Re: [Freeipa-devel] FreeIPA and Dogtag support for User Certificates in OpenStack Keystone

2013-08-27 Thread Ade Lee
On Mon, 2013-08-26 at 12:38 -0400, Adam Young wrote: Keystone needs signing certificates for Signing PKI tokens. In addition, CERN has a developed an approach that allows user to authenticate to Keystone via X509 for batch jobs. This requires Client Certs. Both of these use cases are

[Freeipa-devel] FreeIPA and Dogtag support for User Certificates in OpenStack Keystone

2013-08-26 Thread Adam Young
Keystone needs signing certificates for Signing PKI tokens. In addition, CERN has a developed an approach that allows user to authenticate to Keystone via X509 for batch jobs. This requires Client Certs. Both of these use cases are easily supported by Dogtag, but not exposed via FreeIPA