Search
  • Software
    • Overview
    • Project Navigator
    • Sample Configs
    • Security
    • Get Started
    • Roadmap
    • Latest Release
    • Source Code
  • Users
    • Overview
    • Telecoms and NFV
    • OpenStack in the Enterprise
    • Application Developers & ISVs
    • Superuser Magazine
    • User Survey
  • Community
    • Welcome! Start Here
    • OpenStack Foundation
    • OpenStack Wiki
    • User Groups
    • Speakers Bureau
    • Supporting Companies
    • Jobs
    • Join The Community
  • Marketplace
  • Events
    • Overview
    • The OpenStack Summit
    • More OpenStack Events
    • OpenStack Days
  • Learn
    • Training
    • Get Certified
    • Ask a Technical Question
    • Superuser Magazine
    • Summit Videos
    • Analyst Reports
    • News
    • Blog
  • Docs
  • Join
    • Sign up for Foundation Membership
    • Sponsor the Foundation
    • More about the Foundation
  • Log In

All about keystone tokens

this page last updated: 2019-01-29 21:35:53

All about keystone tokens¶

Everything you need to know about keystone tokens.

  • Keystone tokens
    • Authorization scopes
    • Token providers
  • Fernet - Frequently Asked Questions
    • What is a fernet token?
    • What is a fernet key?
    • What are the different types of keys?
    • So, how does a staged key help me and why do I care about it?
    • Where do I put my key repository?
    • What is the recommended way to rotate and distribute keys?
    • Do fernet tokens still expire?
    • Why should I choose fernet tokens over UUID tokens?
    • Why should I choose fernet tokens over PKI or PKIZ tokens?
    • Should I rotate and distribute keys from the same keystone node every rotation?
    • How do I add new keystone nodes to a deployment?
    • How should I approach key distribution?
    • How long should I keep my keys around?
    • Is a fernet token still a bearer token?
    • What if I need to revoke all my tokens?
    • What can an attacker do if they compromise a fernet key in my deployment?
    • I rotated keys and now tokens are invalidating early, what did I do?
  • JWS key rotation
    • Initial setup
    • Continued operations
  • Token provider
this page last updated: 2019-01-29 21:35:53
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.

found an error? report a bug questions?
  • Guides
  • Install Guides
  • User Guides
  • Configuration Guides
  • Operations and Administration Guides
  • API Guides
  • Contributor Guides
  • Languages
  • Deutsch (German)
  • Français (French)
  • Bahasa Indonesia (Indonesian)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • 한국어 (Korean)
  • Português (Portuguese)
  • Türkçe (Türkiye)
  • 简体中文 (Simplified Chinese)

keystone

  • Keystone Installation Tutorial
  • Getting Started
  • Code Documentation
  • Indices and tables
  • Contributor Documentation
  • User Documentation
  • CLI Documentation
  • Administrator Guides
    • Getting Started
    • Keystone Configuration
    • Keystone Operations
    • All about keystone tokens
    • Identity API protection with role-based access control (RBAC)
    • Advanced Keystone Features
    • Authentication Mechanisms
  • Keystone Configuration Options

OpenStack

  • Projects
  • OpenStack Security
  • Common Questions
  • Blog
  • News

Community

  • User Groups
  • Events
  • Jobs
  • Companies
  • Contribute

Documentation

  • OpenStack Manuals
  • Getting Started
  • API Documentation
  • Wiki

Branding & Legal

  • Logos & Guidelines
  • Trademark Policy
  • Privacy Policy
  • OpenStack CLA

Stay In Touch

The OpenStack project is provided under the Apache 2.0 license. Openstack.org is powered by Rackspace Cloud Computing.