Description of problem: Fernet tokens are not default in upstream Mitaka due to several unit tests failing. Once these have been resolved, the changes required should be backported to ship with OSP 8.
This needs a spec for Tripleo, as there is no support for deploying and syncing keys. it might be possible to do in a manual process, but will not be default, or managed, by openstack overcloud deploy.
Upstream discussion on key rotation: http://lists.openstack.org/pipermail/openstack-dev/2016-August/101262.html
A series of reviews in Puppet, Heat, and Tripleo look likely to make this a reality, or at least much closer. https://review.openstack.org/#/q/topic:keystone/credentials
(In reply to Adam Young from comment #4) > A series of reviews in Puppet, Heat, and Tripleo look likely to make this a > reality, or at least much closer. > > https://review.openstack.org/#/q/topic:keystone/credentials These did not actually implement Fernet support, so more work is needed here.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2016-2948.html