OpenStack Networking - keystone used for authentication

Information

OpenStack supports various authentication strategies like noauth, keystone etc. If the 'noauth' strategy is used then the users could interact with OpenStack services without any authentication. This could be a potential risk since an attacker might gain unauthorized access to the OpenStack components. Thus it is strongly recommended that all services must be authenticated with keystone using their service accounts.

Solution

Set the value of parameter 'auth_strategy' under [DEFAULT] section in /etc/neutron/neutron.conf to keystone

See Also

http://docs.openstack.org/security-guide/networking/checklist.html

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5

Plugin: Unix

Control ID: 178d303c055f201c9e4264b4d7c1607df8ca368901f7e8dbaf461323108ff765