OpenStack Identity - Identity uses strong hashing algorithms for PKI tokens

Information

MD5 is a weak and depreciated hashing algorithm. It can be cracked using brute force attack. Identity tokens are sensitive and need to be protected with a stronger hashing algorithm to prevent unauthorized disclosure and subsequent access.

Solution

Set the value of parameter hash_algorithm under [token] section in /etc/keystone/keystone.conf to SHA256

See Also

http://docs.openstack.org/security-guide/identity/checklist.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Unix

Control ID: d222d7255190941e49d3e78c233285ccf4ed198cc2c04f4160c4137004237953