Integrate Identity back end with LDAP in Administrator Guide

Bug #1628135 reported by Dave Walker
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Invalid
High
Unassigned
openstack-manuals
Fix Released
Medium
Eric Brown

Bug Description

The guide states that both "keystone.identity.backends.ldap.Identity" and "user_attribute_ignore" can be used, but as you can see below this is deprecated (and infact not working in current Newton)

==> keystone-apache-admin-error.log <==
2016-09-27 10:35:13.891436 2016-09-27 10:35:13.890 24 WARNING stevedore.named [req-01e2b673-51b3-4364-a131-ad0bb8c78e01 - - - - -] Could not load keystone.identity.backends.ldap.Identity

==> keystone.log <==
2016-09-27 10:35:13.914 24 WARNING oslo_config.cfg [req-01e2b673-51b3-4364-a131-ad0bb8c78e01 - - - - -] Option "user_attribute_ignore" from group "ldap" is deprecated for removal. Its value may be silently ignored in the future.

==> keystone-apache-admin-error.log <==
2016-09-27 10:35:13.914683 2016-09-27 10:35:13.914 24 WARNING oslo_config.cfg [req-01e2b673-51b3-4364-a131-ad0bb8c78e01 - - - - -] Option "user_attribute_ignore" from group "ldap" is deprecated for removal. Its value may be silently ignored in the future.

-----------------------------------
Release: 0.9 on 2016-09-27 12:00
SHA: 974a8b3e88ffdda8b621a6befc124d4f9ca9bdc7
Source: http://git.openstack.org/cgit/openstack/openstack-manuals/tree/doc/admin-guide/source/keystone-integrate-identity-backend-ldap.rst
URL: http://docs.openstack.org/admin-guide/keystone-integrate-identity-backend-ldap.html

Revision history for this message
Steve Martinelli (stevemar) wrote :

A lot of the keystone bits in the admin-guide are out of date, in particular, the LDAP bits.

[1] Instruction for LDAP assignment backend can be removed. keystone-integrate-assignment-backend-ldap.rst
[2] The write support for the LDAP identity backend will be removed in Ocata
[3] Instructions for PKI can be removed: keystone-certificates-for-pki.rst
[4] The drivers should be "ldap" or "sql"

https://github.com/openstack/openstack-manuals/tree/master/doc/admin-guide/source

I'll propose revising this in a sprint at the next keystone meeting.

Changed in keystone:
status: New → Triaged
importance: Undecided → High
milestone: none → ocata-1
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to openstack-manuals (master)

Fix proposed to branch: master
Review: https://review.openstack.org/382634

Changed in openstack-manuals:
assignee: nobody → Eric Brown (ericwb)
status: New → In Progress
tags: added: documentation ldap
Changed in openstack-manuals:
importance: Undecided → Medium
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to openstack-manuals (master)

Reviewed: https://review.openstack.org/382634
Committed: https://git.openstack.org/cgit/openstack/openstack-manuals/commit/?id=5674db0f24f83f98724c60ec3433baa35d3c05e8
Submitter: Jenkins
Branch: master

commit 5674db0f24f83f98724c60ec3433baa35d3c05e8
Author: Eric Brown <email address hidden>
Date: Wed Oct 5 12:29:51 2016 -0700

    Update identity section of admin guide

    A number of configuration options stated in the identity admin
    guides are deprecated or since removed. This updates to the latest
    config and fixes the referenced bug.

    The keystone-integrate-assignment-backend-ldap was also removed
    since this is no longer support by keystone.

    Change-Id: I854b2d1d9e1ad8ea88a6e30a15905e332663c7b3
    Closes-Bug: #1628135

Changed in openstack-manuals:
status: In Progress → Fix Released
Changed in keystone:
status: Triaged → Invalid
milestone: ocata-1 → none
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/openstack-manuals 15.0.0

This issue was fixed in the openstack/openstack-manuals 15.0.0 release.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.