Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: OpenStack: Dev

[Keystone] PKI

 

 

OpenStack dev RSS feed   Index | Next | Previous | View Threaded


heckj at mac

May 15, 2012, 12:06 PM

Post #1 of 7 (117 views)
Permalink
[Keystone] PKI

Coming out of the Keystone meeting from today (http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-meeting.2012-05-15-18.02.html), I thought it worth mentioning that adam young has been doing some tremendous lifting in terms of looking at adding in PKI support to Keystone. The writeup and details are on the OpenStack wiki at http://wiki.openstack.org/PKI

I rather suspect there's a lot of interest in this topic, so I wanted to make sure the broader community knew about the effort, what we were thinking, and were we are.

If you're interested in discussing, the keystone meeting is on Tuesday mornings at 18:00 UTC

-joe

_______________________________________________
Mailing list: https://launchpad.net/~openstack
Post to : openstack [at] lists
Unsubscribe : https://launchpad.net/~openstack
More help : https://help.launchpad.net/ListHelp


razique.mahroua at gmail

May 15, 2012, 1:30 PM

Post #2 of 7 (113 views)
Permalink
Re: [Keystone] PKI [In reply to]

great topic :)


> Joseph Heck <mailto:heckj [at] mac>
> 15 mai 2012 21:06
> Coming out of the Keystone meeting from today
> (http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-meeting.2012-05-15-18.02.html),
> I thought it worth mentioning that adam young has been doing some
> tremendous lifting in terms of looking at adding in PKI support to
> Keystone. The writeup and details are on the OpenStack wiki at
> http://wiki.openstack.org/PKI
>
> I rather suspect there's a lot of interest in this topic, so I wanted
> to make sure the broader community knew about the effort, what we were
> thinking, and were we are.
>
> If you're interested in discussing, the keystone meeting is on Tuesday
> mornings at 18:00 UTC
>
> -joe
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> Post to : openstack [at] lists
> Unsubscribe : https://launchpad.net/~openstack
> More help : https://help.launchpad.net/ListHelp

--
Nuage & Co - Razique Mahroua
razique.mahroua [at] gmail
Attachments: postbox-contact.jpg (1.24 KB)
  image.jpg (9.88 KB)


thor at wolpert

May 15, 2012, 1:47 PM

Post #3 of 7 (120 views)
Permalink
Re: [Keystone] PKI [In reply to]

If you're open to levarging other OSS projects,
http://www.ejbca.org/architecture.html us a great one to look at, assuming
you need a PKI implementation available.

I believe it is at least worth a look.

On Tue, May 15, 2012 at 1:30 PM, Razique Mahroua
<razique.mahroua [at] gmail>wrote:

> great topic :)
>
>
> Joseph Heck <heckj [at] mac>
> 15 mai 2012 21:06
> Coming out of the Keystone meeting from today (
> http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-meeting.2012-05-15-18.02.html),
> I thought it worth mentioning that adam young has been doing some
> tremendous lifting in terms of looking at adding in PKI support to
> Keystone. The writeup and details are on the OpenStack wiki at
> http://wiki.openstack.org/PKI
>
> I rather suspect there's a lot of interest in this topic, so I wanted to
> make sure the broader community knew about the effort, what we were
> thinking, and were we are.
>
> If you're interested in discussing, the keystone meeting is on Tuesday
> mornings at 18:00 UTC
>
> -joe
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> Post to : openstack [at] lists
> Unsubscribe : https://launchpad.net/~openstack
> More help : https://help.launchpad.net/ListHelp
>
>
> --
> Nuage & Co - Razique Mahroua
> razique.mahroua [at] gmail
>
>
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> Post to : openstack [at] lists
> Unsubscribe : https://launchpad.net/~openstack
> More help : https://help.launchpad.net/ListHelp
>
>


ayoung at redhat

May 15, 2012, 6:09 PM

Post #4 of 7 (117 views)
Permalink
Re: [Keystone] PKI [In reply to]

Well, the PKI pieces are the same regardless of the CA and certificate
issuing pieces. All we will need to do is to use a signing key to sign
a document. So EJBCA or Dogtag will work equally as well. If people
already have a CA infrastructure, they should be able to leverage that, too.


