Ce contenu n'est pas disponible dans la langue sélectionnée.
Chapter 8. Using Fernet keys for encryption in the overcloud
Fernet is the default token provider, that replaces uuid
. You can review your Fernet deployment and test that tokens are working correctly. Fernet uses three types of keys, which are stored in /var/lib/config-data/puppet-generated/keystone/etc/keystone/fernet-keys
. The highest-numbered directory contains the primary key, which generates new tokens and decrypts existing tokens.
8.1. Rotating fernet keys Copier lienLien copié sur presse-papiers!
You can rotate fernet keys for security compliance purposes. Use the rotate-fernet-keys.yaml
ansible playbook to complete this task.
Procedure
Run the
rotate-fernet-keys.yaml
playbook:ansible-playbook \ -i config-download/overcloud/tripleo-ansible-inventory.yaml \ /usr/share/ansible/tripleo-playbooks/rotate-fernet-keys.yaml
ansible-playbook \ -i config-download/overcloud/tripleo-ansible-inventory.yaml \ /usr/share/ansible/tripleo-playbooks/rotate-fernet-keys.yaml
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
8.2. Reviewing the Fernet deployment Copier lienLien copié sur presse-papiers!
To test that Fernet tokens are working correctly, retrieve the IP address of the Controller node, SSH into the Controller node, and review the settings of the token driver and provider.
Procedure
Retrieve the IP address of the Controller node:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow SSH into the Controller node:
ssh tripleo-admin@192.0.2.16
[tripleo-admin@overcloud-controller-0 ~]$ ssh tripleo-admin@192.0.2.16
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Retrieve the values of the token driver and provider settings:
sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token driver sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token provider
[tripleo-admin@overcloud-controller-0 ~]$ sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token driver sql [tripleo-admin@overcloud-controller-0 ~]$ sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token provider fernet
Copy to Clipboard Copied! Toggle word wrap Toggle overflow Test the Fernet provider:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow The result includes the long Fernet token.