[Openstack-security] [Bug 1434034] Re: Disabling users & groups may not invalidate previously-issued tokens
Doug Chivers
1434034 at bugs.launchpad.net
Thu Sep 3 18:12:45 UTC 2015
*** This bug is a duplicate of bug 1435530 ***
https://bugs.launchpad.net/bugs/1435530
** This bug has been marked a duplicate of bug 1435530
keystonemiddleware without TRL checking and default cache config can allow access after token revocation
--
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1434034
Title:
Disabling users & groups may not invalidate previously-issued tokens
Status in Keystone:
Won't Fix
Status in Keystone juno series:
Won't Fix
Status in OpenStack Security Advisory:
Won't Fix
Status in OpenStack Security Notes:
Confirmed
Bug description:
Even if the user is disabled, can use the last token is validated.
0. user foo is enable
1. get token (a)
2. user foo is disabled
3. foo can still use any APIs by token(a)
that's all.
This issue is not cache process.
To manage notifications about this bug go to:
https://bugs.launchpad.net/keystone/+bug/1434034/+subscriptions
More information about the Openstack-security
mailing list