ABCDEFGHIJKLMNOPQRSTUVWXY
1
Ocata priorities for Keystone, leave a comment to sign up for something
2
New Features that are approvedStatusBug or Spec referencePatch / Topic / Gerrit linkOwnerComments
3
PCI-DSS Query Password Expired UsersCompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/pci-dss-expired-password.htmlhttps://review.openstack.org/#/q/topic:bp/pci-dss-query-password-expired-usersspilla
4
Shadow mappingCompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/shadow-mapping.htmlhttps://review.openstack.org/#/q/topic:bp/shadow-mappinglbragstadgroups, projects, roles should all be auto-provisioned, make mappings managed by domain admins, should mapping change invalidate the assignments, what about expiring assignments (based on token)
5
PCI-DSS NotificationsCompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/pci-dss-notification.htmlhttps://review.openstack.org/#/q/topic:bp/pci-dss-notificationsgagehugo
6
Allow retrieving an expired tokenCompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/allow-expired.htmlhttps://review.openstack.org/#/q/topic:bp/allow-expiredjamielennox
7
PCI-DSS Password Requirements APICompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/pci-dss-password-requirements-api.htmlhttps://review.openstack.org/#/q/topic:bp/pci-dss-password-requirements-apilbragstad
8
Drop Support for Driver VersioningCompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/drop-driver-version.htmlhttps://review.openstack.org/#/q/topic:bp/removed-as-of-ocatarderose
9
Per-User Auth Plugin RequirementsCompletehttp://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/per-user-auth-plugin-requirements.htmlhttps://review.openstack.org/#/q/topic:bp/per-user-auth-plugin-reqsmorganOld spec: http://specs.openstack.org/openstack/keystone-specs/specs/keystone/ocata/password-totp-plugin.html
10
11
Bugs that should be addressed in OcataStatusBug or Spec referencePatch / Topic / Gerrit linkOwnerComments
12
Federation: Missing domains for federated usersCompletehttps://bugs.launchpad.net/keystone/+bug/1642687https://review.openstack.org/#/q/topic:bug/1642687rderose
13
PCI: user must change password upon first useCompletehttps://bugs.launchpad.net/keystone/+bug/1645487https://review.openstack.org/#/c/403916/rderose
14
KSA/KSC: Hash the Service TokenCompletehttps://bugs.launchpad.net/python-keystoneclient/+bug/1654847https://review.openstack.org/#/q/topic:bug/1654847lamt
15
KSC/KSA: exceptions raise when uploading large objectsCompletehttps://bugs.launchpad.net/python-keystoneclient/+bug/1616105https://review.openstack.org/#/q/topic:bug/1616105samuelwill need fixes in ksa and ksc
16
KSC: implied roles bugsCompletehttps://bugs.launchpad.net/python-keystoneclient/+bug/1647934https://review.openstack.org/#/c/412236/stevemar
17
Federation: Include `mapped` by defaultCompletehttps://bugs.launchpad.net/keystone/+bug/1645391https://review.openstack.org/#/c/403816/rodrigods
18
Federation: mapping engine tester issuesCompletehttps://bugs.launchpad.net/keystone/+bug/1655182https://review.openstack.org/#/c/418165/jdennis
19
Federation: cannot delete protocol if user has auth'edCompletehttps://bugs.launchpad.net/keystone/+bug/1642692https://review.openstack.org/#/c/415906/9rodrigods
20
Fernet: rotate doesn't work when disk is fullCompletehttps://bugs.launchpad.net/keystone/+bug/1642457https://review.openstack.org/#/c/413495/johnlinp
21
Roles: Include domain role when listing role assignmentsCompletehttps://bugs.launchpad.net/keystone/+bug/1607114https://review.openstack.org/#/c/373516/spilla
22
Roles: Assignment not showing inheritance when using --namesCompletehttps://bugs.launchpad.net/keystone/+bug/1625230https://review.openstack.org/#/c/380973/kanika
23
keystone-doctor: Add testsCompletehttps://bugs.launchpad.net/keystone/+bug/1641621https://review.openstack.org/#/q/topic:bug/1641621ravelar
24
keystone-doctor: add developer docsCompletehttps://bugs.launchpad.net/keystone/+bug/1641623https://review.openstack.org/#/c/399163/lbragstad
25
Notifications: switch to cadf by defaultCompletehttps://bugs.launchpad.net/keystone/+bug/1641660https://review.openstack.org/397339lamt
26
Performance: Fix a slight regression when caching was fixedCompletehttps://bugs.launchpad.net/keystone/+bug/1641652https://review.openstack.org/#/c/380376/breton
27
Performance: Enable ``cache_on_issue`` by defaultCompletehttps://bugs.launchpad.net/keystone/+bug/1641816https://review.openstack.org/#/c/383333/mfisch
28
Policy: Update revoke API to be admin requiredCompletehttps://bugs.launchpad.net/keystone/+bug/1649446https://review.openstack.org/#/c/416841/stevemarlow hanging fruit
29
