← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1534834] Re: Policy check forces impersonation for redelgation of trust

 

marking this as invalid. based on the latest keystone meeting it was
decided that the behaviour is correct

** Changed in: keystone
       Status: In Progress => Invalid

** Changed in: keystone
    Milestone: mitaka-3 => None

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Identity (keystone).
https://bugs.launchpad.net/bugs/1534834

Title:
  Policy check forces impersonation for redelgation of trust

Status in OpenStack Identity (keystone):
  Invalid

Bug description:
  When redelegating a trust, the API specifies that the trustor_id is
  the original trustor_id.  However, the policy check for create_trust
  enforces that user_id = trust.trustor_user_id. Effectily limiting the
  redelgation ofr trusts to trusts which  provide impersonation.

To manage notifications about this bug go to:
https://bugs.launchpad.net/keystone/+bug/1534834/+subscriptions


References