Federated Identity via WebSSO
Summary:
Support federated identity in Keystone.
Motivation:
Keystone is pushing for federated identity via websso, and will most likely land in late Kilo. We need to ensure this feature is supported in Horizon (more specifically DOA).
Description:
This Keystone spec below describes the process in detail. Keystone will do most of the heavy lifting.
From Horizon stand point, we just need to provide a mechanism that would allow users to authenticate via websso or via credentials.
Link to spec: https:/
Work done by CERN we can build on:
https:/
UX:
Users can select a preferred authentication method via a drop-down:
1. Via websso
2. Via credentials
Sample screen from Jeff Calcaterra:
https:/
Outside Dependencies:
N/A
Requirements Update Required:
N/A
Doc Impact:
N/A
Blueprint information
- Status:
- Complete
- Approver:
- David Lyle
- Priority:
- High
- Drafter:
- Thai Tran
- Direction:
- Approved
- Assignee:
- Thai Tran
- Definition:
- Approved
- Series goal:
- Accepted for kilo
- Implementation:
- Implemented
- Milestone target:
- 2015.1.0
- Started by
- Thai Tran
- Completed by
- Lin Hua Cheng
Related branches
Related bugs
Sprints
Whiteboard
Gerrit topic: https:/
Addressed by: https:/
login websso
NEEDS REVIEW
Gerrit topic: https:/
[david-lyle | 2015-03-18] Moving out of Kilo. This doesn't feel quite ready and I would like to see a better defined auth plugin system in django_
Work Items
Dependency tree
* Blueprints in grey have been implemented.