fungi | d34dh0r53: thanks for opening https://launchpad.net/bugs/1992183 | 16:58 |
---|---|---|
fungi | would you mind linking the earlier rh bug in a comment if not the description? | 16:58 |
fungi | gagehugo: ^ you may have also had input on that | 16:59 |
gagehugo | The 1 minute app cred thing is weird, but I can see the security issue there | 17:03 |
gagehugo | just an odd use case | 17:03 |
gagehugo | my main concern is making sure we document the behavior of token expiry using app creds vs the config setting if we change it | 17:03 |
gagehugo | but that is more keystone talk than security | 17:04 |
fungi | keystone is security | 17:06 |
* gagehugo puts the security hat on top of the keystone hat | 17:07 | |
fungi | i mean, it's central to authentication and authorization for all of openstack (except in standalone service deployments), so it's definitely on topic here | 17:07 |
fungi | much like pretty much everything barbican touches is on topic here | 17:07 |
fungi | but yes, if you want to convince other keystone core reviewers of the merits of approving some documentation patch, then maybe the keystone channel would be better. is anyone writing that change yet? | 17:08 |
Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!