Friday, 2026-06-26

opendevreviewLajos Katona proposed openstack/keystone master: LDAP: add new cfg option for pw expiry format  https://review.opendev.org/c/openstack/keystone/+/97661811:35
croelandtHello! Glance PTL here. I'm currently trying to review https://review.opendev.org/c/openstack/glance/+/967371 . The proposed patch seems wrong to me (see my comments: wrong type for the options, wrong... name for the options), and I'm not sure about the overall approach. Is glance supposed to manually call register_opt() for Keystone options? I'd appreciate help in understanding how we're 13:20
croelandtsupposed to use Keystone here13:20
gtemahey croelandt. I would need to have a look after I finish my current task. Just wanted to point out that we had a significant change in the trust behavior due to security issue and it is not possible to manage trusts with application credentials (and other way around). You definitely need to be aware of it13:23
croelandtIs there a document/release note that summarizes the changes I could read?13:31
gtemacroelandt https://review.opendev.org/c/openstack/keystone/+/99050213:32
gtemaah, this is one change without rn, lemme find the ossa for it13:32
gtemahttps://security.openstack.org/ossa/OSSA-2026-015.html13:33
gtemadamn, this is also way too short13:34
gtemahttps://review.opendev.org/c/openstack/keystone/+/990500 is better13:35
croelandtgtema: so all projects using "trust" have changes to push right now?14:02
gtemacroeland - not that all services need to make changes, but they need to be aware that trusts are a broken concept and should be avoided15:27
croelandtgtema: ok thanks I'll discuss that with the Glance team17:47
croelandtgtema: so moving forward, are you deprecating trusts? Thinking about removing them in a future release?17:47
gtemanot now, it is just that they were from scratch considered a dirty workaround (as initial specs say) and we needed to cut functionality due to the architectural security vulnerabilities. People should just stop using them really. We still need a proper solution for that which does not seem to be possible without a big reimplementation that I am working on17:49
croelandtAny chance this becomes a PTG discussion in October? :)17:50
gtemathe reimpl is a PTG and wide discussion since few years already (remember this mailinglist discussion with keywords keystone and rust). I am not sure we are able to implement a good replacement for trusts in keystone v317:51
croelandtI see18:02
croelandtI'll try to keep an eye on it18:02
croelandtand ideally wwe'll just remove that in Glance18:02
croelandtbut I have to catch up on the whole concept of trusts and why we needed them in the first place :D18:03
gtemacorrect - this is the main18:06
opendevreviewOria Weng proposed openstack/keystone master: Remove `enabled` as a filter for endpoint groups  https://review.opendev.org/c/openstack/keystone/+/99483418:45
opendevreviewMerged openstack/oslo.limit master: Honor -1 as unlimited in enforce_limits  https://review.opendev.org/c/openstack/oslo.limit/+/99478718:46
opendevreviewOria Weng proposed openstack/keystone master: Pre-commit: Use bandit through ruff  https://review.opendev.org/c/openstack/keystone/+/99483319:00
opendevreviewOria Weng proposed openstack/keystone master: Pre-commit: Use bandit through ruff  https://review.opendev.org/c/openstack/keystone/+/99483321:55
opendevreviewOria Weng proposed openstack/keystone master: Pre-commit: Add toml dependency for bandit  https://review.opendev.org/c/openstack/keystone/+/99483322:03

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!