Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1092744 (ovirt-aaa-sso)

Summary: [RFE][AAA] Introduce uniform login services
Product: [oVirt] ovirt-engine Reporter: Alon Bar-Lev <alonbl>
Component: RFEsAssignee: Ravi Nori <rnori>
Status: CLOSED CURRENTRELEASE QA Contact: Gonza <grafuls>
Severity: medium Docs Contact:
Priority: medium    
Version: ---CC: bazulay, bugs, iheim, juwu, mgoldboi, movciari, oourfali, pstehlik, rbalakri, redhat, srevivo, trichard
Target Milestone: ovirt-4.0.0-betaKeywords: FutureFeature, Improvement
Target Release: 4.0.0Flags: rule-engine: ovirt-4.0.0+
grafuls: testing_plan_complete+
mgoldboi: planning_ack+
oourfali: devel_ack+
pstehlik: testing_ack+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
With this release, a single sign on module has been added that authenticates the user once, and allows access to both the Administration Portal and User Portal. Signing off from one portal closes the session on SSO and the user is logged out of all portals.
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-08-01 12:29:22 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Infra RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 956226, 975730, 1019921, 1164300, 1164302, 1285883, 1285885, 1285887    
Bug Blocks: 1037844, 1104107, 1425415    

Description Alon Bar-Lev 2014-04-29 21:17:48 UTC
CURRENT IMPLEMENTATION

Each webapp has its own login services, the shared bit is the j2ee session id.

Client side login implementation exists at client side at webadmin and userportal.

Single signon with jasper is incomplete, as no role transfer exist, so admin user should access the jasper directly.

API supports only subset of authentication mechanisms.

PROBLEMS IN CURRENT IMPLEMENTATION

Logic of login is distributed among several applications.

Implementation of challenges, password change is to be duplicated as well.

Accessing services on different servers is not supported as the j2ee session id cannot be shared.

Multiple identity in case of the Jasper interaction.

NEW IMPLEMENTATION

Single service webapp to perform authentication and authorization. All applications will interact with this service to perform authentication using either backend request or http redirect.

If no good reason, implementation should be based on saml[1], there are java implementations[2], we can use these if are doing at least 80% of the implementation and we use at least 80% of their implementation.

Authn and Authz should be done within the service, passing the entire principal record into application.

The webapp implementation can be implemented as negotiate authn, this means that we should split the extension list into each application.

REQUIREMENTS

1. Modify the jasper filter to be able to set roles.
2. Add roles to users:
a. Login to application X
b. Jasper admin

WISH

Limit the usage of users and groups table within engine, rely solely on the information obtained during login.

Move authz sync code to aaa service, or better remove it completely.

[1] http://en.wikipedia.org/wiki/SAML_2.0
[2] https://wiki.shibboleth.net/confluence/display/OpenSAML/Home

Comment 1 Itamar Heim 2014-09-29 07:43:27 UTC
while the current SSO for VM isn't a great solution, we need to find a way to allow kerberos only to webadmin (and API), while allowing non kerberized login to user portal for the SSO to continue working.
not sure if this RFE prevents this.

Comment 2 Oved Ourfali 2014-09-29 11:00:04 UTC
(In reply to Itamar Heim from comment #1)
> while the current SSO for VM isn't a great solution, we need to find a way
> to allow kerberos only to webadmin (and API), while allowing non kerberized
> login to user portal for the SSO to continue working.
> not sure if this RFE prevents this.

Are there plans to improve that to be supported in the spice level rather than via the engine? Or any other plans to make it in a better way?

Comment 3 Itamar Heim 2015-05-06 14:40:24 UTC
(In reply to Oved Ourfali from comment #2)
> (In reply to Itamar Heim from comment #1)
> > while the current SSO for VM isn't a great solution, we need to find a way
> > to allow kerberos only to webadmin (and API), while allowing non kerberized
> > login to user portal for the SSO to continue working.
> > not sure if this RFE prevents this.
> 
> Are there plans to improve that to be supported in the spice level rather
> than via the engine? Or any other plans to make it in a better way?

please discuss with michal and david blechter

Comment 4 Moran Goldboim 2015-07-20 13:11:01 UTC
moving to 4.0, wasn't delivered feature freeze

Comment 5 Red Hat Bugzilla Rules Engine 2015-10-19 11:03:19 UTC
Target release should be placed once a package build is known to fix a issue. Since this bug is not modified, the target version has been reset. Please use target milestone to plan a fix for a oVirt release.

Comment 7 Mike McCune 2016-03-28 23:29:58 UTC
This bug was accidentally moved from POST to MODIFIED via an error in automation, please see mmccune with any questions

Comment 8 Sandro Bonazzola 2016-05-02 09:57:58 UTC
Moving from 4.0 alpha to 4.0 beta since 4.0 alpha has been already released and bug is not ON_QA.

Comment 9 Gonza 2016-07-18 09:32:31 UTC
Verified with:
rhevm-4.0.0.5-0.1.el7ev.noarch