Re: [openstack-dev] [Horizon][Keystone] Steps toward Kerberos and Federation

2014-09-05 Thread Marco Fargetta
Hi, I am wondering if the solution I was trying to sketch with the spec https://review.openstack.org/#/c/96867/13; is not easier to implement and manage then the steps highlated till n.2. Maybe, the spec is not yet there and should be improved (I will abandon or move to Kilo as Marek suggest) but

[openstack-dev] [keystone] SAML consumption Blueprints

2014-02-20 Thread Marco Fargetta
Dear all, I am interested to the integration of SAML with keystone and I am analysing the following blueprint and its implementation: https://blueprints.launchpad.net/keystone/+spec/saml-id https://review.openstack.org/#/c/71353/ Looking at the code there is something I cannot undertand. In

Re: [openstack-dev] [keystone] SAML consumption Blueprints

2014-02-21 Thread Marco Fargetta
Hi Dolph, On 21 Feb 2014, at 03:05, Dolph Mathews dolph.math...@gmail.com wrote: On Thu, Feb 20, 2014 at 4:18 AM, Marco Fargetta marco.farge...@ct.infn.it wrote: Dear all, I am interested to the integration of SAML with keystone and I am analysing the following blueprint and its

Re: [openstack-dev] [all][keystone] Increase of USER_ID length maximum from 64 to 255

2014-02-26 Thread Marco Fargetta
-- Eng. Marco Fargetta, PhD Istituto Nazionale di Fisica Nucleare (INFN) Catania, Italy EMail: marco.farge...@ct.infn.it smime.p7s Description: S/MIME cryptographic signature

Re: [openstack-dev] Replication multi cloud

2014-03-13 Thread Marco Fargetta
with different keystones and administrative domains. Is this possible with the current replication facilities or they should stay in the same cloud sharing the keystone? Cheers, Marco -- Eng. Marco Fargetta, PhD Istituto

Re: [openstack-dev] Replication multi cloud

2014-03-13 Thread Marco Fargetta
there). Chmouel On Thu, Mar 13, 2014 at 5:25 PM, Marco Fargetta marco.farge...@ct.infn.itwrote: Thanks Donagh, I will take a look to the ontainer-to-container synchronization to understand if it fits with my scenario. Cheers, Marco On Thu, Mar 13, 2014 at 03:28:03PM +

Re: [openstack-dev] [Keystone][Horizon] Proposed Changed for Unscoped tokens.

2014-07-07 Thread Marco Fargetta
://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev -- Eng. Marco Fargetta, PhD Istituto Nazionale di Fisica Nucleare (INFN) Catania, Italy EMail: marco.farge...@ct.infn.it smime.p7s

Re: [openstack-dev] [Keystone][Horizon] Proposed Changed for Unscoped tokens.

2014-07-07 Thread Marco Fargetta
3. Unscoped tokens should be very short lived: 10 minutes. Unscoped tokens should be infinitely extensible: If I hand an unscoped token to keystone, I get one good for another 10 minutes. Using this time limit horizon should extend all the unscoped token every x min (with x 10). Is

Re: [openstack-dev] [keystone][federation] Coordination for Juno

2014-05-27 Thread Marco Fargetta
Hi All, • Federated Keystone and Horizon □ Completely open-ended, there isn't much an expectation that we deliver this in Juno, but it's something we should start thinking about. □ I have just registered a new blueprint for this point:

Re: [openstack-dev] [keystone][federation] Coordination for Juno

2014-05-27 Thread Marco Fargetta
On Tue, May 27, 2014 at 07:39:01AM -0500, Dolph Mathews wrote: On Tue, May 27, 2014 at 6:30 AM, Marco Fargetta marco.farge...@ct.infn.itwrote: Hi All, • Federated Keystone and Horizon □ Completely open-ended, there isn't much an expectation that we deliver

