Search
  • Software
    • Overview
    • OpenStack Components
    • SDKs
    • Deployment Tools
    • OpenStack Map
    • Sample Configs
  • Use Cases
    • Users in Production

    • Ironic Bare Metal
    • Edge Computing
    • Telecom & NFV
    • Science and HPC
    • Containers
    • Enterprise
    • User Survey
  • Events
    • OpenInfra Summit
    • Project Teams Gathering
    • OpenDev
    • Community Events
    • OpenStack & OpenInfra Days
    • Summit Videos
  • Community
    • Welcome! Start Here
    • OpenStack Technical Committee
    • Speakers Bureau
    • OpenStack Wiki
    • Get Certified (COA)
    • Jobs
    • Marketing Resources
    • Community News
    • Superuser Magazine

    • OpenInfra Foundation Supporting Organizations
    • OpenInfra Foundation
  • Marketplace
    • Training
    • Distros & Appliances
    • Public Clouds
    • Hosted Private Clouds
    • Remotely Managed Private Clouds
    • Consulting & Integrators
    • Drivers
  • Blog
  • Docs
  • Join
    • Sign up for Foundation Membership
    • Sponsor the Foundation
    • More about the Foundation
  • Log In

Identity

Identity¶

Identity service (keystone) provides identity, token, catalog, and policy services for use specifically by services in the OpenStack family. Identity service is organized as a group of internal services exposed on one or many endpoints. Many of these services are used in a combined fashion by the front end. For example, an authentication call validates user and project credentials with the identity service. If successful, it will create and return a token with the token service. More information can be found by reading the keystone Developer Documentation.

  • Authentication
    • Invalid login attempts
    • Multi-factor authentication
  • Authentication methods
    • Internally implemented authentication methods
    • External authentication methods
  • Authorization
    • Establish formal access control policies
    • Service authorization
    • Administrative users
    • End users
  • Policies
  • Tokens
    • Fernet tokens
    • JWT tokens
  • Domains
  • Federated keystone
    • Why use Federated Identity?
  • Checklist
    • Check-Identity-01: Is user/group ownership of config files set to keystone?
    • Check-Identity-02: Are strict permissions set for Identity configuration files?
    • Check-Identity-03: is TLS enabled for Identity?
    • Check-Identity-04: (Obsolete)
    • Check-Identity-05: Is max_request_body_size set to default (114688)?
    • Check-Identity-06: Disable admin token in /etc/keystone/keystone.conf
    • Check-Identity-07: insecure_debug false in /etc/keystone/keystone.conf
    • Check-Identity-08: Use fernet token in /etc/keystone/keystone.conf
this page last updated: 2025-05-06 22:08:01
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.

found an error? report a bug
  • Guides
  • Install Guides
  • User Guides
  • Configuration Guides
  • Operations and Administration Guides
  • API Guides
  • Contributor Guides
  • Languages
  • Deutsch (German)
  • Français (French)
  • Bahasa Indonesia (Indonesian)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • 한국어 (Korean)
  • Português (Portuguese)
  • Türkçe (Türkiye)
  • 简体中文 (Simplified Chinese)

Security Guide

  • Conventions
  • Introduction
  • System documentation
  • Management
  • Secure communication
  • API endpoints
  • Identity
    • Authentication
    • Authentication methods
    • Authorization
    • Policies
    • Tokens
    • Domains
    • Federated keystone
    • Checklist
  • Dashboard
  • Compute
  • Block Storage
  • Image Storage
  • Shared File Systems
  • Networking
  • Object Storage
  • Secrets Management
  • Message queuing
  • Data processing
  • Databases
  • Tenant data privacy
  • Instance security management
  • Monitoring and logging
  • Compliance
  • Security review
  • Security Checklist
  • Appendix

OpenStack

  • Projects
  • OpenStack Security
  • Blog
  • News

Community

  • User Groups
  • Events
  • Jobs
  • Companies
  • Contribute

Documentation

  • OpenStack Manuals
  • Getting Started
  • API Documentation
  • Wiki

Branding & Legal

  • Legal Docs
  • Logos & Guidelines
  • Trademark Policy
  • Privacy Policy
  • OpenInfra CLA

Stay In Touch

The OpenStack project is provided under the Apache 2.0 license. Docs.openstack.org is powered by Rackspace Cloud Computing.