Single Sign on Users must have an identity in keystone

Bug #1593362 reported by Sachin
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Identity (keystone)
Expired
Undecided
Unassigned

Bug Description

Single sign on (SSO) users from an external identity provider (IDP) are mapped to keystone group/user with a mapping rule. The identity of such a user is lost in context of OpenStack. Once the operation makes it to OpenStack services, only group is available in the context. This poses multiple problems
1. The owners of various objects like VMs, Volumes, Networks are not identifiable as that specific SSO user.
2. The user-quota api for various projects like nova, cinder and neutron does not work.

Revision history for this message
Steve Martinelli (stevemar) wrote :

So this was mostly solved in Mitaka and we will continue to work on this issue in Newton. The shadow users spec is now storing all federated users in a keystone database (https://blueprints.launchpad.net/keystone/+spec/shadow-users), we will start allowing individual role assignments to these users in Newton (https://blueprints.launchpad.net/keystone/+spec/shadow-users-newton)

Revision history for this message
Steve Martinelli (stevemar) wrote :

If it's alright with you, I'd prefer to mark this bug as invalid since we are tracking the blueprints

Revision history for this message
Dolph Mathews (dolph) wrote :

Marking this as incomplete unless there are additional specifics beyond what is tracked in the shadow users specs that should cause this bug to remain open.

Changed in keystone:
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for OpenStack Identity (keystone) because there has been no activity for 60 days.]

Changed in keystone:
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.