default signing_dir config causes WARNINGs

Bug #1185098 reported by Dan Prince
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Cinder
Fix Released
Medium
Dan Prince

Bug Description

By default we set signing_dir to /var/lib/cinder. This can typically cause warnings like:

2013-05-28 10:39:53.829 5147 WARNING keystoneclient.middleware.auth_token [-] signing_dir mode is 0755 instead of 0700

...

Although I can work around this via package it seems like having authtoken create its own directory withing the /var/lib/cinder tree (like it does by default) is a better out of the box default for cinder.

Dan Prince (dan-prince)
Changed in cinder:
assignee: nobody → Dan Prince (dan-prince)
importance: Undecided → Medium
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to cinder (master)

Fix proposed to branch: master
Review: https://review.openstack.org/30756

Revision history for this message
Pádraig Brady (p-draigbrady) wrote :

Is it better to mark the equiv nova bug 1174608 as affecting cinder or create a new bug?

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to cinder (master)

Reviewed: https://review.openstack.org/30756
Committed: http://github.com/openstack/cinder/commit/896b69e33dd7e67e03767548a14b770266f5dec5
Submitter: Jenkins
Branch: master

commit 896b69e33dd7e67e03767548a14b770266f5dec5
Author: Dan Prince <email address hidden>
Date: Tue May 28 12:20:01 2013 -0400

    Don't set signing_dir by default.

    Allow the auth_token middleware to setup its own signing_dir
    if required.

    Fixes LP Bug #1185098.

    Change-Id: Id8766efb34d37ca382b865167ec2465d0a1ce8dc

Changed in cinder:
status: In Progress → Fix Committed
Thierry Carrez (ttx)
Changed in cinder:
milestone: none → havana-2
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in cinder:
milestone: havana-2 → 2013.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.