On 05/15/2012 04:47 PM, Thor Wolpert wrote:
> If you're open to levarging other OSS projects,
> http://www.ejbca.org/architecture.html us a great one to look at,
> assuming you need a PKI implementation available.
>
> I believe it is at least worth a look.
>
> On Tue, May 15, 2012 at 1:30 PM, Razique Mahroua
> <razique.mahroua [at] gmail <mailto:razique.mahroua [at] gmail>> wrote:
>
> great topic :)
>
>
>> Joseph Heck <mailto:heckj [at] mac>
>> 15 mai 2012 21:06
>> Coming out of the Keystone meeting from today
>> (http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-meeting.2012-05-15-18.02.html),
>> I thought it worth mentioning that adam young has been doing some
>> tremendous lifting in terms of looking at adding in PKI support
>> to Keystone. The writeup and details are on the OpenStack wiki at
>> http://wiki.openstack.org/PKI
>>
>> I rather suspect there's a lot of interest in this topic, so I
>> wanted to make sure the broader community knew about the effort,
>> what we were thinking, and were we are.
>>
>> If you're interested in discussing, the keystone meeting is on
>> Tuesday mornings at 18:00 UTC
>>
>> -joe
>>
>> _______________________________________________
>> Mailing list: https://launchpad.net/~openstack
>> <https://launchpad.net/%7Eopenstack>
>> Post to : openstack [at] lists
>> <mailto:openstack [at] lists>
>> Unsubscribe : https://launchpad.net/~openstack
>> <https://launchpad.net/%7Eopenstack>
>> More help : https://help.launchpad.net/ListHelp
>
> --
> Nuage & Co - Razique Mahroua
> razique.mahroua [at] gmail <mailto:razique.mahroua [at] gmail>
>
>
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> <https://launchpad.net/%7Eopenstack>
> Post to : openstack [at] lists
> <mailto:openstack [at] lists>
> Unsubscribe : https://launchpad.net/~openstack
> <https://launchpad.net/%7Eopenstack>
> More help : https://help.launchpad.net/ListHelp
>
>
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> Post to : openstack [at] lists
> Unsubscribe : https://launchpad.net/~openstack
> More help : https://help.launchpad.net/ListHelp


haneefmlist at gmail

May 15, 2012, 8:31 PM

Post #5 of 7 (120 views)
Permalink
Re: [Keystone] PKI [In reply to]

Hi Adam,

Can you please clarify the following in PKI blueprint?


1) Do you assume that roles won't be changed after getToken and before
validateToken?

<!--

if the token contains just the following data :

- {username: admiyo,tenant: Fedora,expires: 2359:05May2012, roles:
[admin,editor]}

This message is then encrypted with Keystones private key. Any service that
has Keystones public key can decrypt the message. Since it is decrypted
with the public key, it had to be encrypted by Keystone, and is therefore
valid. The Keystone Certificate only has to be distributed once to each
service, and can be fetched on demand.

-->

What is keystone private key? Do you mean user private key?
<!--When a user is created in Keystone, they will be given a
one-time-password that they will then use to establish a key-pair. Only the
Public Key will be stored on the Keystone server, the Private key will only
be stored on the end users system. The public key will be signed by the
certificate authority (X509) and then stored in the Keystone system. From
this point on, when authenticating to Keystone, the user will use the
client certificate.
-->

1) Why do we need to store users client cert in keystone system? BTW what
do you mean by keystone system? Is it keystone server? or any system
like swift/nova which uses keystone to authenticate

Thanks

On Tue, May 15, 2012 at 6:09 PM, Adam Young <ayoung [at] redhat> wrote:

