Comment 12 for bug 1872737

Revision history for this message
Gage Hugo (gagehugo) wrote : Re: Keystone doesn't check signature TTL of the EC2 credential auth method

Thanks for the diff, looks good to me.

With the attack vector here being sniffing the auth header/no TTL, then using the header to reissue openstack tokens, this appears to be a Class A.[0] If this is agreed to be the case, I can work on drafting up an impact description here.

[0] https://security.openstack.org/vmt-process.html#incident-report-taxonomy