On Fri, Feb 28, 2014 at 8:13 AM, <j...@ioctl.org> wrote:

> The second would be to have a way for the nova process to extend proxy
> credentials until such point as they are required by the post- stages.
> I'll elide the potential security concerns over putting such an API call
> into keystone, but it should probably be considered.
>
>
This facility is already implemented in Keystone, it's called trusts[1].

[1]
https://github.com/openstack/identity-api/blob/master/openstack-identity-api/v3/src/markdown/identity-api-v3-os-trust-ext.md

- Brant
_______________________________________________
OpenStack-dev mailing list
OpenStack-dev@lists.openstack.org
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev

Reply via email to