what does "insecure" in keystonemiddleware configuration mean? [closed]

asked 2014-12-03 02:56:17 -0500

darren-wang

hey guys,

this is a small question yet I got confused.

there is one configuration option in keystonemiddleware named "insecure", the comment says:" Verify the Https connection." and its default value is "False"

so what exactly does "insecure" here mean, when we set it to false, we verify the connection or not?


answered 2014-12-03 08:10:06 -0500

9lives

The insecure option has the same meaning as we are using curl -k to access the web site start with https.

In curl when we specify -k option, this will allow connections to SSL sites without verify server cert which is inscure. In keystonemiddleware if we set the insecure= False, the keystone client will verify the cert used by https, this is the a secure way.

Hope that helps!


so insecure = Flase correspond to verify, insecure = True corresponds to NOT verify, which is "insecure". got it, thx!

darren-wang

