From rocky keystone is bootstrapped with a 'member' ; CephRgw used to allow 'Member' instead

Bug #1847539 reported by Giulio Fidente on 2019-10-09
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
High
Giulio Fidente

Bug Description

With the implementation of the keystone blueprint basic-default-roles [1] in rocky, a role called 'member' is created in keystone by default.

Before rocky instead, the role was created after keystone started and used to be named 'Member'.

CephRgw is whitelisting the roles which allowed to create content and it used to only permits access to admin and Member

1. https://blueprints.launchpad.net/keystone/+spec/basic-default-roles

Fix proposed to branch: master
Review: https://review.opendev.org/687680

Changed in tripleo:
assignee: nobody → Giulio Fidente (gfidente)
status: Confirmed → In Progress
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers