Comment 13 for bug 1260080

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Trustee token revocations with memcache backend

Draft impact description -

Title: Trustee token revocations does not work with memcache backend
Reporter: Morgan Fainberg
Products: Keystone
Affects: All supported versions

Description:
Morgan Fainberg reported a vulnerability in Keystone memcache token backend.
When a trustor issue a trust token with impersonation enabled, the token is
only added to the trustor's token list and not to the trustee's token list.
This results in the trust token not being invalidated by trustee's token
revocation (bulk revocation). This is most noticeable when the trustee user
is disabled or the trustee change a password.
Only setups using memcache backend for token in Keystone are affected.