Bug 1263012 - [RFE] New attributes for SAML Assertion generated by keystone IdP
Summary: [RFE] New attributes for SAML Assertion generated by keystone IdP
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-keystone
Version: 8.0 (Liberty)
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: beta
: 8.0 (Liberty)
Assignee: Nathan Kinder
QA Contact: Rodrigo Duarte
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-09-14 22:00 UTC by Nathan Kinder
Modified: 2023-02-22 23:02 UTC (History)
7 users (show)

Fixed In Version: openstack-keystone-8.0.0-1.el7ost
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-04-07 21:08:22 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2016:0603 0 normal SHIPPED_LIVE Red Hat OpenStack Platform 8 Enhancement Advisory 2016-04-08 00:53:53 UTC

Description Nathan Kinder 2015-09-14 22:00:59 UTC
From upstream blueprint (https://blueprints.launchpad.net/keystone/+spec/assertion-extra-attributes):

"Currently, SAML assertions generated by a keystone Identity Provider only return three attributes: openstack_user, openstack_project and openstack_roles. It's known that users and projects don't have unique names in different domains, for this reason we need the user domain and project domain information in order to unique identify this entities when mapping them in a keystone Service Provider."

This is just a minor addition to the SAML assertion contents that is used with K2K federation.  It should be easy to verify the contents of the assertion to see that the new data is provided once K2K is set up.

Comment 6 Rodrigo Duarte 2016-01-28 13:30:51 UTC
Verified for "openstack-keystone-8.0.0-1.el7ost"

Comment 9 errata-xmlrpc 2016-04-07 21:08:22 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHEA-2016-0603.html


Note You need to log in before you can comment on or make changes to this bug.