[rhos-list] Keystone user authentication with existing LDAP

Adam Young ayoung at redhat.com
Thu Dec 6 14:33:55 UTC 2012


On 12/06/2012 07:26 AM, Kumar Vaibhav wrote:
> Hi,
>
> I want to authenticate my users with existing OpenLDAP server. It 
> already have the username and password for users.
> I use this OpenLDAP server for authenticating Linux servers in the 
> network.
>
> Is it possible to keep only user information in LDAP.?

Not yet, sorry.

>
> Since my LDAP server do not have Role, Group, and other Tree DN 
> available, I want these to be stored in database only.

Can you not modify the LDAP schema?  These are trivial to maintain in LDAP.

Or, are you not going to be modifying the User list?

One thing you can try is to sync the user list over to the SQL Database 
without passwords, run Keystone in apache and use mod_auth_ldap to log 
in.  It is an untested configuration, but it should work.

>
> I should have used Only DB also but the problem is my OpenLDAP server 
> has passwords encrypted in MD5.
>
> Regards,
> Vaibhav
>
>
> Get Yourself a cool, short *@in.com* Email ID now! 
> <http://www3.in.com/sso/commonregister.php?ref=IN&utm_source=invite&utm_medium=outgoing>
>
>
> _______________________________________________
> rhos-list mailing list
> rhos-list at redhat.com
> https://www.redhat.com/mailman/listinfo/rhos-list

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/rhos-list/attachments/20121206/b23ea041/attachment.htm>


More information about the rhos-list mailing list