I can't delete subnet with master. It will message as below: 'Unable to complete operation on subnet 64a14036-67e0-477a-b666-7740bf2a31e9. One or more ports