kerberos disable mutual authentication

Bug #1681448 reported by Jose Castro Leon
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
keystoneauth
Fix Released
Undecided
Jose Castro Leon

Bug Description

In keystoneauth library the kerberos plugin configures requests_kerberos to do mutual authentication in optional mode. On certain cases, all your backends behind a DNS load balanced alias, this configuration fails if the reply of the negotiate command comes from different nodes.

The suggestion is to allow an option to the plugin allowing to disable the mutual authentication in those cases while leaving as default the actual behavior

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystoneauth (master)

Fix proposed to branch: master
Review: https://review.openstack.org/455330

Changed in keystoneauth:
assignee: nobody → Jose Castro Leon (jose-castro-leon)
status: New → In Progress
Changed in keystoneauth:
assignee: Jose Castro Leon (jose-castro-leon) → Adam Young (ayoung)
Changed in keystoneauth:
assignee: Adam Young (ayoung) → Jose Castro Leon (jose-castro-leon)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystoneauth (master)

Reviewed: https://review.openstack.org/455330
Committed: https://git.openstack.org/cgit/openstack/keystoneauth/commit/?id=bb5cb9d41856663408be9f8d847c5b716441bb1b
Submitter: Jenkins
Branch: master

commit bb5cb9d41856663408be9f8d847c5b716441bb1b
Author: Jose Castro Leon <email address hidden>
Date: Mon Apr 10 15:52:49 2017 +0200

    Parameter to tune mutual authentication in kerberos

    Parameter is optional.

    Change-Id: Idfec093d5af677ba4899dc17aafa1ede17f0d4c0
    Closes-Bug: #1681448

Changed in keystoneauth:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystoneauth (stable/pike)

Fix proposed to branch: stable/pike
Review: https://review.openstack.org/492529

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/keystoneauth 3.2.0

This issue was fixed in the openstack/keystoneauth 3.2.0 release.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on keystoneauth (stable/pike)

Change abandoned by Jose Castro Leon (<email address hidden>) on branch: stable/pike
Review: https://review.openstack.org/492529
Reason: The parameter will be available on queens release, no need backport it

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.