Re: [openstack-dev] [keystone] Redesign of Keystone Federation

2014-05-28 Thread Marco Fargetta
mailing list OpenStack-dev@lists.openstack.org http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev -- Eng. Marco Fargetta, PhD Istituto Nazionale di Fisica Nucleare (INFN) Catania, Italy EMail: marco.farge...@ct.infn.it

Re: [openstack-dev] [keystone][federation] Coordination for Juno

2014-05-30 Thread Marco Fargetta
: On Tue, May 27, 2014 at 8:12 AM, Marco Fargetta marco.farge...@ct.infn.itwrote: On Tue, May 27, 2014 at 07:39:01AM -0500, Dolph Mathews wrote: On Tue, May 27, 2014 at 6:30 AM, Marco Fargetta marco.farge...@ct.infn.itwrote: Hi All, • Federated Keystone and Horizon

Re: [openstack-dev] [Keystone] Bug in federation

2014-12-24 Thread Marco Fargetta
/mailman/listinfo/openstack-dev ___ OpenStack-dev mailing list OpenStack-dev@lists.openstack.org http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev Eng. Marco Fargetta, PhD Istituto

Re: [openstack-dev] [Keystone] Bug in federation

2014-12-24 Thread Marco Fargetta
. regards david On 24/12/2014 10:19, Marco Fargetta wrote: Hi All, this bug was already reported and fixed in two steps: https://bugs.launchpad.net/ossn/+bug/1390124 The first step is in the documentation. There should be also an OSS advice for previous version of OpenStack

Re: [openstack-dev] [Keystone] Bug in federation

2014-12-24 Thread Marco Fargetta
list OpenStack-dev@lists.openstack.org http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev Eng. Marco Fargetta, PhD Istituto Nazionale di Fisica Nucleare (INFN) Catania, Italy EMail: marco.farge...@ct.infn.it

Re: [openstack-dev] [Keystone] Bug in federation

2015-01-05 Thread Marco Fargetta
parameters. A simple table in Keystone will map the IdPs and protocols into the correct mapping rule to use. This is not a huge change to make, in fact it should be a rather simple re-engineering task. regards David On 24/12/2014 17:50, Marco Fargetta wrote: On 24 Dec 2014, at 17

Re: [openstack-dev] [Keystone] Proposing Marek Denis for the Keystone Core Team

2015-02-11 Thread Marco Fargetta
. Marco Fargetta, PhD Istituto Nazionale di Fisica Nucleare (INFN) Catania, Italy EMail: marco.farge...@ct.infn.it smime.p7s Description: S/MIME cryptographic signature

Re: [openstack-dev] [Keystone][FFE] - IdP ID (remote_id) registration and validation

2015-03-19 Thread Marco Fargetta
This is a good workaround to allow the authentication on the IdP but with the new websso is problematic because you do not know which mapping to use but you have the Shib-Identity-Provider. With the new information the entityIDs are associated with the keystone IdP so it is easy to find the

Re: [openstack-dev] Need help in configuring keystone

2015-02-27 Thread Marco Fargetta
Hi Akshik, the metadata error is in your SP, if the error was on testshib you should not be redirected back after the login. Maybe there is a configuration problem with shibboleth. Try to restart the service and look at shibboleth logs. Check also the metadata of testshib are downloaded correctly

Re: [openstack-dev] [nova][all] Architecture Diagrams in ascii art?

2015-05-12 Thread Marco Fargetta
+1 I prefer the ascii art in the specs and/or code doumentation. Figures could be better in other contexts like user and administrator manuals but they should not go in the code repository in my opinion. Cheers, Marco Fargetta On Mon, May 11, 2015 at 09:11:24PM -0400, Steve Martinelli wrote

Re: [openstack-dev] [horizon][keystone] Getting Auth Token from Horizon when using Federation

2016-04-21 Thread Marco Fargetta
On Thu, Apr 21, 2016 at 10:22:46AM -0400, John Dennis wrote: > On 04/18/2016 12:34 PM, Martin Millnert wrote: > >(** ECP is a new feature, not supported by all IdP's, that at (second) > >best requires reconfiguration of core authentication services at each > >customer, and at worst requires