Keystone should log authentication success

Bug #1320302 reported by Michael Solberg
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Invalid
Undecided
Unassigned
Havana
Fix Released
Wishlist
Nathan Kinder

Bug Description

Some security regulations require the auditing of authentication success. Keystone currently logs authentication failures, but doesn't log when a user successfully gets a token.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/93975

Changed in keystone:
assignee: nobody → Michael Solberg (msolberg)
status: New → In Progress
Changed in keystone:
assignee: Michael Solberg (msolberg) → Nathan Kinder (nkinder)
Alan Pevec (apevec)
Changed in keystone:
assignee: Nathan Kinder (nkinder) → nobody
status: In Progress → Invalid
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (stable/havana)

Fix proposed to branch: stable/havana
Review: https://review.openstack.org/94517

Revision history for this message
Dolph Mathews (dolph) wrote :

In icehouse, keystone emits CADF notifications on all authentication events (except for external & federated identities, I believe).

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on keystone (master)

Change abandoned by Morgan Fainberg (<email address hidden>) on branch: master
Review: https://review.openstack.org/93975
Reason: Abandoning, stable/havana change is here: https://review.openstack.org/#/c/94517/

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (stable/havana)

Reviewed: https://review.openstack.org/94517
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=49722668c29e388971e90e13db849f99c1547b80
Submitter: Jenkins
Branch: stable/havana

commit 49722668c29e388971e90e13db849f99c1547b80
Author: Michael Solberg <email address hidden>
Date: Fri May 16 13:52:17 2014 -0400

    Adds log message upon token granting

    This change adds a log message when a token is granted for a user.

    Change-Id: I21e87e54fe2eca552e403066ce9b3d5a20fbdb78
    Closes-Bug: #1320302

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.