Hi,

Suppose I have an application X currently managed through FreeIPA LDAP
(that application query directly freeIPA LDAP).
Suppose I also have an enterprise IdP for SAML communication.
My application is used by another application Y that is customer facing and
uses impersonation. At some point needs to retrieve groups for the end-user
(hence the LDAP query).
Now I want to move all my auth authz workflow to SAML. My problem is that
if I do that, my local LDAP DB is not populated with my enterprise IdP
users and groups and my distant IdP can't be queried in LDAP by my
application X so I can't retrieve my group.
Is there a way to make this workflow work using some functionality in
FreeIPA ?
X = Hdfs
Y = any application that gives access to hdfs data for example Dataiku

Regards,
Ivan
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to