)]}'
{"security-notes/OSSN-0111.yaml":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"a1b15fc86eb94e0def5dc1f4c708bc92178e7a7c","unresolved":true,"context_lines":[{"line_number":1,"context_line":"id: OSSN-0111"},{"line_number":2,"context_line":""},{"line_number":3,"context_line":"title: Keystone MFA enforcement gaps and authentication replay weaknesses"},{"line_number":4,"context_line":""},{"line_number":5,"context_line":"affected-services: |"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"d7ff0ca8_f7051ac2","line":2,"updated":"2026-09-22 15:08:11.000000000","message":"This\u0027ll need a \"date\" key with a date attached. This is why in the rendered version, it\u0027s in the index as \"...replay weaknesses ()\" (the date is usually appended)","commit_id":"8dfa7c0b0bbfd334c9d8d68fae9181da6d365132"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"b0a485609314887bdb2a4b546243f96abd9fce13","unresolved":true,"context_lines":[{"line_number":16,"context_line":"  seeds, or let operators configure MFA in ways that lock users out."},{"line_number":17,"context_line":"  Deployments that rely on TOTP MFA for account protection should treat these"},{"line_number":18,"context_line":"  as known limitations until patched Keystone releases are deployed. MFA still"},{"line_number":19,"context_line":"  materially raises the bar over password-only authentication; this note"},{"line_number":20,"context_line":"  documents what it does and does not protect today."},{"line_number":21,"context_line":""},{"line_number":22,"context_line":"discussion: |"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"e81bbc55_54492a08","line":19,"updated":"2026-09-24 09:43:13.000000000","message":"I wonder about this phrasing. I don\u0027t want to be too alarming, but the main issue right now is that if you can steal any session token, then you have access to the APIs to read a TOTP seed, effectively also \"stealing\" the hardware token. You can also create new ones or change the current one. Same for the account password, as you can change it without OTP.\n\nThe recommended action below state it precisely enough though, IMO.","commit_id":"8dfa7c0b0bbfd334c9d8d68fae9181da6d365132"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"a1b15fc86eb94e0def5dc1f4c708bc92178e7a7c","unresolved":true,"context_lines":[{"line_number":252,"context_line":"  **Patches:**"},{"line_number":253,"context_line":""},{"line_number":254,"context_line":"  Fixes are under review in the Keystone project. Gerrit review links will be"},{"line_number":255,"context_line":"  added here as changes are published."},{"line_number":256,"context_line":""},{"line_number":257,"context_line":"credits:"},{"line_number":258,"context_line":"  - Grzegorz Grasza, Red Hat"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"5dae47cf_40792979","line":255,"updated":"2026-09-22 15:08:11.000000000","message":"We usually post the reviews when they are up, or even a link to a hashtag that would be on all the changes. I assume since this is WIP though that we intend on having the patches ready/linked before advisory?","commit_id":"8dfa7c0b0bbfd334c9d8d68fae9181da6d365132"},{"author":{"_account_id":14250,"name":"Grzegorz Grasza","email":"xek@redhat.com","username":"xek"},"change_message_id":"f59c97a6b1d611978ac903d70ef079b1bceea032","unresolved":true,"context_lines":[{"line_number":252,"context_line":"  **Patches:**"},{"line_number":253,"context_line":""},{"line_number":254,"context_line":"  Fixes are under review in the Keystone project. Gerrit review links will be"},{"line_number":255,"context_line":"  added here as changes are published."},{"line_number":256,"context_line":""},{"line_number":257,"context_line":"credits:"},{"line_number":258,"context_line":"  - Grzegorz Grasza, Red Hat"}],"source_content_type":"text/x-yaml","patch_set":1,"id":"777507c6_d183e606","line":255,"in_reply_to":"5dae47cf_40792979","updated":"2026-09-24 10:50:02.000000000","message":"I added the keystone changes, right now I\u0027m working on","commit_id":"8dfa7c0b0bbfd334c9d8d68fae9181da6d365132"}]}
