3d6f3088a3
This change creates a pre-delete hook to clean out all entries in the credential table of the keystone database when the keystone service is deleted. Note that these are not the typical username/password.[0] This fixes the issue of leftover credential blobs being saved in the database that are unable to be decrypted since the original encryption keys are removed upon deletion of the keystone service [0] https://specs.openstack.org/openstack/keystone-specs/specs/keystone/newton/credential-encryption.html Change-Id: I8adf0878af2f3b880e9194a6cb8d97b58d6895a5 |
||
---|---|---|
.. | ||
_bootstrap.sh.tpl | ||
_cred-clean.py.tpl | ||
_db-sync.sh.tpl | ||
_domain-manage-init.sh.tpl | ||
_domain-manage.py.tpl | ||
_domain-manage.sh.tpl | ||
_endpoint-update.py.tpl | ||
_fernet-manage.py.tpl | ||
_keystone-api.sh.tpl |