Bug 1380874 - RFE: Keystone should be able to handle nested groups within Active Directory domains
Summary: RFE: Keystone should be able to handle nested groups within Active Directory ...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-keystone
Version: 8.0 (Liberty)
Hardware: x86_64
OS: Linux
unspecified
high
Target Milestone: ---
: ---
Assignee: Adam Young
QA Contact: nlevinki
URL:
Whiteboard:
Depends On:
Blocks: 1385438 1385439
TreeView+ depends on / blocked
 
Reported: 2016-09-30 21:48 UTC by nalmond
Modified: 2021-08-30 12:05 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 1385438 (view as bug list)
Environment:
Last Closed: 2017-01-16 20:11:15 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 2788301 0 None None None 2016-12-01 02:55:28 UTC

Description nalmond 2016-09-30 21:48:54 UTC
- What is the nature and description of the request? 
Keystone should be able to list and authenticate with Active Directory users that are members of a subgroup of a higher level group. If the upper group has a given role, users that are members of groups below (but not the upper group directly) should also have the same roles.

- Why does the customer need this? (List the business requirements here) 
To integrate with an existing Active Directory server and allow users to authenticate based on permissions set across a broad scope of groups.

- How would the customer like to achieve this? (List the functional requirements here) 

Add support in keystone to correctly perform ldap queries that require memberof:1.2.840.113556.1.4.1941: as part of the query.

- For each functional requirement listed, specify how Red Hat and the customer can test to confirm the requirement is successfully implemented.

'openstack user list --domain AD --group subgroup' should list all users that are members of the group 'subgroup', not just those that are also members of the parent group.

- Is there already an existing RFE upstream or in Red Hat Bugzilla?
no


Note You need to log in before you can comment on or make changes to this bug.