Description of problem: Customers wanting to do SAML federation using the methodology Red Hat documents need to have the mod_auth_mellon package available in the Keystone container. Today, integration can be done with a customized image, but it would be nice to have this in the stock container image. Version-Release number of selected component (if applicable): Image tag 12.0-20180405.1 Do we want to force customers to build custom images for procedures like SAML federation that we have documented? My preference is to have the package in the stock image, but this could also be a documentation item instead.
Just for additional context: we hit this during FFWD upgrade testing with non-default keystone configs.
*** Bug 1573316 has been marked as a duplicate of this bug. ***
This bugzilla has been removed from the release since it has not been triaged, and needs to be reviewed for targeting another release.
Ozz, didn't you add mod_auth_mellon to the package set a while ago?
I did add them to the kolla templates, however, I am unsure if we're carrying this package in the downstream dockerfile. Apparently we don't directly use kolla downstream, but instead we carry dockerfiles based on what was generated by kolla (at some point)... so we need to double check if that package was added to our downstream file (I don't know where that is).
I see the package in the 13.0-54 tag of the OSP13 Keystone container image.
Adding FIV per comment #14 and moving bug to MODIFIED.
Currently released build in NVR openstack-keystone-base-container-13.0-60
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2019:0072