Duplicate users (federated and sql) results in 401
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
Expired
|
High
|
Unassigned |
Bug Description
Release: Mitaka
I setup federation (saml2) with a product called vIDM which automatically has a user named "admin". I also have keystone configured to use a sql backend and have a user named "admin". These users exist on different domains (Federated) and (default), and have different user_ids, yet I cannot login with this federated user without a hard error:
2017-01-05 21:59:56.448 19546 DEBUG keystone.
2017-01-05 21:59:56.448 19546 DEBUG keystone.
2017-01-05 21:59:56.482 19546 WARNING keystone.
tags: | added: federation |
Changed in keystone: | |
assignee: | nobody → David Stanek (dstanek) |
Changed in keystone: | |
assignee: | David Stanek (dstanek) → Eric Brown (ericwb) |
root@controller 02:/home/ viouser# openstack user list --long ------- ------- ------- ------- +------ ------- ------+ ------- ------- ------- ------- ------+ ------- ------- ------- ------- ------+ ------- ------+ ------- +------ ---+ ------- ------- ------- ------- +------ ------- ------+ ------- ------- ------- ------- ------+ ------- ------- ------- ------- ------+ ------- ------+ ------- +------ ---+ bb3068256e0cc5c cd | browne | | None | | | True | 8bc1fa32ebfb4d1 79 | cinder | ceabb23c085a4bd d80d870efad1aab 3b | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | 4a3bc460c11a034 b5 | vio-service | ceabb23c085a4bd d80d870efad1aab 3b | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | e89adb06b3fbf06 c7 | nova | ceabb23c085a4bd d80d870efad1aab 3b | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | ca6b8f50a68a930 6b | ericwb | 8e67167398e7448 8a045b403a44dd3 26 | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | 987d12438c7163e 8a | neutron | ceabb23c085a4bd d80d870efad1aab 3b | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | 5b9785ce2496fc9 75 | glance | ceabb23c085a4bd d80d870efad1aab 3b | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | da1b8e1a93cbc40 d1 | heat | ceabb23c085a4bd d80d870efad1aab 3b | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | 2a4ca72ad021336 2c | vio-service | | default | | | True | 0ab7992bdbeb1f8 77 | admin | | None | | | True | 0940a29287c06a1 30 | admin | 701b5fafaf0f470 eb77749ab086971 4d | default | | | True | 9bacfa6b6283f42 61 | heat_domain_admin | | 4d216d7412ef475 99e42a4c829ada9 05 | | | True | dba5b37102586ad 78 | ericwb | 701b5fafaf0f470 eb77749ab086971 4d | default | | | True | ------- ------- ------- ------- +------ ------- ------+ ------- ------- ------- ------- ------+ ------- ------- ------- ------- ------+ ------- ------+ ------- +------ ---+
Password:
+------
| ID | Name | Project | Domain | Description | Email | Enabled |
+------
| 0ad39c049606490
| 2abd39636fe14d2
| 2cb443b8fbf8457
| 3afb280b434348c
| 527dde44764d4f3
| 5edfe02f8bb7403
| 7c0f4e167b70498
| 8ba3a407d0b6448
| 907f97ca68f94d2
| 9b2dde9538864fc
| e38f2348129a41d
| e916b1a1f79944c
| f90cb7cb04074d0
+------