Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-8671

[fiware-stackoverflow] KeyRock failing to update policies on AuthzForce

    Details

      Description

      Created question in FIWARE Q/A platform on 07-05-2017 at 22:05
      Please, ANSWER this question AT http://stackoverflow.com/questions/43836571/authzforce-failed-update-policies

      Question:
      AuthzForce failed update policies

      Description:
      I'm assigning permission (only access to /resource1) to a role.
      However Keyrock said 'Failed to update policies in Access Control GE'.

      So, even I request the resource2 (not resource1) with an access token that has the permission that can access resource1 only, AuthzForce permit the access because policies are not updated (it might be other problem).

      The question is why authzforce cannot update policy?

      Now, I successfully linked permission to the role (except failing policy update), and I assigned the role to the user. Then I double checked configurations of Keyrock and AuthzForce. They are connected well I think.

      Error msg of Keyrock

      What makes I think AuthzForce working well (this is the Wilma's successful log when I send a access request to Wilma with the access token)

      Please refer above images and below configuretion of Keyrock.

      // 'local_settings.py' in Keyrock
      ACCESS_CONTROL_URL = 'http://127.0.0.1:8080'
      ACCESS_CONTROL_MAGIC_KEY = 'abcdefghijkmn'

        Activity

        Transition Time In Source Status Execution Times Last Executer Last Execution Date
        Open Open In Progress In Progress
        1d 10h 40m 1 Cyril Dangerville 09/May/17 10:45 AM
        In Progress In Progress Closed Closed
        2d 1h 19m 1 Backlog Manager 11/May/17 12:04 PM
        fla Fernando Lopez made changes -
        Fix Version/s 2021 [ 12600 ]
        Hide
        backlogmanager Backlog Manager added a comment -

        2017-05-11 12:05|UPDATED status: transition Finish| # answers= 1, accepted answer= True

        Show
        backlogmanager Backlog Manager added a comment - 2017-05-11 12:05|UPDATED status: transition Finish| # answers= 1, accepted answer= True
        backlogmanager Backlog Manager made changes -
        Resolution Done [ 10000 ]
        Status In Progress [ 3 ] Closed [ 6 ]
        cdangerville Cyril Dangerville made changes -
        Assignee Cyril Dangerville [ cyril.dangerville ] Alvaro Alonso [ aalonsog ]
        cdangerville Cyril Dangerville made changes -
        Summary [fiware-stackoverflow] AuthzForce failed update policies [fiware-stackoverflow] KeyRock failing to update policies on AuthzForce
        Hide
        cdangerville Cyril Dangerville added a comment -

        Asking for more info. A priori an issue with KeyRock-Authzforce incompatibility. May re-assign to KeyRock owner.

        Show
        cdangerville Cyril Dangerville added a comment - Asking for more info. A priori an issue with KeyRock-Authzforce incompatibility. May re-assign to KeyRock owner.
        cdangerville Cyril Dangerville made changes -
        Status Open [ 1 ] In Progress [ 3 ]
        fla Fernando Lopez made changes -
        HD-Enabler AuthZForce [ 10887 ]
        Description
        Created question in FIWARE Q/A platform on 07-05-2017 at 22:05
        {color: red}Please, ANSWER this question AT{color} http://stackoverflow.com/questions/43836571/authzforce-failed-update-policies


        +Question:+
        AuthzForce failed update policies

        +Description:+
        I'm assigning permission (only access to /resource1) to a role.
        However Keyrock said 'Failed to update policies in Access Control GE'.

        So, even I request the resource2 (not resource1) with an access token that has the permission that can access resource1 only, AuthzForce permit the access because policies are not updated (it might be other problem).

        The question is why authzforce cannot update policy?

        Now, I successfully linked permission to the role (except failing policy update), and I assigned the role to the user. Then I double checked configurations of Keyrock and AuthzForce. They are connected well I think.

        Error msg of Keyrock

        What makes I think AuthzForce working well (this is the Wilma's successful log when I send a access request to Wilma with the access token)

        Please refer above images and below configuretion of Keyrock.

        // 'local_settings.py' in Keyrock
        ACCESS_CONTROL_URL = 'http://127.0.0.1:8080'
        ACCESS_CONTROL_MAGIC_KEY = 'abcdefghijkmn'

        Created question in FIWARE Q/A platform on 07-05-2017 at 22:05
        {color: red}Please, ANSWER this question AT{color} http://stackoverflow.com/questions/43836571/authzforce-failed-update-policies


        +Question:+
        AuthzForce failed update policies

        +Description:+
        I'm assigning permission (only access to /resource1) to a role.
        However Keyrock said 'Failed to update policies in Access Control GE'.

        So, even I request the resource2 (not resource1) with an access token that has the permission that can access resource1 only, AuthzForce permit the access because policies are not updated (it might be other problem).

        The question is why authzforce cannot update policy?

        Now, I successfully linked permission to the role (except failing policy update), and I assigned the role to the user. Then I double checked configurations of Keyrock and AuthzForce. They are connected well I think.

        Error msg of Keyrock

        What makes I think AuthzForce working well (this is the Wilma's successful log when I send a access request to Wilma with the access token)

        Please refer above images and below configuretion of Keyrock.

        // 'local_settings.py' in Keyrock
        ACCESS_CONTROL_URL = 'http://127.0.0.1:8080'
        ACCESS_CONTROL_MAGIC_KEY = 'abcdefghijkmn'

        HD-Chapter Security [ 10841 ]
        fla Fernando Lopez made changes -
        Assignee Cyril Dangerville [ cyril.dangerville ]
        backlogmanager Backlog Manager made changes -
        Field Original Value New Value
        Component/s FIWARE-TECH-HELP [ 10278 ]
        Hide
        backlogmanager Backlog Manager added a comment -

        2017-05-08 00:05|CREATED monitor | # answers= 0, accepted answer= False

        Show
        backlogmanager Backlog Manager added a comment - 2017-05-08 00:05|CREATED monitor | # answers= 0, accepted answer= False
        backlogmanager Backlog Manager created issue -

          People

          • Assignee:
            aalonsog Alvaro Alonso
            Reporter:
            backlogmanager Backlog Manager
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: