#2767 security realm rights in .fedoraproject.org should be cross=-site
Closed: Invalid 6 years ago Opened 6 years ago by herrold.

https://src.fedoraproject.org/

required that I re-authenticate, and seems to have a 'too narrow' trust domain

I was already logged into

https://pagure.io/packaging-committee/issue/726

and in process filing an update.

instead after re-authentication, I saw:
14:33 =orc_fedo> Trust Root
14:33 =orc_fedo> https://src.fedoraproject.org/

14:33 =orc_fedo> seems wrong

per Subject


pagure.io and fedoraproject.org are two entirely different domain name so I am not sure this is going to change.

pkgdb, bodhi, fedocal, elections, nuancier, FMN all of these require you to log in, if you log in one you won't be logged in, in the others. Pagure is no different there.

Ipsilong (running at id.fedoraproject.org) has been taught to trust src.fedoraproject.org with info coming from FAS, so you shouldn't see the "Approve" button next time you log in (assuming you logged in recently enough or have a kerberos ticket).

I think this is the best we can do.

Since this is/was not a pagure issue though, I will close this ticket as invalid.

Thanks for your report!

Metadata Update from @pingou:
- Issue close_status updated to: Invalid

6 years ago

Login to comment on this ticket.

Metadata