Description of CA and SSL configuration options
Configuration option = Default value Description
[eventlet_server_ssl]
= /etc/keystone/ssl/certs/ca.pem (StrOpt) Path of the CA cert file for SSL.
= False (BoolOpt) Require client certificate.
= /etc/keystone/ssl/certs/keystone.pem (StrOpt) Path of the certfile for SSL. For non-production environments, you may be interested in using `keystone-manage ssl_setup` to generate self-signed certificates.
= False (BoolOpt) Toggle for SSL support on the Keystone eventlet servers.
= /etc/keystone/ssl/private/keystonekey.pem (StrOpt) Path of the keyfile for SSL.
[signing]
= /etc/keystone/ssl/certs/ca.pem (StrOpt) Path of the CA for token signing.
= /etc/keystone/ssl/private/cakey.pem (StrOpt) Path of the CA key for token signing.
= /C=US/ST=Unset/L=Unset/O=Unset/CN=www.example.com (StrOpt) Certificate subject (auto generated certificate) for token signing.
= /etc/keystone/ssl/certs/signing_cert.pem (StrOpt) Path of the certfile for token signing. For non-production environments, you may be interested in using `keystone-manage pki_setup` to generate self-signed certificates.
= 2048 (IntOpt) Key size (in bits) for token signing cert (auto generated certificate).
= /etc/keystone/ssl/private/signing_key.pem (StrOpt) Path of the keyfile for token signing.
= 3650 (IntOpt) Days the token signing cert is valid for (auto generated certificate).
[ssl]
= /etc/keystone/ssl/private/cakey.pem (StrOpt) Path of the CA key file for SSL.
= /C=US/ST=Unset/L=Unset/O=Unset/CN=localhost (StrOpt) SSL certificate subject (auto generated certificate).
= 1024 (IntOpt) SSL key length (in bits) (auto generated certificate).
= 3650 (IntOpt) Days the certificate is valid for once signed (auto generated certificate).