[Openstack-devel] Bug#689181: python-keystone: LDAP attributes modifications ignored

Alberto Molina Coballes alb.molina at gmail.com
Sat Sep 29 20:27:42 UTC 2012


Package: python-keystone
Version: 2012.1.1-6
Severity: normal

Dear Maintainer,

In a keystone configuration with a LDAP backend, it is possible to
change default attributes types for users, tenants or roles at 
/etc/keystone/keystone.conf, but at this moment it doesn't have any 
effect because default are used, e.g. changing user_name and user_id
to uid at /etc/keystone/keystone.conf:

user_name_attribute = uid
user_id_attribute = uid

With debug mode enabled, it is possible to see at keystone logs that
sn attribute (default one) is still used:

DEBUG [keystone.common.ldap.core] LDAP search: dn=ou=People,dc=\
example,com, scope=1, query=(&(sn=username)(objectClass=inetOrgPerson))

-- System Information:
Debian Release: wheezy/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-3-amd64 (SMP w/6 CPU cores)
Locale: LANG=es_ES.UTF-8, LC_CTYPE=es_ES.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages python-keystone depends on:
ii  python              2.7.3~rc2-1
ii  python-dateutil     1.5+dfsg-0.1
ii  python-eventlet     0.9.16-2
ii  python-greenlet     0.3.1-2
ii  python-httplib2     0.7.4-2
ii  python-lxml         2.3.2-1
ii  python-migrate      0.7.2-3
ii  python-nova         2012.1.1-10
ii  python-pam          0.4.2-13
ii  python-passlib      1.5.3-2
ii  python-paste        1.7.5.1-4.1
ii  python-pastedeploy  1.5.0-3
ii  python-pastescript  1.7.5-2
ii  python-routes       1.13-2
ii  python-sqlalchemy   0.7.8-1
ii  python-sqlite       1.0.1-9
ii  python-webob        1.1.1-1

Versions of packages python-keystone recommends:
ii  python-ldap      2.4.10-1
ii  python-memcache  1.48-1

python-keystone suggests no packages.

-- no debconf information



More information about the Openstack-devel mailing list