Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6677

Enable STS support for ACS in AWS

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • None
    • None
    • False
    • None
    • False

      1. Proposed title of this feature request
      Enable AWS STS support for ACS in AWS

      2. What is the nature and description of the request?
      Enable AWS STS support for ACS in AWS.

      3. Why does the customer need this? (List the business requirements here)
      Security conscious customers want to minimize the possibility of mis-use of tokens. AWS STS provides temporary security credentials. 

      • "Temporary security credentials are short-term, as the name implies. They can be configured to last for anywhere from a few minutes to several hours. After the credentials expire, AWS no longer recognizes them or allows any kind of access from API requests made with them."
      • "Temporary security credentials are not stored with the user but are generated dynamically and provided to the user when requested. When (or even before) the temporary security credentials expire, the user can request new credentials, as long as the user requesting them still has permissions to do so."

      4. List any affected packages or components.
      ACS
      AWS STS

      https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html 

      https://docs.openshift.com/container-platform/4.10/authentication/understanding-identity-provider.html

      https://docs.openshift.com/container-platform/4.11/authentication/managing_cloud_provider_credentials/cco-mode-sts.html 

              atelang@redhat.com Anjali Telang
              knewcome@redhat.com Kirsten Newcomer
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: