On 14 November 2014 10:05, Matthieu Huin <matthieu.h...@enovance.com> wrote:
> Hello Don, > > Federation and regular auth are distinct and can coexist. Furthermore, > you'll need to specify the auth > method when you're using openstackclient (or the auth plugin if you are > using the keystoneclient library) > so your users will take different paths depending on how they need to > authenticate anyway. > You might even define your federation mapping so that the users from your > saml system get mapped to > existing keystone users. I believe it is what you will have to do if you > want to keep your user = tenant > relationship. > > Thanks for the info. How would I specify the auth method from e.g. the CLI? so e.g. using 'nova' command line client, i don't thnk its 'os-auth-system' which is currently keystone, but maybe that's what it is? i see some of this in e.g. https://github.com/openstack/python-novaclient/blob/master/novaclient/auth_plugin.py but i'm not sure what that would translate to on the CLI.
_______________________________________________ Mailing list: http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack Post to : openstack@lists.openstack.org Unsubscribe : http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack