)]}'
{"specs/central-auth.rst":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":22,"context_line":"Problem Description"},{"line_number":23,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"Our services need logins, and we need to be able to associate"},{"line_number":26,"context_line":"accounts across different services with the same individual. We have"},{"line_number":27,"context_line":"traditionally used Launchpad/Ubuntu OpenID for this. With the"},{"line_number":28,"context_line":"addition of non-OpenStack projects, requiring people to have a"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_530b7e28","line":25,"updated":"2020-06-24 18:46:29.000000000","message":"At least those, yes, potentially many more (we currently manage or semi-manage 7 services which authenticate against either UbuntuOne or OpenStackID (some of which may go away or be declared \"not our problem\"), with at least several more in the works. I\u0027ll get specific in the next revision.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"dcbaeef6b00586027086a9d7cad6b611fa063366","unresolved":false,"context_lines":[{"line_number":22,"context_line":"Problem Description"},{"line_number":23,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":24,"context_line":""},{"line_number":25,"context_line":"Our services need logins, and we need to be able to associate"},{"line_number":26,"context_line":"accounts across different services with the same individual. We have"},{"line_number":27,"context_line":"traditionally used Launchpad/Ubuntu OpenID for this. With the"},{"line_number":28,"context_line":"addition of non-OpenStack projects, requiring people to have a"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_bd186084","line":25,"range":{"start_line":25,"start_character":0,"end_line":25,"end_character":24},"updated":"2020-06-11 13:18:21.000000000","message":"How many services are we talking about here? Which services specifically?\n\n* Gerrit\n* Storyboard\n\nAnything else? I feel this needs to be explicited so we can have an idea of the scope, and also be aware of the amount of support these services already have for third party Identity Providers.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":31,"context_line":"individuals can be connected to a corresponding OSF profile for"},{"line_number":32,"context_line":"affiliation and CCLA tracking."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"* We want a central single sign-on system for OpenDev services"},{"line_number":35,"context_line":"* We do not want it to directly handle authentication credentials"},{"line_number":36,"context_line":"* We want the SSO infrastructure operated within OpenDev"},{"line_number":37,"context_line":"* We want OpenStackID to be one of the available federated IDPs"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_b3065a1f","line":34,"updated":"2020-06-24 18:46:29.000000000","message":"I suppose if we want to embrace the idea of Zuul tenant admins this might be a good way to manage them, I\u0027ll mention it in the next rev, thanks!","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"ccfcc9cdac54ff816e3f36ea51084e0c82dfbd25","unresolved":false,"context_lines":[{"line_number":31,"context_line":"individuals can be connected to a corresponding OSF profile for"},{"line_number":32,"context_line":"affiliation and CCLA tracking."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"* We want a central single sign-on system for OpenDev services"},{"line_number":35,"context_line":"* We do not want it to directly handle authentication credentials"},{"line_number":36,"context_line":"* We want the SSO infrastructure operated within OpenDev"},{"line_number":37,"context_line":"* We want OpenStackID to be one of the available federated IDPs"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_c2be8cd3","line":34,"updated":"2020-06-25 14:04:58.000000000","message":"I suppose that means if we want to rely on the same accounts for Gerrit users and Zuul tenant admins, we\u0027d need them all in the same realm? I don\u0027t think we\u0027d want users having to authenticate with a different realm depending on which project they\u0027re reviewing changes for anyway, and I guess it\u0027s entirely possible for one person to be an admin for multiple Zuul tenants, so maybe realms are only adding complexity there.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"58e791bc759b9ee12f94f01bff4885e48ef05f45","unresolved":false,"context_lines":[{"line_number":31,"context_line":"individuals can be connected to a corresponding OSF profile for"},{"line_number":32,"context_line":"affiliation and CCLA tracking."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"* We want a central single sign-on system for OpenDev services"},{"line_number":35,"context_line":"* We do not want it to directly handle authentication credentials"},{"line_number":36,"context_line":"* We want the SSO infrastructure operated within OpenDev"},{"line_number":37,"context_line":"* We want OpenStackID to be one of the available federated IDPs"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_7876d640","line":34,"range":{"start_line":34,"start_character":0,"end_line":34,"end_character":62},"updated":"2020-06-11 13:22:34.000000000","message":"do we want to split the user bases in distinct realms ?\n\n* OpenDev\n* OpenStack\n* ?\n\nZuul is already using tenants which could be mapped to realms, for example.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"192b2e59e0c98605173f3c781b6cb09dcd4e13b1","unresolved":false,"context_lines":[{"line_number":31,"context_line":"individuals can be connected to a corresponding OSF profile for"},{"line_number":32,"context_line":"affiliation and CCLA tracking."