Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1413753

Summary: Invalid Accept HTTP header generated during ECP flow
Product: Red Hat OpenStack Reporter: John Dennis <jdennis>
Component: python-keystoneauth1Assignee: John Dennis <jdennis>
Status: CLOSED CURRENTRELEASE QA Contact: Shai Revivo <srevivo>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 11.0 (Ocata)CC: apevec, jschluet, lhh, nkinder, rhos-maint, srevivo
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: python-keystoneauth1-2.18.0-1.el7ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1413751 Environment:
Last Closed: 2017-06-07 17:34:36 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1413751    
Bug Blocks:    

Description John Dennis 2017-01-16 21:37:18 UTC
+++ This bug was initially created as a clone of Bug #1413751 +++

During SAML ECP authentication 2 specially formatted HTTP headers *MUST* be included in the request in order for the SP (Service Provider) to recognize the client is ECP capable and to start the SAML ECP flow. One is the PAOS header and the other is the Accept header which must include the "application/vnd.paos+xml" media type. Media types in the Accept header are separated by a comma (,). Unfortunately keystoneauth uses a semicolon (;) as the media type separator. The HTTP spec reserves the semicolon in the Accept header to attach parameters to the media type. For example

Accept: type1;params1,type2;params2

Using a semicolon as a media type separator is syntactically invalid and can cause failures in servers that parse the Accept header. For example mod_auth_mellon emits this error message and fails to process the ECP request:

request supplied valid PAOS header but omitted PAOS media type in Accept header
have_paos_media_type=False valid_paos_header=True is_paos=False

This indicates only 1 of the 2 required conditions were met.

Comment 1 Nathan Kinder 2017-06-07 17:34:36 UTC
This was fixed in the initial 2.18.0 release upstream, which is the version that was shipped for OSP11.  Closing this as CURRENTRELEASE.