Using generic SAML2, you can integrate OpenStack Management Server with any Identity Provider solution within your organization. Generic SAML2 authenticates directly with the identity service.

Since this integration does not automatically associate the Keystone Service Provider with your Identity Provider solution, contact your Identity Provider deployment administrator to collect information for mapping before configuring SAML2 integration.

SAML2 Federation uses a single OpenStack Management Server deployment.

Procedure

  1. Add an Identity Provider on the OpenStack Management Server deployment.
    viocli federation identity-provider add

    Enter input for prompts.

    Prompt

    Description

    Sample Value

    Identity provider type

    Enter saml2. Value is case insensitive.

    saml2

    Identity provider name

    Unique name to identify the Identity Provider. Name must not include special characters or spaces that the URL cannot interpret.

    vmware_saml

    Identity provider display name

    Human readable name to identify the Identity Provider in Horizon. Appears in the Horizon drop down menu.

    VMware Generic SAML2

    Description

    Human readable name to identify the Identity Provider in Keystone and VMware Integrated OpenStack.

    VMware Identity Manager @ vio-identity-manager.eng.vmware.com

    address

    Endpoint address of the vIDM deployment

    vio-identity-manager.eng.vmware.com

    vIDM admin user

    User must have permission to list users.

    admin

    vIDM admin password

    vmware

    Enter the name of the domain that federated users associate with.

    Name of the domain to which all federated users belong. If uncertain of the domain, enter Default. If it does not exist, VMware Integrated OpenStack creates the domain.

    Default

    Enter the name of the groups that federated users associate with (separated by commas ",").

    Name of the groups to which all federated users belong. If using a customized mapping file, include all defined groups. If no mapping file exists, VMware Integrated OpenStack creates the groups within the domain.

    ALL USERS, Federated Users

  2. Configure the deployment
    viocli identity configure

    Following configuration, expect a period of downtime to your VMware Integrated OpenStack deployment.

What to do next

If you do not want to use the default mapping, you can customize mapping. See Customize Mapping.