[Openstack-security] Certificate life in OpenStack

Clark, Robert Graham robert.clark at hp.com
Thu May 8 09:10:44 UTC 2014

We are looking at various appliocations of short-life certificates in
OpenStack, an idea I've discussed with a few members of the OpenStack
Security Group previously.

Has anyone done any analysis on what the shortest lifespan you can
generally get away with, or to put it another way, what's the longest
operation that ever happens with an individual certificate?

I'm sure this will vary by service but very curious to see what others
have done.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6187 bytes
Desc: not available
URL: <http://lists.openstack.org/pipermail/openstack-security/attachments/20140508/8289a51f/attachment.bin>

More information about the Openstack-security mailing list