OpenStack Identity - max_request_body_size set to default

Information

The parameter max_request_body_size defines the maximum body size per request in bytes. If the maximum size is not defined, the attacker could craft an arbitrary request of large size causing the service to crash and finally resulting in Denial Of Service attack. Assigning the maximum value ensures that any malicious oversized request gets blocked ensuring continued availability of the component.

Solution

Set value of parameter max_request_body_size in /etc/keystone/keystone.conf is set to default (114688) or some reasonable value based on your environment

See Also

http://docs.openstack.org/security-guide/identity/checklist.html

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5(2)

Plugin: Unix

Control ID: bf6e300071ba4c91c1eaae247f702097a9b5733de938b39d988fdd3f0c1ace93