add keystone service id to observer audit

Bug #1428946 reported by Steve Martinelli
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
Low
Ryosuke Mizuno

Bug Description

When a CADF notification is sent off, the 'observer' portion looks like the following:

"observer": {
            "typeURI": "service/security",
            "id": "openstack:3d4a50a9-2b59-438b-bf19-c231f9c7625a"
        },

The ID field should be the ID of the keystone/identity service.

Revision history for this message
Morgan Fainberg (mdrnstm) wrote :

Spoke with Steve, this requires making keystone aware of it's own Endpoint. This is something we want, but not trivial w/o requiring onerous configuration.

Changed in keystone:
status: New → Triaged
importance: Undecided → Low
Changed in keystone:
assignee: nobody → takehiro-kaneko (takehiro-kaneko)
Changed in keystone:
assignee: takehiro-kaneko (takehiro-kaneko) → nobody
tags: added: notifications
Changed in keystone:
assignee: nobody → Ron De Rose (ronald-de-rose)
Changed in keystone:
assignee: Ron De Rose (ronald-de-rose) → nobody
Changed in keystone:
assignee: nobody → Ryosuke Mizuno (r-mizuno)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/303963

Changed in keystone:
status: Triaged → In Progress
Changed in keystone:
assignee: Ryosuke Mizuno (r-mizuno) → Morgan Fainberg (mdrnstm)
Changed in keystone:
assignee: Morgan Fainberg (mdrnstm) → Ryosuke Mizuno (r-mizuno)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/303963
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=3ff7f133472a015ec28f806d353f7d5d6570476f
Submitter: Jenkins
Branch: master

commit 3ff7f133472a015ec28f806d353f7d5d6570476f
Author: Ryosuke Mizuno <email address hidden>
Date: Mon Apr 11 17:07:29 2016 +0900

    Add keystone service ID to observer audit

    Information of the observer in the CADF notification was only two of
    the "typeURI" and "id".
    So, add the ID of the identity service as a "identity_id".

    Change-Id: I579ad3051f784a6411f6f7af636c2c91d75c7425
    Closes-Bug: #1428946

Changed in keystone:
status: In Progress → Fix Released
Revision history for this message
Doug Hellmann (doug-hellmann) wrote : Fix included in openstack/keystone 10.0.0.0b1

This issue was fixed in the openstack/keystone 10.0.0.0b1 development milestone.

Changed in keystone:
milestone: none → newton-1
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.