keystone/doc/source/admin/federation
Jadon Naas 7ac0c3cd33 Update OIDC Apache config to avoid masking Keystone API endpoint
The current configuration for the OIDCRedirectURI results in
mod_auth_openidc masking the Keystone federation authentication
endpoint, which results in incorrect responses to requests for
Keystone tokens. This change updates the documentation to
recommend using a vanity URL that does not match a Keystone
API endpoint.

Closes-Bug: 2075349
Change-Id: I1dfba5c71da68522fdb6059f0dc03cddc74cb07d
2024-08-01 21:13:17 -04:00
..
configure_federation.rst Add expiring user group memberships on mapped authentication 2020-04-07 19:30:57 -04:00
federated_identity.rst Restructure federation guide 2018-12-30 11:32:43 -08:00
introduction.rst Fix typo in openid federation diagram 2023-05-09 13:08:11 +02:00
mapping_combinations.rst Keystone to honor the "domain" attribute mapping rules. 2024-01-16 08:54:56 -03:00
mellon.inc Docs: Make robust with using real links 2019-08-09 20:15:14 +02:00
openidc.inc Update OIDC Apache config to avoid masking Keystone API endpoint 2024-08-01 21:13:17 -04:00
shibboleth.inc Add openstack_groups to assertion 2020-03-19 20:14:41 +05:30