Current Series Release Notes

30.0.0-4

New Features

  • Keystone now transparently upgrades stored password hashes on successful authentication when the stored hash uses a different algorithm than [identity] password_hash_algorithm, or a weaker work factor than the currently configured value. This applies to bcrypt, bcrypt_sha256, scrypt, and PBKDF2-SHA512. Operators can raise password_hash_rounds or change algorithm without requiring users to reset their passwords. The rehash preserves password metadata (created_at, expires_at, history) and only updates the hash itself. See the administrator guide on password hashing for details.

Upgrade Notes

  • The deprecated [oslo_policy] enforce_scope configuration option has been removed in oslo.policy version 6.0.0 which will impact Keystone as there is no longer any way to disable RBAC policy scope enforcement; scope checks are now always enforced regardless of configuration.

    If you are not upgrading the oslo.policy to 6.0.0, then there will not be any change in scope enforcement behaviour.