[Openstack-security] [OSSN][DRAFT] Disabling a tenant does not disable a user token

Chmouel Boudjnah launchpad at chmouel.com
Thu Aug 8 16:47:10 UTC 2013


On Thu, Aug 8, 2013 at 5:53 PM, Kurt Seifried <kseifried at redhat.com> wrote:
>
> E.g. for Python pickle the main docs for it:
>
> http://docs.python.org/2/library/pickle.html
>
> have a giant red warning at the top stating the security risk. Does a
> similar thing exist for OpenStack tokens?

keystone is not using pickle anywhere.

Chmouel.




More information about the Openstack-security mailing list