[openstack-dev] [keystone] Case for renewability of tokens, increasing expiration time

2015-11-16 Thread Lindsay Pallickal
I was having an issue extending the expiration on unscoped and tenant/project scoped tokens retrieved with an existing token. I now realize this is a feature, not a bug, but I've got some points to argue that extending token expiration when getting a new token with an existing one (renewal), is wor

Re: [openstack-dev] [keystone] Case for renewability of tokens, increasing expiration time

2015-11-17 Thread Lindsay Pallickal
On Tue, Nov 17, 2015 at 5:31 AM, Dolph Mathews wrote: > > > On Tuesday, November 17, 2015, Lindsay Pallickal > wrote: > >> >> It looks like expiration is done this way to limit the damage from stolen >> tokens, but if a token were stolen, it could be stolen fro