Cannot list group members with policy.v3cloudsample.json
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
New
|
Undecided
|
Unassigned |
Bug Description
Version: Mitaka
I updated my /etc/keystone/
However, when I wanted to list members in a group as a domain admin, an error occurred: "You are not authorized to perform the requested action: identity:
The reproduce steps are:
As cloud admin:
- openstack domain create taiwan # Assume the id of "taiwan" is "18eaa46db5324a
- TAIWAN_
- openstack user create --domain $TAIWAN_DOMAIN_ID --password 5ecret taiwan-president
- openstack role add --user taiwan-president --domain $TAIWAN_DOMAIN_ID admin
As taiwan-president:
- openstack group create --domain $TAIWAN_DOMAIN_ID indigenous
- openstack user create --domain $TAIWAN_DOMAIN_ID margaret
- openstack group add user --group-domain $TAIWAN_DOMAIN_ID --user-domain $TAIWAN_DOMAIN_ID indigenous margaret
- openstack user list --group indigenous --domain $TAIWAN_DOMAIN_ID
The last command will generate the 403 error.
The rule for "identity:
I can reproduce this issue in devstack.
[1] https:/
description: | updated |
description: | updated |
description: | updated |