第1章 Using Fernet keys for encryption in the overcloud
Fernet is the default token provider, that replaces uuid. You can review your Fernet deployment and rotate the Fernet keys.
1.1. Reviewing the Fernet deployment リンクのコピーリンクがクリップボードにコピーされました!
Review your configuration to confirm that Fernet tokens are working correctly.
Procedure
Retrieve the IP address of the controller node:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow SSH into the Controller node:
ssh heat-admin@192.0.2.16
[heat-admin@overcloud-controller-0 ~]$ ssh heat-admin@192.0.2.16Copy to Clipboard Copied! Toggle word wrap Toggle overflow Retrieve the values of the token driver and provider settings:
sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token driver sql sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token provider fernet
[heat-admin@overcloud-controller-0 ~]$ sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token driver sql [heat-admin@overcloud-controller-0 ~]$ sudo crudini --get /var/lib/config-data/puppet-generated/keystone/etc/keystone/keystone.conf token provider fernetCopy to Clipboard Copied! Toggle word wrap Toggle overflow Test the Fernet provider:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow The result includes the long Fernet token.