Enable OIDC in the CAS build, puppetise OIDC-related options and initially enabled in idp-test to allow tests for Juniper Service Asset APIs
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Open | None | T305518 Upgrade IDPs to CAS 6.6/Bullseye and enable webauthn | |||
Restricted Task | |||||
Resolved | jbond | T311999 Enable OIDC in CAS | |||
Resolved | Jelto | T320390 migrate gitlab away from the CAS protocol | |||
Resolved | Stevemunene | T305874 Switch DataHub authentication to OIDC |
Event Timeline
Change 810867 had a related patch set uploaded (by Muehlenhoff; author: Muehlenhoff):
[operations/software/cas-overlay-template@master] Enable OIDC in Gradle build
Change 858362 had a related patch set uploaded (by Jbond; author: jbond):
[operations/puppet@production] apero_cas: (WIP) add addtional paramas for OIDC
Change 858362 merged by Jbond:
[operations/puppet@production] apero_cas: (WIP) add addtional paramas for OIDC
Change 862942 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] idp::standalon: Add OIDC config
Change 862942 merged by Jbond:
[operations/puppet@production] idp::standalon: Add OIDC config
Change 863006 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] apereo_cas: add OidcRegisteredService service support
Change 863292 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] apereo_cas::services: drop mfa-u2f support
Change 863292 merged by Jbond:
[operations/puppet@production] apereo_cas::services: drop mfa-u2f support
Change 863006 merged by Jbond:
[operations/puppet@production] apereo_cas: add OidcRegisteredService service support
Change 869750 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] apereo_cas: Add OIDC service to cloud instance
Change 869750 merged by Jbond:
[operations/puppet@production] apereo_cas: Add OIDC service to cloud instance
Change 869837 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] aereo_cas: add addtional OIDC parameteres
Change 869837 merged by Jbond:
[operations/puppet@production] aereo_cas: add addtional OIDC parameteres
Change 869840 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] apreo_cas: Bypass the approval prompt
Change 869840 merged by Jbond:
[operations/puppet@production] apreo_cas: Bypass the approval prompt
Change 810867 abandoned by Muehlenhoff:
[operations/software/cas-overlay-template@master] Enable OIDC in Gradle build
Reason:
Similar patch was merged by John
Change 879807 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] idp: add oidc_issuers_pattern via the profile
Change 879807 abandoned by Jbond:
[operations/puppet@production] idp: add oidc_issuers_pattern via the profile
Reason:
for now i dont think we need to change this
Change 879809 had a related patch set uploaded (by Jbond; author: John Bond):
[operations/puppet@production] idp: add idm-test services
Change 879809 merged by Jbond:
[operations/puppet@production] idp: add idm-test services
Hi @jbond and @MoritzMuehlenhoff - how are things looking with regard to this OIDC support?
We would still like to be able to T305874: Switch DataHub authentication to OIDC using idp because the LDAP support in DataHub isn't great, but currently it's the only thing we have.
Do you know when we might be able to start testing OIDC authentication via CAS? Thanks.
@BTullis OIDC support is now possible and is being tried out by the new IDM. It should be to a state where you can start using it and happy to help out/provide more pointers just keep in mind you will be an early adopter so there may be something to work out on the fly. Check the config for idm_test in production and the private repo
@jbond - Many thanks. That's excellent. I think I'd be keen to look at doing that and helping find out the issues. I've asked the Data-Engineering team so I'll get back to you in a couple of days.