[Openstack] Messaging level auth

Joshua Harlow harlowja at yahoo-inc.com
Wed Sep 21 21:20:48 UTC 2011


A quick security question.

Is there any plan to force authentication/authorization of the rabbitmq messages?

Right now it seems like keystone (tbd) will protect the external<->openstack layers but what about the openstack<->openstack layers.

If someone got access to the rabbitmq it seems like without this kind of layer bad things could happen (create me 1000 nodes...).

Has there been any thought in that area?

-Josh

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack/attachments/20110921/386016d1/attachment.html>


More information about the Openstack mailing list