Can another identity provider be used with keystone as service provider other than Shibboleth?

I need to test keystone as a service provider while identity provider will be my organization's product is this possible

The question is a little abstract, please, add more info about what you need or want to achieve. For example: your organization identity provider in what tech is based? SQL, LDAP, third party, etc

my organization identity provider is using mysql and it is implemented on cloud so i had to use keystone as a service provider and use our product as an identity provider, please specify any other details you need to clear me out the question

Hi, I don't really know if you can connect an external mysql identity provider to an existing keystone service. The current federation, only supports 2 protocols:

  • SAML ( Shibboleth and Mellon)

  • OpenID Connect

I know that with OpenID there are some projects that support MySQL as backend, but i don't know if supports existing MySQL instances. Maybe you can create a wrap to allow this, as a middleware adding dinamically the content of your MySQL to the OpenID MySQL, and then configure Keystone to use federation with OpenID.

Check this link for more information about federation:

Hope it helps.

Regards, Eduardo

Also, ask in the #openstack-keystone irc channel, they probably will give you a better answer

thanks for reply, can we implement my idp with SAML protocol as this protocol is supported by our idp.

i had asked my question on openstack-keyston irc channel but there was no reply

@Eduardo Gonzalez Can i use Shibboleth to have gmail based authentication in keystone? I am a little confused if both OpenID connect and Shibboleth can be used with gmail IdP. Can you please share your opinion on this.

