Bug 2185640 - [RFE] SAML2 and Federation Support
Summary: [RFE] SAML2 and Federation Support
Keywords:
Status: NEW
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-keystone
Version: 16.2 (Train)
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: ---
Assignee: Douglas Mendizábal
QA Contact: Jeremy Agee
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-04-10 17:22 UTC by jhardee
Modified: 2023-08-09 14:44 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker OSP-24075 0 None None None 2023-04-10 17:23:23 UTC

Description jhardee 2023-04-10 17:22:42 UTC
Description of problem:
SAML2 and Federation Support on RHOSP

Version-Release number of selected component (if applicable):
OpenStack 17.x

How reproducible:
N/A

Steps to Reproduce:
1.
2.
3.

Actual results:
IT-Sec would like to enable SSO/Federation support on RHOSP


Expected results:
IT-Sec would like to enable SSO/Federation support on RHOSP

Additional info:
We see that SAML and Federation Support is only for lab settings and not for production stack envrionment [1] 

I would like to implement SSO by SAML2 or Federation as per the upstream doc. https://docs.openstack.org/keystone/pike/admin/federated-identity.html


[1] https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/16.1/html/federate_with_identity_service/introduction

Comment 6 jhardee 2023-07-14 13:27:19 UTC
Hi Team,

Is there any support for SSO or SAML2/federation support on RHOSP in production environment in the future?

In the doc for 16.2, I see the warning "Red Hat does not support federation at this time. This feature should only be used for testing, and should not be deployed in a production environment."

Comment 7 jhardee 2023-07-19 15:14:29 UTC
Hi Team,

I wanted to see if there's any update I can pass along to the customer on this issue?

Comment 9 jhardee 2023-08-09 14:44:36 UTC
Hi Team,

I know with OpenStack 16 we do no support federation. This feature should only be used for testing, and should not be deployed in a production environment.

With future version of OpenStack are you still not going to support federation or is this something we will support in the future?


Note You need to log in before you can comment on or make changes to this bug.