[openstack-dev] [barbican] No ca_file in the KeystonePassword class

Thomas Goirand zigo at debian.org
Wed Nov 7 13:40:39 UTC 2018


Hi,

Trying to implement kms_keymaster in Swift (to enable encryption), I
have found out that Castellan's KeystonePassword doesn't include any
option for root CA certificates (neither a insecure=True option). In
such a configuration, it's not easy to test.

So my question is: has anyone from the Barbican thought about this,
and/or is there any workaround this? Going to production without any
possibility to test with fake certs is a little bit annoying... :P

Cheers,

Thomas Goirand (zigo)



More information about the OpenStack-dev mailing list