> Well, the PKI pieces are the same regardless of the CA and certificate
> issuing pieces. All we will need to do is to use a signing key to sign a
> document. So EJBCA or Dogtag will work equally as well. If people already
> have a CA infrastructure, they should be able to leverage that, too.
>
>
>
> On 05/15/2012 04:47 PM, Thor Wolpert wrote:
>
> If you're open to levarging other OSS projects,
> http://www.ejbca.org/architecture.html us a great one to look at,
> assuming you need a PKI implementation available.
>
> I believe it is at least worth a look.
>
> On Tue, May 15, 2012 at 1:30 PM, Razique Mahroua <
> razique.mahroua [at] gmail> wrote:
>
>> great topic :)
>>
>>
>> Joseph Heck <heckj [at] mac>
>> 15 mai 2012 21:06
>> Coming out of the Keystone meeting from today (
>> http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-meeting.2012-05-15-18.02.html),
>> I thought it worth mentioning that adam young has been doing some
>> tremendous lifting in terms of looking at adding in PKI support to
>> Keystone. The writeup and details are on the OpenStack wiki at
>> http://wiki.openstack.org/PKI
>>
>> I rather suspect there's a lot of interest in this topic, so I wanted to
>> make sure the broader community knew about the effort, what we were
>> thinking, and were we are.
>>
>> If you're interested in discussing, the keystone meeting is on Tuesday
>> mornings at 18:00 UTC
>>
>> -joe
>>
>> _______________________________________________
>> Mailing list: https://launchpad.net/~openstack
>> Post to : openstack [at] lists
>> Unsubscribe : https://launchpad.net/~openstack
>> More help : https://help.launchpad.net/ListHelp
>>
>>
>> --
>> Nuage & Co - Razique Mahroua
>> razique.mahroua [at] gmail
>>
>>
>>
>>
>> _______________________________________________
>> Mailing list: https://launchpad.net/~openstack
>> Post to : openstack [at] lists
>> Unsubscribe : https://launchpad.net/~openstack
>> More help : https://help.launchpad.net/ListHelp
>>
>>
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> Post to : openstack [at] lists
> Unsubscribe : https://launchpad.net/~openstack
> More help : https://help.launchpad.net/ListHelp
>
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> Post to : openstack [at] lists
> Unsubscribe : https://launchpad.net/~openstack
> More help : https://help.launchpad.net/ListHelp
>
>


Tim.Bell at cern

May 15, 2012, 11:21 PM

Post #6 of 7 (119 views)
Permalink
Re: [Keystone] PKI [In reply to]

Fully agreed. Academic and Research sites have extensive X.509
infrastructure that we would not wish to duplicate.



Are you only looking at user certificates or are host certificates in the
scope too ?



Tim



From: openstack-bounces+tim.bell=cern.ch [at] lists
[mailto:openstack-bounces+tim.bell=cern.ch [at] lists] On Behalf Of
Adam Young
Sent: 16 May 2012 03:10
To: openstack [at] lists
Subject: Re: [Openstack] [Keystone] PKI



Well, the PKI pieces are the same regardless of the CA and certificate
issuing pieces. All we will need to do is to use a signing key to sign a
document. So EJBCA or Dogtag will work equally as well. If people already
have a CA infrastructure, they should be able to leverage that, too.


On 05/15/2012 04:47 PM, Thor Wolpert wrote:

If you're open to levarging other OSS projects,
http://www.ejbca.org/architecture.html us a great one to look at, assuming
you need a PKI implementation available.



I believe it is at least worth a look.

On Tue, May 15, 2012 at 1:30 PM, Razique Mahroua <razique.mahroua [at] gmail>
wrote:

great topic :)





<mailto:heckj [at] mac> Joseph Heck

15 mai 2012 21:06

Coming out of the Keystone meeting from today
(http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-me
eting.2012-05-15-18.02.html), I thought it worth mentioning that adam young
has been doing some tremendous lifting in terms of looking at adding in PKI
support to Keystone. The writeup and details are on the OpenStack wiki at
http://wiki.openstack.org/PKI

I rather suspect there's a lot of interest in this topic, so I wanted to
make sure the broader community knew about the effort, what we were
thinking, and were we are.

