keystone server should default to localhost-only

Bug #1424061 reported by Brant Knudson
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ceilometer
Won't Fix
Undecided
Unassigned
OpenStack Identity (keystone)
Won't Fix
Undecided
Unassigned

Bug Description

By default keystone will listen on all interfaces. Keystone should use secure defaults. In this case, listen on localhost-only by default.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/157975

Changed in keystone:
status: New → In Progress
Eric Brown (ericwb)
Changed in ceilometer:
assignee: nobody → Eric Brown (ericwb)
status: New → In Progress
Revision history for this message
Dolph Mathews (dolph) wrote :

This has been discussed in the past as potential security hardening, and we opted to stick with 0.0.0.0. Is there some new motivation behind this worth hampering the deployer experience out of the box?

Brant Knudson (blk-u)
Changed in keystone:
status: In Progress → Won't Fix
assignee: Brant Knudson (blk-u) → nobody
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on keystone (master)

Change abandoned by Brant Knudson (<email address hidden>) on branch: master
Review: https://review.openstack.org/157975
Reason: Sticking with the current default.

Revision history for this message
Brant Knudson (blk-u) wrote :

I'm fine with sticking with the current default for Keystone.

Revision history for this message
gordon chung (chungg) wrote :
Changed in ceilometer:
assignee: Eric Brown (ericwb) → nobody
status: In Progress → Won't Fix
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on ceilometer (master)

Change abandoned by Eric Brown (<email address hidden>) on branch: master
Review: https://review.openstack.org/158523
Reason: This is a controversial change that requires more consensus.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.