Openstack cli authentication saml

asked 2016-02-12

mjblack gravatar image

I'm trying to setup saml2 authentication with my ADFS. I am able to successfully log into horizon using my ADFS idp. I am trying to use the openstack cli command to get a token and I'm not able to authenticate. I tried following the parameters in the cli reference but that did not work neither. (

The ADFSPassword driver currently shipped with Keystone has a few bugs which make it unusable. ( and (

I have a patch to resolve these which I'm happy to provide if this is still of interest

blakegc ( 2017-05-05 )

These issues have been resolved. The fixes will be available in keystoneauth1 version 2.21.0 ( ( (

blakegc ( 2017-06-13 )

I'm on Mitaka which seems to use 2.4.1. Would it work with your patches or are there other issues between 2.4.1 and 2.21.0 that need patching also?

dcreno ( 2017-11-29 )

answered 2017-05-12

amirdhaoui gravatar image

Hi ,

I'm interested to setup SAML2 authetication with shibboleth. did you work on it ? did you successfully configure keystone to identity federation, from your question I think so.

Thank you.

I recommend reading this excellent blog post by Colleen Murphy on Testing Keystone Federation with Devstack ( ( for instructions on configuring SAML federation with OpenStack. Alternatively, find me on IRC or send me an email & I can help.

blakegc ( 2017-05-19 )

thank you :)

I installed the Shibboleth SP, but I had a port problem, I need to change the endpoint with its public port, 5000 to https in the log file I have this :


I need to remove :5000

amirdhaoui ( 2017-05-22 )

