PKI Token revocation

Bug #1037683 reported by Adam Young
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
Critical
Unassigned

Bug Description

NO way to revoke PKI tokens

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/11483

Changed in keystone:
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/11483
Committed: http://github.com/openstack/keystone/commit/7b70818954c2bc80bbfbb7679e0de9a483ee0c61
Submitter: Jenkins
Branch: master

commit 7b70818954c2bc80bbfbb7679e0de9a483ee0c61
Author: Maru Newby <email address hidden>
Date: Wed Aug 8 20:49:23 2012 -0400

    PKI Token revocation

    Co-authored-by: Adam Young <email address hidden>

    Token revocations are captured in the backends,

    During upgrade, all previous tickets are defaulted to valid.

    Revocation list returned as a signed document and can be fetched in an admin context via HTTP

    Change config values for enable diable PKI

    In the auth_token middleware, the revocation list is fetched prior
    to validating tokens. Any tokens that are on the revocation list
    will be treated as invalid.

    Added in PKI token tests that check the same logic as the UUID tests.
    Sample data for the tests is read out of the signing directory.

    dropped number on sql scripts to pass tests.

    Also fixes 1031373

    Bug 1037683

    Change-Id: Icef2f173e50fe3cce4273c161f69d41259bf5d23

Changed in keystone:
status: In Progress → Fix Committed
Joseph Heck (heckj)
Changed in keystone:
importance: Undecided → Critical
milestone: none → folsom-rc1
Thierry Carrez (ttx)
Changed in keystone:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in keystone:
milestone: folsom-rc1 → 2012.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.