[Openstack-docs] installation guide question
Gauvain Pocentek
gauvain.pocentek at objectif-libre.com
Sat Jun 21 19:17:46 UTC 2014
Hi,
Le 2014-06-21 19:51, Frans Thamura a écrit :
> in glance , i try glance .ini, get HTTP 500 when do glance image list,
> but in nova, i use nova api ini, run well.
>
> i feel this is inconsistent
This has been inconsistent across the projects, true. But since the
icehouse release there is no need to touch the *-paste.ini files, all
the authtoken settings are done in the main configuration file of each
project.
Note that this is not something that the doc team could handle anyway.
Projects developers choose where the configuration options should be, we
just document this.
Regards,
Gauvain
>
> F
> --
> Frans Thamura (曽志胜)
> Shadow Master and Lead Investor
> Meruvian.
> Integrated Hypermedia Java Solution Provider.
>
> Mobile: +628557888699
> Blog: http://blogs.mervpolis.com/roller/flatburger (id)
>
> FB: http://www.facebook.com/meruvian
> TW: http://www.twitter.com/meruvian / @meruvian
> Website: http://www.meruvian.org
>
> "We grow because we share the same belief."
>
>
> On Sat, Jun 21, 2014 at 10:41 PM, Anne Gentle <anne at openstack.org>
> wrote:
>>
>>
>>
>> On Sat, Jun 21, 2014 at 5:25 AM, Frans Thamura <frans at meruvian.org>
>> wrote:
>>>
>>> hi all
>>>
>>> i find there is glance-api-paste.ini
>>>
>>> and i google that if we put under [filter:authtoken]
>>>
>>> sql_connection = mysql://glanceuser:glance-pass@db-host/glance
>>>
>>> [keystone_authtoken]
>>> auth_host = <auth-host>
>>> auth_port = 35357
>>> auth_protocol = http
>>> admin_tenant_name = <service tenant name>
>>> admin_user = <glance user>
>>> admin_password = <admin password>
>>>
>>> [paste_deploy]
>>> flavor=keystone
>>>
>>>
>>> we dont have to modify the 4 .confs, in installation chapter 4 sub
>>> 8.
>>>
>>> Configure the Image Service to use the Identity Service for
>>> authentication.
>>>
>>> Edit the /etc/glance/glance-api.conf and
>>> /etc/glance/glance-registry.conf
>>>
>>>
>>> why dont we use the glance-api-paste.ini instead
>>>
>>> so let the keystone token as defaulat as
>>>
>>> admin_tenant_name = %SERVICE_TENANT_NAME%
>>> admin_user = %SERVICE_USER%
>>> admin_password = %SERVICE_PASSWORD%
>>>
>>>
>>
>> I think it was changed by default a security measure -- any
>> middleware
>> passing of passwords is an additional exposure it's better not to
>> take.
>>
>> http://docs.openstack.org/security-guide/content/ch021_paste-and-middleware.html
>>
>>>
>>>
>>> anyone can explain?
>>>
>>>
>>> F
>>>
>>> _______________________________________________
>>> Openstack-docs mailing list
>>> Openstack-docs at lists.openstack.org
>>> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-docs
>>
>>
>
> _______________________________________________
> Openstack-docs mailing list
> Openstack-docs at lists.openstack.org
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-docs
More information about the Openstack-docs
mailing list