security-doc/security-guide/source/identity
Chris MacNaughton 882ec823e3 Update permission checks to include top level directory checks
By expanding the scope of the checks, we can maintain a higher
level of security by ensuring that newly created files created
in project configuration folders are restricted in the same
way as those listed, without hoping that projects update these
checks when they create these files.

For example, making /etc/keystone/keystone.conf have ownership
settings of root:keystone with permissions of 640 is practically
the same as giving /etc/keystone settings of root:keystone with
permissions of 750 as the same user restrictions apply.

Change-Id: I53d395e0d17bdfbdb08b71431b0af29506b94aa9
2019-04-01 06:26:30 +00:00
..
authentication-methods.rst Adding Kerb definition to External auth methods 2017-01-02 22:31:52 -08:00
authentication.rst Moving RST format to main security-guide folder 2015-08-12 06:59:51 +02:00
authorization.rst Use https 2017-01-30 20:15:41 +01:00
checklist.rst Update permission checks to include top level directory checks 2019-04-01 06:26:30 +00:00
domains.rst Replace existing rst markups with new ones 2016-02-22 18:08:05 +05:30
federated-keystone.rst Resolve Sphinx issues with syntax highlighting 2019-03-29 08:52:15 +01:00
policies.rst Resolve Sphinx issues with syntax highlighting 2019-03-29 08:52:15 +01:00
tokens.rst add info about expired tokens validation 2019-01-17 10:56:35 +00:00