Comment 4 for bug 1353315

Revision history for this message
Dolph Mathews (dolph) wrote : Re: Incorrect condition expression for ssl_insecure

The scenario where a deployer specifically sets:

  ssl_insecure = false

... in an attempt to ensure that verification is performed will be sorely disappointed to learn that it is not, and perhaps left vulnerable. This qualifies as a security fix and *should* be fixed in python-keystoneclient as well as keystonemiddleware.