[openstack-dev] [keystone][fernet] Fernet tokens sync
bbobrov at mirantis.com
Fri Mar 27 16:05:59 UTC 2015
On Friday 27 March 2015 17:14:28 Boris Bobrov wrote:
> As you know, keystone introduced non-persistent tokens in kilo -- Fernet
> tokens. These tokens use Fernet keys, that are rotated from time to time. A
> great description of key rotation and replication can be found on  and
>  (thanks, lbragstad). In HA setup there are multiple nodes with
> Keystone and that requires key replication. How do we do that with new
> Fernet tokens?
> Please keep in mind that the solution should be HA -- there should not be
> any "master" server, pushing keys to slave servers, because master server
> might go down.
 and  in the mail are:
After some discussion in #openstack-keystone it seems that token rotation
should not be an often procedure and that 15 minutes in the blog post was just
an example for the sake of simple math.
More information about the OpenStack-dev