From 6ed054951e5d78ce803b4f2932d576dcc9210d2b Mon Sep 17 00:00:00 2001 From: Dolph Mathews Date: Thu, 29 May 2014 10:16:11 -0500 Subject: [PATCH] document pki_setup and ssl_setup in keystone.conf.sample Change-Id: I9630bfa623dbdb470b89978ebb4a8ec026c5e793 Closes-Bug: 1275823 --- etc/keystone.conf.sample | 10 ++++++++-- keystone/common/config.py | 10 ++++++++-- 2 files changed, 16 insertions(+), 4 deletions(-) diff --git a/etc/keystone.conf.sample b/etc/keystone.conf.sample index f4807357ec..b20139d02d 100644 --- a/etc/keystone.conf.sample +++ b/etc/keystone.conf.sample @@ -1176,7 +1176,10 @@ # (string value) #token_format= -# Path of the certfile for token signing. (string value) +# Path of the certfile for token signing. For non-production +# environments, you may be interested in using `keystone- +# manage pki_setup` to generate self-signed certificates. +# (string value) #certfile=/etc/keystone/ssl/certs/signing_cert.pem # Path of the keyfile for token signing. (string value) @@ -1211,7 +1214,10 @@ # (boolean value) #enable=false -# Path of the certfile for SSL. (string value) +# Path of the certfile for SSL. For non-production +# environments, you may be interested in using `keystone- +# manage ssl_setup` to generate self-signed certificates. +# (string value) #certfile=/etc/keystone/ssl/certs/keystone.pem # Path of the keyfile for SSL. (string value) diff --git a/keystone/common/config.py b/keystone/common/config.py index e936973f70..02179c28a3 100644 --- a/keystone/common/config.py +++ b/keystone/common/config.py @@ -288,7 +288,10 @@ FILE_OPTIONS = { 'eventlet servers.'), cfg.StrOpt('certfile', default="/etc/keystone/ssl/certs/keystone.pem", - help='Path of the certfile for SSL.'), + help='Path of the certfile for SSL. For non-production ' + 'environments, you may be interested in using ' + '`keystone-manage ssl_setup` to generate self-signed ' + 'certificates.'), cfg.StrOpt('keyfile', default='/etc/keystone/ssl/private/keystonekey.pem', help='Path of the keyfile for SSL.'), @@ -317,7 +320,10 @@ FILE_OPTIONS = { '[token] section.'), cfg.StrOpt('certfile', default='/etc/keystone/ssl/certs/signing_cert.pem', - help='Path of the certfile for token signing.'), + help='Path of the certfile for token signing. For ' + 'non-production environments, you may be interested ' + 'in using `keystone-manage pki_setup` to generate ' + 'self-signed certificates.'), cfg.StrOpt('keyfile', default='/etc/keystone/ssl/private/signing_key.pem', help='Path of the keyfile for token signing.'),