Keystone Saml Mellon

  • OpenStack Charmers
  • Cloud
Channel Revision Published Runs on
latest/edge 141 17 Nov 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 140 17 Nov 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 139 17 Nov 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 138 17 Nov 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 133 21 Aug 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 132 21 Aug 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 131 21 Aug 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 130 21 Aug 2024
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 79 05 Aug 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 74 05 Aug 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 72 05 Aug 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 70 05 Aug 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 58 17 Apr 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 57 17 Apr 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 56 17 Apr 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 55 17 Apr 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
latest/edge 26 14 Mar 2023
Ubuntu 24.04 Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04 Ubuntu 20.04
yoga/stable 129 24 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 128 24 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 126 22 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 127 22 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 125 22 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 124 22 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 123 22 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
yoga/stable 122 22 Jul 2024
Ubuntu 22.04 Ubuntu 20.04
zed/stable 121 16 Jul 2024
Ubuntu 22.10 Ubuntu 22.04
zed/stable 120 15 Jul 2024
Ubuntu 22.10 Ubuntu 22.04
zed/stable 44 23 Jan 2023
Ubuntu 22.10 Ubuntu 22.04
zed/stable 43 23 Jan 2023
Ubuntu 22.10 Ubuntu 22.04
xena/stable 47 16 Jan 2023
Ubuntu 20.04
wallaby/stable 48 23 Jan 2023
Ubuntu 20.04
victoria/stable 50 26 Jan 2023
Ubuntu 20.04
ussuri/stable 63 01 Jun 2023
Ubuntu 20.04 Ubuntu 18.04
train/candidate 46 13 Dec 2022
Ubuntu 18.04
train/edge 49 16 Jan 2023
Ubuntu 18.04
stein/candidate 46 13 Dec 2022
Ubuntu 18.04
stein/edge 49 16 Jan 2023
Ubuntu 21.10 Ubuntu 21.04 Ubuntu 20.10 Ubuntu 20.04 Ubuntu 18.04 Ubuntu 16.04
stein/edge 12 13 Dec 2022
Ubuntu 21.10 Ubuntu 21.04 Ubuntu 20.10 Ubuntu 20.04 Ubuntu 18.04 Ubuntu 16.04
rocky/candidate 46 13 Dec 2022
Ubuntu 18.04
rocky/edge 49 16 Jan 2023
Ubuntu 18.04
queens/candidate 46 13 Dec 2022
Ubuntu 18.04
queens/edge 49 16 Jan 2023
Ubuntu 18.04
2024.1/candidate 91 02 May 2024
Ubuntu 22.04
2024.1/candidate 90 02 May 2024
Ubuntu 22.04
2024.1/candidate 89 02 May 2024
Ubuntu 22.04
2024.1/candidate 88 02 May 2024
Ubuntu 22.04
2023.2/stable 111 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 110 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 109 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 108 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 107 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 106 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 105 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.2/stable 104 01 Jul 2024
Ubuntu 23.10 Ubuntu 22.04
2023.1/stable 119 09 Jul 2024
Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04
2023.1/stable 118 09 Jul 2024
Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04
2023.1/stable 117 09 Jul 2024
Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04
2023.1/stable 116 09 Jul 2024
Ubuntu 23.04 Ubuntu 22.10 Ubuntu 22.04
juju deploy keystone-saml-mellon --channel yoga/stable
Show information

Platform:

Ubuntu
24.04 23.10 23.04 22.10 22.04 21.10 21.04 20.10 20.04 +2

Learn about configurations >

  • allow-cross-site-cookies | boolean

    Relaxes cross-site cookie security requirements to improve compatibility with IDP providers. However, enabling this options requires that the connection to the IDP provider is HTTPS-Secure to avoid cookie rejection by some modern browsers.

  • authn-requests-signed | boolean

    Default: True

    Indicates whether the samlp:AuthnRequest messages sent by the service provider (mellon) will be signed.

  • debug | boolean

    Enable debug logging

  • idp-discovery-service-url | string

    IDP discovery service URL. If set to "" (default) no discovery service will be used. If used, the resource "idp-metadata" must be an XML file containing descriptors for multiple IDPs

  • idp-metadata-url | string

    An optional URL to retrieve IDP metadata from. If set, takes priority over the "idp-metadata" resource. Auto-updates of metadata occur during any hook execution, including update-status.

  • idp-name | string

    Default: myidp

    Identity provider name to use for URL generation. Must match the one that will be configured via OS-FEDERATION API.

  • nameid-formats | string

    Default: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified,urn:oasis:names:tc:SAML:2.0:nameid-format:transient,urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress,urn:oasis:names:tc:SAML:2.0:nameid-format:persistent,urn:mace:shibboleth:1.0:nameIdentifier

    NameIDFormat entries to be used in Service Provider metadata file and in SAML requests (comma-separated). Different NameID formats could be used like transient, persistent, X509SubjectName, emailAddress, unspecified and so on.

  • protocol-name | string

    Default: mapped

    Protocol name to use for URL and generation. Must match the one that will be configured via OS-FEDERATION API.

  • saml-encryption | boolean

    (optional) Specifies whether SAML assertion encryption should be used. In many cases this option is not needed as TLS is used to encrypt data at the transport level. This option results in Service Provider metadata rendered with the same KeyInfo used for both signing and encryption. In practice, this means that the private key specified in sp-private-key will be used for both signing SAML messages to an idP and decryption of messages sent by idP. idP has to receive the SP metadata file with a public key (or a cert) present with use="encryption" specified.

  • ssl_ca | string

    TLS CA to use to communicate with other components in a deployment. . NOTE: This configuration option will take precedence over any certificates received over the certificates relation.

  • ssl_cert | string

    TLS certificate to install and use for any listening services. . NOTE: This configuration option will take precedence over any certificates received over the certificates relation.

  • ssl_key | string

    TLS key to use with certificate specified as ssl_cert. . NOTE: This configuration option will take precedence over any certificates received over the certificates relation.

  • subject-confirmation-data-address-check | boolean

    Default: True

    This option is used to control the checking of client IP address against the address returned by the IdP in Address attribute of the SubjectConfirmationData node. Can be useful if your SP is behind a reverse proxy or any kind of strange network topology making IP address of client different for the IdP and the SP. Default is on. This can be used for testing with something like testshib if you are behind a NAT.

  • use-internal-endpoints | boolean

    Openstack mostly defaults to using public endpoints for internal communication between services. If set to True this option will configure services to use internal endpoints where possible.

  • use-syslog | boolean

    Setting this to True will allow supporting services to log to syslog.

  • user-facing-name | string

    Default: myidp via mapped

    A user-facing name to be used for the identity provider and protocol combination. Used in the OpenStack dashboard.

  • verbose | boolean

    Enable verbose logging

  • want-assertions-signed | boolean

    Default: True

    Indicates a requirement for the saml:Assertion elements received by this service provider to be signed.