[openstack-dev] [keystone] Support for external authentication (i.e. REMOTE_USER) in Havana

Jamie Lennox jamielennox at redhat.com
Wed Oct 30 23:17:57 UTC 2013


On Wed, 2013-10-30 at 10:27 +0100, Álvaro López García wrote:
> Hi Tim.
> 
> On Tue 29 Oct 2013 (16:18), Tim Bell wrote:
> > 
> > We also need some standardisation on the command line options for the client portion (such as --os-auth-method, --os-x509-cert etc.) . Unfortunately, this is not yet in Oslo so there would be multiple packages to be enhanced.
> 
> I totally agree. We need a common pluggable authentication mechanism
> for the clients (since Keystone supports it, the clients should support
> it). I improved the simple system that was in novaclient [1], but it should
> be moved to keystone client. There was some movement to port this to [2]
> but the change was abandoned in favour of a more complex solutions: one
> that never came in (oslo [3]) and another from Jamie Lennox in [4] that
> is still a WIP.
> 
> [1] https://review.openstack.org/#/c/23820/
> [2] https://review.openstack.org/#/c/36427/
> [3] https://review.openstack.org/#/c/28043/
> [4] https://blueprints.launchpad.net/python-keystoneclient/+spec/auth-plugins
> 
> Regards, 

Completely agree, we're working on this but it's currently postponed
until we've had a chance to discuss it at the summit. 





More information about the OpenStack-dev mailing list