[openstack-dev] [keystone][puppet] Federation using ipsilon

Adam Young ayoung at redhat.com
Sat Jun 13 01:30:19 UTC 2015


On 06/12/2015 04:53 PM, Rich Megginson wrote:
> I've done a first pass of setting up a puppet module to configure 
> Keystone to use ipsilon for federation, using 
> https://github.com/richm/puppet-apache-auth-mods, and a version of 
> ipsilon-client-install with patches 
> https://fedorahosted.org/ipsilon/ticket/141 and 
> https://fedorahosted.org/ipsilon/ticket/142, and a heavily modified 
> version of the ipa/rdo federation setup scripts - 
> https://github.com/richm/rdo-vm-factory.
>
> I would like some feedback from the Keystone and puppet folks about 
> this approach.
>
> __________________________________________________________________________ 
>
> OpenStack Development Mailing List (not for usage questions)
> Unsubscribe: 
> OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev

I take it this is not WebSSO yet, but only Federation.

Around here...

https://github.com/richm/puppet-apache-auth-mods/blob/master/manifests/keystone_ipsilon.pp#L64

You would need to have the trusted dashboard, etc.

But I think that is what you intend.  However, without an ECP setup, we 
really have no way to test it.



More information about the OpenStack-dev mailing list