Project

General

Profile

Actions

Feature #9493

closed

Ability to disable keystone revocation polling when using UUID keystone provider

Added by Kyle Bader over 9 years ago. Updated almost 7 years ago.

Status:
Resolved
Priority:
High
Assignee:
Target version:
-
% Done:

0%

Source:
other
Tags:
Backport:
jewel, kraken
Reviewed:
Affected Versions:
Pull request ID:

Description

When using a UUID keystone provider revocation is handled by deleting the token from the persistence backend (ie. no revocation lists). If rgw is using keystone authentication rgw_keystone_revocation_interval can be set to an arbitrary period, but it does not seem to have a means of disabling revocation entirely. Ideally there should be another tunable, or rgw_keystone_revocation_interval should allow being set to 0 or -1 to disable revocation polling.

https://bugzilla.redhat.com/show_bug.cgi?id=1142424


Related issues 3 (1 open2 closed)

Related to rgw - Feature #19499: rgw: implement support for OS-REVOKE extension of OpenStack Identity API v3New04/05/2017

Actions
Copied to rgw - Backport #19777: kraken: rgw: implement support for OS-REVOKE extension of OpenStack Identity API v3ResolvedNathan CutlerActions
Copied to rgw - Backport #19772: jewel: rgw: swift: disable revocation thread under certain circumstancesResolvedMarcus WattsActions
Actions #1

Updated by Yehuda Sadeh over 9 years ago

  • Tracker changed from Bug to Feature
Actions #2

Updated by Marcus Watts about 7 years ago

I've created a pull request that addresses this: https://github.com/ceph/ceph/pull/14501

Actions #3

Updated by Marcus Watts almost 7 years ago

  • Status changed from New to Pending Backport
  • Assignee changed from Yehuda Sadeh to Marcus Watts
  • Target version set to v10.2.8
Actions #4

Updated by Marcus Watts almost 7 years ago

Jewel backport is in this PR
https://github.com/ceph/ceph/pull/14789

Actions #5

Updated by Nathan Cutler almost 7 years ago

  • Related to Feature #19499: rgw: implement support for OS-REVOKE extension of OpenStack Identity API v3 added
Actions #6

Updated by Nathan Cutler almost 7 years ago

  • Status changed from Pending Backport to Resolved

The PR is already being backported at #19499 - we don't need to flag it twice.

Actions #7

Updated by Nathan Cutler almost 7 years ago

  • Copied to Backport #19777: kraken: rgw: implement support for OS-REVOKE extension of OpenStack Identity API v3 added
Actions #8

Updated by Nathan Cutler almost 7 years ago

  • Copied to Backport #19772: jewel: rgw: swift: disable revocation thread under certain circumstances added
Actions #9

Updated by Nathan Cutler almost 7 years ago

  • Status changed from Resolved to Pending Backport
  • Target version deleted (v10.2.8)
Actions #10

Updated by Nathan Cutler almost 7 years ago

  • Backport set to jewel, kraken
Actions #11

Updated by Nathan Cutler almost 7 years ago

  • Status changed from Pending Backport to Resolved
Actions

Also available in: Atom PDF