Bug 1189639 - [RFE][keystone]: rescope tokens unscoped to scoped only
Summary: [RFE][keystone]: rescope tokens unscoped to scoped only
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-keystone
Version: unspecified
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: Upstream M3
: 7.0 (Kilo)
Assignee: Nathan Kinder
QA Contact: Mike Abrams
URL: https://blueprints.launchpad.net/keys...
Whiteboard: upstream_milestone_kilo-3 upstream_de...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-02-05 14:18 UTC by RHOS Integration
Modified: 2016-04-26 13:45 UTC (History)
5 users (show)

Fixed In Version: openstack-keystone-2015.1.0-1.el7ost
Doc Type: Enhancement
Doc Text:
The Identity service now allows restriction of re-scoping tokens to only allow unscoped changes to be exchanged for scoped tokens. The Identity service allows for an existing token to be used to obtain a new token via the 'token' authentication method. Previously, a user with a valid token scoped for a project could use that token to obtain another token for a different project that they were authorized for. This allowed for anyone possessing a user's token to have access to any project the user has access to, as opposed to only having access to the project that the token is scoped for. To improve the security properties of scoped tokens, it was desirable to not allow this. A new 'allow_rescope_scoped_token' configuration option is available to allow token rescoping to be retricted. Rescoping of tokens is now only allowed by using an unscoped token to authenticate when this option is enabled.
Clone Of:
Environment:
Last Closed: 2015-08-05 13:20:24 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2015:1548 0 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform Enhancement Advisory 2015-08-05 17:07:06 UTC

Description RHOS Integration 2015-02-05 14:18:14 UTC
Cloned from launchpad blueprint https://blueprints.launchpad.net/keystone/+spec/rescoping.

Description:

Allow only rescoping from unscoped tokens.

Specification URL (additional information):

http://specs.openstack.org/openstack/keystone-specs/specs/kilo/rescoping.html

Comment 7 errata-xmlrpc 2015-08-05 13:20:24 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2015:1548


Note You need to log in before you can comment on or make changes to this bug.