If you're interested in discussing, the keystone meeting is on Tuesday
mornings at 18:00 UTC

-joe

_______________________________________________
Mailing list: https://launchpad.net/~openstack
<https://launchpad.net/%7Eopenstack>
Post to : openstack [at] lists
Unsubscribe : https://launchpad.net/~openstack
<https://launchpad.net/%7Eopenstack>
More help : https://help.launchpad.net/ListHelp



--
Nuage & Co - Razique Mahroua
razique.mahroua [at] gmail




_______________________________________________
Mailing list: https://launchpad.net/~openstack
<https://launchpad.net/%7Eopenstack>
Post to : openstack [at] lists
Unsubscribe : https://launchpad.net/~openstack
<https://launchpad.net/%7Eopenstack>
More help : https://help.launchpad.net/ListHelp








_______________________________________________
Mailing list: https://launchpad.net/~openstack
Post to : openstack [at] lists
Unsubscribe : https://launchpad.net/~openstack
More help : https://help.launchpad.net/ListHelp
Attachments: smime.p7s (5.08 KB)


ayoung at redhat

May 16, 2012, 7:39 AM

Post #7 of 7 (117 views)
Permalink
Re: [Keystone] PKI [In reply to]

This builds on X509.

I've written up a proof of concept.

http://adam.younglogic.com/2012/05/signed-authz-authn/



On 05/16/2012 02:21 AM, Tim Bell wrote:
>
> Fully agreed. Academic and Research sites have extensive X.509
> infrastructure that we would not wish to duplicate.
>
> Are you only looking at user certificates or are host certificates in
> the scope too ?
>
> Tim
>
> *From:*openstack-bounces+tim.bell=cern.ch [at] lists
> [mailto:openstack-bounces+tim.bell=cern.ch [at] lists] *On
> Behalf Of *Adam Young
> *Sent:* 16 May 2012 03:10
> *To:* openstack [at] lists
> *Subject:* Re: [Openstack] [Keystone] PKI
>
> Well, the PKI pieces are the same regardless of the CA and certificate
> issuing pieces. All we will need to do is to use a signing key to
> sign a document. So EJBCA or Dogtag will work equally as well. If
> people already have a CA infrastructure, they should be able to
> leverage that, too.
>
>
> On 05/15/2012 04:47 PM, Thor Wolpert wrote:
>
> If you're open to levarging other OSS projects,
> http://www.ejbca.org/architecture.html us a great one to look at,
> assuming you need a PKI implementation available.
>
> I believe it is at least worth a look.
>
> On Tue, May 15, 2012 at 1:30 PM, Razique Mahroua
> <razique.mahroua [at] gmail <mailto:razique.mahroua [at] gmail>> wrote:
>
> great topic :)
>
>
>
> *Joseph Heck* <mailto:heckj [at] mac>
>
> 15 mai 2012 21:06
>
> Coming out of the Keystone meeting from today
> (http://eavesdrop.openstack.org/meetings/openstack-meeting/2012/openstack-meeting.2012-05-15-18.02.html),
> I thought it worth mentioning that adam young has been doing some
> tremendous lifting in terms of looking at adding in PKI support to
> Keystone. The writeup and details are on the OpenStack wiki at
> http://wiki.openstack.org/PKI
>
> I rather suspect there's a lot of interest in this topic, so I wanted
> to make sure the broader community knew about the effort, what we were
> thinking, and were we are.
>
> If you're interested in discussing, the keystone meeting is on Tuesday
> mornings at 18:00 UTC
>
> -joe
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> <https://launchpad.net/%7Eopenstack>
> Post to : openstack [at] lists
> <mailto:openstack [at] lists>
> Unsubscribe : https://launchpad.net/~openstack
> <https://launchpad.net/%7Eopenstack>
> More help : https://help.launchpad.net/ListHelp
>
> --
> Nuage & Co - Razique Mahroua
> *razique.mahroua [at] gmail <mailto:razique.mahroua [at] gmail>*
>
>
> _______________________________________________
> Mailing list: https://launchpad.net/~openstack
> <https://launchpad.net/%7Eopenstack>
> Post to : openstack [at] lists
> <mailto:openstack [at] lists>
> Unsubscribe : https://launchpad.net/~openstack
> <https://launchpad.net/%7Eopenstack>
> More help : https://help.launchpad.net/ListHelp
>
>
>
>
> _______________________________________________
> Mailing list:https://launchpad.net/~openstack <https://launchpad.net/%7Eopenstack>
> Post to :openstack [at] lists <mailto:openstack [at] lists>
> Unsubscribe :https://launchpad.net/~openstack <https://launchpad.net/%7Eopenstack>
> More help :https://help.launchpad.net/ListHelp
>

OpenStack dev RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.