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"* We want a central single sign-on system for OpenDev services"},{"line_number":35,"context_line":"* We do not want it to directly handle authentication credentials"},{"line_number":36,"context_line":"* We want the SSO infrastructure operated within OpenDev"},{"line_number":37,"context_line":"* We want OpenStackID to be one of the available federated IDPs"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_7a1f6e07","line":34,"in_reply_to":"bf51134e_b3065a1f","updated":"2020-06-25 08:07:38.000000000","message":"Be aware that gerrit does not support multiple realms, as far as I can tell. You\u0027d need one gerrit instance per realm.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"4dafbfd3127bd55cb6a17a517e84b248f5396319","unresolved":false,"context_lines":[{"line_number":46,"context_line":"  providers"},{"line_number":47,"context_line":"* Selecting one of these options bounces them through the"},{"line_number":48,"context_line":"  corresponding IDP to authenticate"},{"line_number":49,"context_line":"* Once authenticated, opendevid.org redirects the user back to the"},{"line_number":50,"context_line":"  original service"},{"line_number":51,"context_line":"* A user can always go to a URL such as opendevid.org/account and"},{"line_number":52,"context_line":"  associate additional identities with their account, so that"},{"line_number":53,"context_line":"  they\u0027re not limited to just a single external IDP"},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"Proposed Change"},{"line_number":56,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_b8db4e1f","line":53,"range":{"start_line":49,"start_character":0,"end_line":53,"end_character":51},"updated":"2020-06-11 13:26:49.000000000","message":"Do we also need to manage ACLs with the central auth ? Gerrit would be a special beast because it stores ACLs in a project\u0027s config branch; but OpenID Connect\u0027s token can include roles and groups claims that other services could use to figure out a user\u0027s ACLs.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":50,"context_line":"  original service"},{"line_number":51,"context_line":"* A user can always go to a URL such as opendevid.org/account and"},{"line_number":52,"context_line":"  associate additional identities with their account, so that"},{"line_number":53,"context_line":"  they\u0027re not limited to just a single external IDP"},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"Proposed Change"},{"line_number":56,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_93019609","line":53,"updated":"2020-06-24 18:46:29.000000000","message":"I don\u0027t know, but if we gain that ability then it might be nice to have (for example StoryBoard currently lacks non-admin group management, to create or modify the membership of an SB team you have to be a global admin).","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"ccfcc9cdac54ff816e3f36ea51084e0c82dfbd25","unresolved":false,"context_lines":[{"line_number":50,"context_line":"  original service"},{"line_number":51,"context_line":"* A user can always go to a URL such as opendevid.org/account and"},{"line_number":52,"context_line":"  associate additional identities with their account, so that"},{"line_number":53,"context_line":"  they\u0027re not limited to just a single external IDP"},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"Proposed Change"},{"line_number":56,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_a2c1d856","line":53,"updated":"2020-06-25 14:04:58.000000000","message":"Yeah, and to be honest I think I\u0027d still prefer to see things like group membership driven by structured data in a revision control system, so that we have the ability to make those changes reviewable and testable before they go into effect (this is my current plan for StoryBoard group management too, I have a straw man example at https://review.opendev.org/685778 awaiting time to implement).","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"192b2e59e0c98605173f3c781b6cb09dcd4e13b1","unresolved":false,"context_lines":[{"line_number":50,"context_line":"  original service"},{"line_number":51,"context_line":"* A user can always go to a URL such as opendevid.org/account and"},{"line_number":52,"context_line":"  associate additional identities with their account, so that"},{"line_number":53,"context_line":"  they\u0027re not limited to just a single external IDP"},{"line_number":54,"context_line":""},{"line_number":55,"context_line":"Proposed Change"},{"line_number":56,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_3ab856e3","line":53,"in_reply_to":"bf51134e_93019609","updated":"2020-06-25 08:07:38.000000000","message":"So that\u0027s another thing to list for a future revision: do our services support role and group mappings from the JWT?\n\n* Gerrit: no\n* Storyboard: would be implemented along support for OIDC \n* Zuul: yes\n...","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":119,"context_line":"but this is something we should be doing regardless once we\u0027re off"},{"line_number":120,"context_line":"of Launchpad/UbuntuOne. OpenID v1 is pretty dead these days. For"},{"line_number":121,"context_line":"example, if we go with Dex, there is a Dex-specific plugin for"},{"line_number":122,"context_line":"Gerrit alread."},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"A challenge with the coreos/golang broker was that adding new"},{"line_number":125,"context_line":"providers was not too bad, but there weren\u0027t generic providers other"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_f601e006","line":122,"updated":"2020-06-24 18:46:29.000000000","message":"Yep, I\u0027ll add a sentence mentioning it, thanks.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"dcbaeef6b00586027086a9d7cad6b611fa063366","unresolved":false,"context_lines":[{"line_number":118,"context_line":"to authenticate with the broker over something other than OpenID v1,"},{"line_number":119,"context_line":"but this is something we should be doing regardless once we\u0027re off"},{"line_number":120,"context_line":"of Launchpad/UbuntuOne. OpenID v1 is pretty dead these days. For"},{"line_number":121,"context_line":"example, if we go with Dex, there is a Dex-specific plugin for"},{"line_number":122,"context_line":"Gerrit alread."