Bug 987684 - [RFE] Keystone with Kerberos authentication
Summary: [RFE] Keystone with Kerberos authentication
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-keystone
Version: 4.0
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: Upstream M3
: 4.0
Assignee: Adam Young
QA Contact: Jeremy Agee
URL: http://docs.openstack.org/developer/k...
Whiteboard:
Depends On: 988935
Blocks: RHOS40RFE
TreeView+ depends on / blocked
 
Reported: 2013-07-23 21:36 UTC by Adam Young
Modified: 2016-04-27 04:35 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-12-20 00:15:04 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2013:1859 0 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform Enhancement Advisory 2013-12-21 00:01:48 UTC

Description Adam Young 2013-07-23 21:36:23 UTC
Configure Keystone to run in Apache HTTPD and requires Kerberos authentication 
(RH IdM is the simplest means)

Comment 1 Dmitri Pal 2013-07-23 21:47:57 UTC
How to test: use keystone with Apache mod_auth_krb5.

Comment 3 Adam Young 2013-07-31 23:24:15 UTC
This is a refinement of an earlier blueprint for handling REMOTE_USER, specific to using Kerberos.  The upstream commit was https://github.com/openstack/keystone/commit/e276d142541e2517484e5bc539a19a5495a1c679  but we did not explicitly test it.

Comment 4 Jeremy Agee 2013-11-26 22:15:53 UTC
Tests verified however when PKI tokens are in use BZ1035032 occurs for v3 token request.

Comment 6 Jeremy Agee 2013-12-10 16:28:00 UTC
for v3 test cases requesting pki tokens without the catalog. This is a workaround for the following issue that is unrelated to this feature.

https://bugzilla.redhat.com/show_bug.cgi?id=1035032

Tests passed

Comment 8 errata-xmlrpc 2013-12-20 00:15:04 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHEA-2013-1859.html


Note You need to log in before you can comment on or make changes to this bug.