'[DEFAULT] admin_token' is deprecated
Bug #1837113 reported by
Peter Matulis
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Keystone Charm |
Fix Released
|
Medium
|
Unassigned |
Bug Description
This deprecation warning was found in keystone.log:
(keystone.
(keystone.
See bug 1578678
Setup:
Bionic
OpenStack Queens
Juju 2.6.5
LXD containers [1]
LXD host:
Linux node-pytheas 4.15.0-54-generic #58-Ubuntu SMP Mon Jun 24 10:55:24 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
summary: |
- '[DEFAULT] admin_token' configurationoption presents a significant - security risk + '[DEFAULT] admin_token' is deprecated |
Changed in charm-keystone: | |
status: | New → Triaged |
importance: | Undecided → Medium |
Changed in charm-keystone: | |
milestone: | none → 20.05 |
Changed in charm-keystone: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.
Reviewed: https:/ /review. opendev. org/712040 /git.openstack. org/cgit/ openstack/ charm-keystone/ commit/ ?id=0a02c30fe5f 4650235519897b7 1588ae22fa0971
Committed: https:/
Submitter: Zuul
Branch: master
commit 0a02c30fe5f4650 235519897b71588 ae22fa0971
Author: Frode Nordahl <email address hidden>
Date: Mon Mar 9 15:06:09 2020 +0100
Replace use of admin_token with Keystone bootstrap
Stop the use of the admin_token and use the bootstrap process
to initialize Keystone instead. Fortunately the implementation
of the bootstrap process is both idempotent when it needs to be
and it can be safely called on an existing deployment.
Subsequently we can migrate by just removing the admin_token
from the configuration and create new credentials for use by
the charm with a call to ``keystone-manage bootstrap``.
Remove configuration templates for versions prior to Mitaka, by mitaka` ` folder.
doing this we need to move any configuration initially defined
prior to Miataka forward to the ``templates/
A side effect of this migration is that newly bootstrapped
deployments will get their ``default`` domain created with a
literal ID of ``default``. Prior to this change third party
software making assumptions about that being the case may have
had issues.
Closes-Bug: #1859844 /github. com/openstack- charmers/ zaza-openstack- tests/pull/ 191 ee34149f035c3bd f9ff54812c9
Closes-Bug: #1837113
Related-Bug: #1774733
Closes-Bug: #1648719
Closes-Bug: #1578678
Func-Test-Pr: https:/
Change-Id: I23940720c24527