auth_token fails to fetch revocation list

Bug #1038309 reported by Adam Young
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
High
Adam Young

Bug Description

The revocation list is only accessible to admin requests. Currently, the auth_token middleware requests it as a end user. Thus, the request fails, and the user is not authenticated.

Adam Young (ayoung)
Changed in keystone:
assignee: nobody → Adam Young (ayoung)
Adam Young (ayoung)
description: updated
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/11599

Changed in keystone:
status: New → In Progress
Thierry Carrez (ttx)
Changed in keystone:
milestone: none → folsom-rc1
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/11599
Committed: http://github.com/openstack/keystone/commit/3fa4ba537e7d297aeb63554231d041da7ad2476f
Submitter: Jenkins
Branch: master

commit 3fa4ba537e7d297aeb63554231d041da7ad2476f
Author: Adam Young <email address hidden>
Date: Fri Aug 17 19:17:17 2012 -0400

    Fix auth_token middleware to fetch revocation list as admin.

    Make the revocation list into a JSON document and get the Vary header.
    This will also allow the revocation list to carry additional
    information in the future, to include sufficient information for the
    calling application to figure out how to get the certificates it
    requires.

    Bug 1038309

    Change-Id: I4a41cbd8a7352e5b5f951027d6f2063b169bce89

Changed in keystone:
status: In Progress → Fix Committed
Joseph Heck (heckj)
Changed in keystone:
importance: Undecided → High
Thierry Carrez (ttx)
Changed in keystone:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in keystone:
milestone: folsom-rc1 → 2012.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.