yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #53511
[Bug 1593542] Re: Keystone-manage bootstrap can't bootstrap domains other than default
I think this should be marked as WONTFIX. This feature is currently
designed to be used when first installing keystone and not for creating
new domains.
** Changed in: keystone
Status: New => Opinion
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Identity (keystone).
https://bugs.launchpad.net/bugs/1593542
Title:
Keystone-manage bootstrap can't bootstrap domains other than default
Status in OpenStack Identity (keystone):
Opinion
Bug description:
When using keystone-manage bootstrap, you can't define the domain that
you want to bootstrap. It will always work with default. The problem
is this doesn't help with a multi-domain environment. An admin user
defined in the default domain doesn't have any permissions in other
domains. Once a new domain is created a different admin user specific
to that domain would need to be created in order to be able to act
within it.
If the keystone-manage bootstrap utility could allow bootstrapping of
non-default domains then it could facilitate the administration of
larger, multi-domain cloud environments without the security concern
that arises from the older admin_token method.
To manage notifications about this bug go to:
https://bugs.launchpad.net/keystone/+bug/1593542/+subscriptions
References