Upgrade: Make bootstrap idempotentCompletehttps://bugs.launchpad.net/keystone/+bug/1647800https://review.openstack.org/#/q/topic:bug/1647800lbragstad
30
Upgrade: add note about triggers needed SUPER privCompletehttps://bugs.launchpad.net/keystone/+bug/1638368https://review.openstack.org/#/c/394603/ravelar
31
LDAP: mapping_populate unhandled exceptionCompletehttps://bugs.launchpad.net/keystone/+bug/1645571https://review.openstack.org/#/c/404197/breton
32
LDAP: Nested groups for ADCompletehttps://bugs.launchpad.net/keystone/+bug/1638603https://review.openstack.org/389316ayoung
33
LDAP: add new timeout config optionCompletehttps://bugs.launchpad.net/keystone/+bug/1636950https://review.openstack.org/390948knasim
34
PCI: When the user is locked they can’t change their passwordCompletehttps://bugs.launchpad.net/keystone/+bug/1641645https://review.openstack.org/#/c/404022/gagehugo
35
PCI: malicious user can DoS a cloudCompletehttps://bugs.launchpad.net/keystone/+bug/1642348https://review.openstack.org/#/c/398571/rderoseoverlaps with https://bugs.launchpad.net/keystone/+bug/1641642
36
Include healthcheck middlewareCompletehttps://bugs.launchpad.net/keystone/+bug/1641654https://review.openstack.org/#/c/387731/jlk
37
Verbose 401/403 debug responsesCompletehttps://bugs.launchpad.net/keystone/+bug/1625120https://review.openstack.org/#/c/372433/amakarov
38
Remove deprecated config optionCompletehttps://bugs.launchpad.net/keystone/+bug/1653472https://review.openstack.org/#/c/416267/lbragstad
39
SQL: add retry on deadlock for delete userCompletehttps://bugs.launchpad.net/keystone/+bug/1648542https://review.openstack.org/#/c/416872/shanguolow hanging fruit
40
Tests: No need to use pep8 internalsCompletehttps://bugs.launchpad.net/keystone/+bug/1652458https://review.openstack.org/#/q/topic:bug/1652458stevemar
41
Force use of AuthContext object in .authentcate()Completehttps://bugs.launchpad.net/keystone/+bug/1656076https://review.openstack.org/#/c/419693/morgan
42
V2: Endpoint with missing "region" causes 500 errorCompletehttps://bugs.launchpad.net/keystone/+bug/1557166https://review.openstack.org/#/c/304489/breton
43
44
DocsStatusBug or Spec referencePatch / Topic / Gerrit linkOwnerComments
45
Config Reference: Add PCI optionsCompletehttps://bugs.launchpad.net/keystone/+bug/1641823https://review.openstack.org/#/c/405711/shanguodupe of https://bugs.launchpad.net/keystone/+bug/1640504
46
Admin Guide: Cleanup LDAPCompletehttps://bugs.launchpad.net/keystone/+bug/1641821https://review.openstack.org/#/q/topic:bug/1641821ravelarhttp://docs.openstack.org/admin-guide/identity-management.html
47
Admin Guide: Cleanup cachingCompletehttps://bugs.launchpad.net/keystone/+bug/1641818https://review.openstack.org/382655browne
48
Admin Guide: Add PCICompletehttps://bugs.launchpad.net/keystone/+bug/1641822https://review.openstack.org/#/c/399337/stevemar
49
Dev Docs: clean them all upComplete--https://review.openstack.org/#/q/topic:keystone_doc_cleanupstevemarhttp://docs.openstack.org/developer/keystone/configuration.html
50
API: Add changelog from 3.0->3.7Completehttps://bugs.launchpad.net/keystone/+bug/1637214https://review.openstack.org/#/c/399301/stevemarhttp://developer.openstack.org/api-ref/identity/v3/index.html
51
52
Horizon & Keystone workStatusBug or Spec referencePatch / Topic / Gerrit linkOwnerComments
53
K2K supportCompletehttps://blueprints.launchpad.net/horizon/+spec/k2k-federationhttps://review.openstack.org/#/q/topic:bp/k2k-horizonetubillara
54
Make users panel a search first panel, so LDAP worksComplete--https://review.openstack.org/#/c/419133/3dcastellanos
55
v3 policy is not parseable using oslo.policyCompletehttps://bugs.launchpad.net/oslo.policy/+bug/1547684https://review.openstack.org/#/q/topic:bug/1547684stevemar
56
bring in kerberos code to django_openstack_authCompletehttps://bugs.launchpad.net/django-openstack-auth/+bug/1584432https://review.openstack.org/#/q/topic:bug/1584432stevemarRetiring the repo instead
57
Remove token revocation on logoutCompletehttps://bugs.launchpad.net/django-openstack-auth/+bug/1637460https://review.openstack.org/#/c/391183/_ducttape
58
Default domain usage consistentComplete--https://review.openstack.org/#/c/389679/crinkle
59
60
https://etherpad.openstack.org/p/ocata-keystone-horizon
61
62
Long goals
63
DevStack v3 by defaultCompletehttps://etherpad.openstack.org/p/v3-only-devstack<no single topic>dims
64
Refactor the token providerCompleteno bug, it's a refactorhttps://review.openstack.org/#/q/topic:cleanup-token-providerlbragstad
65
Make fernet the default token formatCompletehttps://bugs.launchpad.net/keystone/+bug/1561054https://review.openstack.org/#/q/topic:make-fernet-defaultlbragstad
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100