Re: [openstack-dev] [Keystone][Oslo] User mapping and X509 for signing

2014-10-09 Thread John Dennis
On 10/08/2014 04:58 PM, Adam Young wrote: When gyee posted his X509 server-side auth plugin patch, the feedback we gave was that it should be using the mapping code from Federation to transform the environment variables set by the web server to the Keystone userid, username, domain name,

Re: [openstack-dev] [Keystone][Oslo] User mapping and X509 for signing

2014-10-09 Thread Adam Young
On 10/09/2014 09:31 AM, John Dennis wrote: On 10/08/2014 04:58 PM, Adam Young wrote: When gyee posted his X509 server-side auth plugin patch, the feedback we gave was that it should be using the mapping code from Federation to transform the environment variables set by the web server to the

[openstack-dev] [Keystone][Oslo] User mapping and X509 for signing

2014-10-08 Thread Adam Young
When gyee posted his X509 server-side auth plugin patch, the feedback we gave was that it should be using the mapping code from Federation to transform the environment variables set by the web server to the Keystone userid, username, domain name, and so forth. The PKI token format currently