can a service provider validate an authorization delegation?
Robert Duncan
Robert.Duncan at ncirl.ie
Thu Feb 2 06:17:21 EST 2017
Thanks John,
I was aware that this is something that needs to be fixed in keystone, and it needs to work with *all* federated users, at the moment it doesn't work with *any*. Although, we can use keystone as an idp now, which is great!
Rob.
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of John Dennis
Sent: Wednesday 1 February 2017 18:55
To: Shib Users <users at shibboleth.net>
Subject: Re: can a service provider validate an authorization delegation?
On 02/01/2017 12:41 PM, Robert Duncan wrote:
> Thanks Scott,
>
> I only ask because I'm subscribed to a bug in OpenStack detailing this scenario, now it looks like this type of delegated authorization is causing concerns/issues.
> https://bugs.launchpad.net/keystone/+bug/1600366
>
> OpenStack administrators won't always control the SP I suppose - but
> possibly some sort of conditional check could be baked in to keystone
> https://wiki.openstack.org/wiki/Keystone
>
> Perhaps if you had the time you could chime in with some thoughts - I think someone with your level of insight into federated AuthN would be extremely useful, I am not a contributor but would like for it to work.
I do development work in Keystone and also SAML. The problem you cite in bug 1600366 is not a SAML issue. The problem is in the architecture of Keystone which treats federated users differently than "local" users.
This is very clearly outlined in the bug. The solution need to occur in Keystone. Don't forget SAML is only one of several possible federation schemes in OpenStack, the solution has to address *all* federated users.
--
John
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
The information contained and transmitted in this e-mail is confidential information, and is intended only for the named recipient to which it is addressed. The content of this e-mail may not have been sent with the authority of National College of Ireland. Any views or opinions presented are solely those of the author and do not necessarily represent those of National College of Ireland. If the reader of this message is not the named recipient or a person responsible for delivering it to the named recipient, you are notified that the review, dissemination, distribution, transmission, printing or copying, forwarding, or any other use of this message or any part of it, including any attachments, is strictly prohibited. If you have received this communication in error, please delete the e-mail and destroy all record of this communication. Thank you for your assistance.
________________________________
More information about the users
mailing list