[Openstack-security] [openstack/horizon] SecurityImpact review request change I6774b9b7215d191259586e4721e357487bb777cd
gerrit2 at review.openstack.org
gerrit2 at review.openstack.org
Sun Aug 24 15:07:55 UTC 2014
Hi, I'd like you to take a look at this patch for potential
SecurityImpact.
https://review.openstack.org/116510
Log:
commit f9b3684a6ef82290e57d20e5e141031abfd5b768
Author: Brant Knudson <bknudson at us.ibm.com>
Date: Sun Aug 24 10:04:10 2014 -0500
Document token hash algorithm option
With https://review.openstack.org/#/c/116509/ ,
django-openstack-auth will support a new option for the token hash
algorithm. This adds the documentation to Horizon's local settings
example file.
This is for security hardening. The token hash algorithm defaults
to MD5, which is considered too weak due to the potential for hash
collisions. Some security standards require a SHA2 hash algorithm to
be used.
DocImpact
SecurityImpact
Change-Id: I6774b9b7215d191259586e4721e357487bb777cd
Closes-Bug: #1174499
More information about the Openstack-security
mailing list