Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

External Authentication Revamp #1677

Open
jrafanie opened this issue May 27, 2022 · 2 comments
Open

External Authentication Revamp #1677

jrafanie opened this issue May 27, 2022 · 2 comments

Comments

@jrafanie
Copy link
Member

We need to review and summarize authentication support in podified and appliances, what is done automatically or needs manual configuration (creating groups to match ldap groups and giving correct permissions) and determine if some of the documentation or supported configurations are still relevant.

I couldn't find documentation that, regardless of external authentication type, you'd need to create groups either in ldap (to match internal groups) or internally to match external authentication and configure what permissions this group has.

This line is hidden is hidden in the middle or end of a large page of documentation in multiple places:

In Configure→Configuration→Access Control

Make sure the user’s groups are created on the Appliance and appropriate roles assigned to those groups.

https://www.manageiq.org/docs/reference/latest/auth/openid_connect.html
and https://www.manageiq.org/docs/reference/latest/auth/ldap.html

It seems like we should start with the common steps for all authentication configurations for podified and appliances and then give links to separate documentation for just that specific configuration.

@Fryguy
Copy link
Member

Fryguy commented May 27, 2022

I'm thinking we need an https://www.manageiq.org/docs/reference/latest/auth/overview.html page that talks about external authentication in general, what types are supported by which deployments (or perhaps that should be in the capabilities matrix), and this rules about groups being configured properly.

@Fryguy Fryguy self-assigned this Jun 8, 2022
@Fryguy Fryguy removed the help wanted label Jun 8, 2022
@Fryguy Fryguy removed their assignment Aug 19, 2022
@miq-bot miq-bot added the stale label Feb 27, 2023
@miq-bot
Copy link
Member

miq-bot commented Feb 27, 2023

This issue has been automatically marked as stale because it has not been updated for at least 3 months.

If you can still reproduce this issue on the current release or on master, please reply with all of the information you have about it in order to keep the issue open.

Thank you for all your contributions! More information about the ManageIQ triage process can be found in the triage process documentation.

@Fryguy Fryguy removed the stale label Mar 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants