Questo contenuto non è disponibile nella lingua selezionata.

Chapter 24. Implementing Federation


Red Hat supports federation using Red Hat’s single sign-on (SSO) or Microsoft Active Directory Federation Services (AD FS) in combination with Red Hat OpenStack Platform (RHOSP).

24.1. Federate with IdM using single sign-on

You can use Red Hat’s single sign-on (SSO) to federate your IdM users for OpenStack authentication (authN). Federation allows your IdM users to login to the OpenStack Dashboard without revealing their credentials to any OpenStack services. Instead, when Dashboard needs a user’s credentials, it will forward the user to SSO and allow them to enter their IdM credentials there. As a result, SSO asserts back to Dashboard that the user has successfully authenticated, and Dashboard then allows the user to access the project.

24.2. The federation workflow

This section describes how the Identity service (keystone), Red Hat’s single sign-on (SSO) and IdM interact with each other. Federation in OpenStack uses the concept of Identity Providers and Service Providers:

Identity Provider (IdP) - the service that stores the user accounts. In this case, the user accounts held in IdM, are presented to Keystone using SSO.

Service Provider (SP) - the service that requires authentication from the users in the IdP. In this case, keystone is the service provider that grants Dashboard access to IdM users.

You can configure the Identity service (the SP) to communicate with SSO (the IdP), which is also able to serve as a universal adapter for other IdPs. In this configuration, you can point keystone at SSO, and SSO will forward requests on to the Identity Providers that it supports (known as authentication modules), these currently include IdM and Active Directory. This is done by having the Service Provider (SP) and Identity Provider (IdP) exchange metadata, which each sysadmin then makes a decision to trust. The result is that the IdP can confidently make assertions, and the SP can then receive these assertions.

Red Hat logoGithubredditYoutubeTwitter

Formazione

Prova, acquista e vendi

Community

Informazioni sulla documentazione di Red Hat

Aiutiamo gli utenti Red Hat a innovarsi e raggiungere i propri obiettivi con i nostri prodotti e servizi grazie a contenuti di cui possono fidarsi. Esplora i nostri ultimi aggiornamenti.

Rendiamo l’open source più inclusivo

Red Hat si impegna a sostituire il linguaggio problematico nel codice, nella documentazione e nelle proprietà web. Per maggiori dettagli, visita il Blog di Red Hat.

Informazioni su Red Hat

Forniamo soluzioni consolidate che rendono più semplice per le aziende lavorare su piattaforme e ambienti diversi, dal datacenter centrale all'edge della rete.

Theme

© 2026 Red Hat
Torna in cima