[Openstack] best practise to add SAML into keystone deployment and keep local auth?

Don Waterloo don.waterloo at gmail.com
Fri Nov 14 14:32:14 UTC 2014


I have a system (juno/ubuntu 14.10) which currently has keystone as the
master of the
universe for identity and authentication.
By convention, each user of my system is also a tenant, which is my intent
to continue.
My system is used by a combination of our team members, but also by 3rd
parties
(e.g. we use it for training on our products).

I would like to make our saml system authoritative for identity/auth for the
team members, but leave keystone authoritative for 3rd parties.

Is there any documentation on someone who has such a system, or, is there
any recommended best practises to follow?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack/attachments/20141114/7c3c14ab/attachment.html>


More information about the Openstack mailing list