OpenStack Identity - SSL enabled

Information

OpenStack components communicate with each other using various protocols and the communication might involve sensitive or confidential data. An attacker may try to eavesdrop on the channel in order to get access to sensitive information. Thus all the components must communicate with each other using a secured communication protocol like HTTPS.

Solution

Set the value of parameter enable under [ssl] section in /etc/keystone/keystone.conf to True

See Also

http://docs.openstack.org/security-guide/identity/checklist.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1)

Plugin: Unix

Control ID: 775c1c6d0f68fa10328ae7b76bcf707ab80e806941bf7ddf9f4de424f8d5451f