wsgi generating wrong entity_id values when issuing saml assertions.

Bug #1374033 reported by Marek Denis
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Fix Released
Medium
Marek Denis

Bug Description

Attribute issuer should always be set to CONF.saml.idp_entity_id, otherwise entityID from the IdP metadata and the generated assertion can differ and hence make Service Provider reject the assertion.

Changed in keystone:
assignee: nobody → Marek Denis (marek-denis)
Changed in keystone:
importance: Undecided → Medium
status: New → Triaged
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to keystone (master)

Fix proposed to branch: master
Review: https://review.openstack.org/124176

Changed in keystone:
status: Triaged → In Progress
tags: added: federation juno-rc-potential
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to keystone (master)

Reviewed: https://review.openstack.org/124176
Committed: https://git.openstack.org/cgit/openstack/keystone/commit/?id=62099029e9c794c5bc4a780fe34fd51ebffee6e1
Submitter: Jenkins
Branch: master

commit 62099029e9c794c5bc4a780fe34fd51ebffee6e1
Author: Marek Denis <email address hidden>
Date: Thu Sep 25 22:17:00 2014 +0200

    Set issuer value to CONF.saml.idp_entity_id.

    When generating SAML assertion Keystone should always set issuer value
    in federation.controllers.Auth.create_saml_assertion() to
    CONF.saml.idp_entity_id.

    Change-Id: If970cdf20cfca8b1dc667eefd030083fdafe9424
    Closes-Bug: #1374033

Changed in keystone:
status: In Progress → Fix Committed
Changed in keystone:
milestone: none → juno-rc1
Thierry Carrez (ttx)
Changed in keystone:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in keystone:
milestone: juno-rc1 → 2014.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.