},{"line_number":123,"context_line":""},{"line_number":124,"context_line":"A challenge with the coreos/golang broker was that adding new"},{"line_number":125,"context_line":"providers was not too bad, but there weren\u0027t generic providers other"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_781b7672","line":122,"range":{"start_line":121,"start_character":0,"end_line":122,"end_character":14},"updated":"2020-06-11 13:18:21.000000000","message":"gerrit\u0027s OAuth2 plugin has extensive support for many identity providers: https://github.com/davido/gerrit-oauth-provider","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":183,"context_line":"This has the benefit of not needing to write any Launchpad/UbuntuOne"},{"line_number":184,"context_line":"OpenID support code, but has a drawback of the initial database"},{"line_number":185,"context_line":"mapping being potentially incomplete/inexact, so there might be"},{"line_number":186,"context_line":"rectifications that need to be done."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Help Improve Launchpad/UbuntuOne"},{"line_number":189,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_d6049c17","line":186,"updated":"2020-06-24 18:46:29.000000000","message":"Gerrit *wants* E-mail addresses to be unique, but its OpenID support has traditionally fallen short on this (it will happily autocreate more than one account with the same address if they\u0027re associated with different OpenIDs, and then break on things like group membership or requested reviewer addition because it assumes but does not enforce address uniqueness). Gerrit\u0027s actual \"source of truth\" for users *was* an autoincrement field in the accounts table, so an integer account ID number essentially, though with the recent switch to NoteDB I\u0027m not positive that still holds true.\n\nI\u0027m in favor of the test you suggest if someone wants to give that a shot, but I\u0027m fairly certain that at least up through Gerrit 2.15 you\u0027ll just autocreate an additional account with a conflicting E-mail address. Regardless, there are other ways around that problem if we deem it critical to solve.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"dcbaeef6b00586027086a9d7cad6b611fa063366","unresolved":false,"context_lines":[{"line_number":160,"context_line":"Map Identities via ETL"},{"line_number":161,"context_line":"~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"Do a behind the scenes OpenID mapping exchange with OpenStackID"},{"line_number":164,"context_line":"based on user E-mail. Pre-generate a set of OpenStackID identities"},{"line_number":165,"context_line":"for each account based on E-mail address. Put those accounts into the"},{"line_number":166,"context_line":"backend DB of opendevid.org. Go ahead and add other IDPs. If someone"},{"line_number":167,"context_line":"logs in from one of the other IDPs and it comes back with a known"},{"line_number":168,"context_line":"E-mail address we have associated with an OpenStackID, make them log"},{"line_number":169,"context_line":"into OpenStackID too proving they are that person, which will"},{"line_number":170,"context_line":"then just add the association. If they log in with not-OpenStackID,"},{"line_number":171,"context_line":"it\u0027ll just create a new account."},{"line_number":172,"context_line":""},{"line_number":173,"context_line":"In this case we would map Launchpad/UbuntuOne to OpenStackID at a"},{"line_number":174,"context_line":"point in time, then rely on the OpenStackID E-mail matching any"},{"line_number":175,"context_line":"other accounts from that point forward. This would work with"},{"line_number":176,"context_line":"existing brokers because we don\u0027t need to OpenID v1, and allows us"},{"line_number":177,"context_line":"to just do a hard cutover using, for example, the generic"},{"line_number":178,"context_line":"openid-connect support in Dex. The biggest question here is, do we"},{"line_number":179,"context_line":"believe that E-mail address matching for the intial mapping will be"},{"line_number":180,"context_line":"good enough that followup support issues will be reasonable to"},{"line_number":181,"context_line":"handle?"},{"line_number":182,"context_line":""},{"line_number":183,"context_line":"This has the benefit of not needing to write any Launchpad/UbuntuOne"},{"line_number":184,"context_line":"OpenID support code, but has a drawback of the initial database"},{"line_number":185,"context_line":"mapping being potentially incomplete/inexact, so there might be"},{"line_number":186,"context_line":"rectifications that need to be done."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Help Improve Launchpad/UbuntuOne"},{"line_number":189,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_d858c232","line":186,"range":{"start_line":163,"start_character":0,"end_line":186,"end_character":36},"updated":"2020-06-11 13:18:21.000000000","message":"I think gerrit\u0027s source of truth for users is emails. ie if you activate gerrit\u0027s oauth plugin on an instance where users have already been registered, the mapping should be done through registered emails.\n\nIt wouldn\u0027t be too difficult to confirm:\n1. spawn a test gerrit using UbuntuOne authentication\n2. Have users do some stuff on the test instance, so that they\u0027re registered there\n3. Switch to oauth\n4. Have users log in again (make sure they\u0027re known by the same email than with U1 on the new oauth Identity Provider)\n5. Make sure they\u0027re mapped to the right user\n\nWe\u0027d need to make sure other services currently using U1 would behave similarly; if it\u0027s the case it would greatly simplify migration, as we\u0027d have to simply ask returning users to choose an identity provider where they\u0027re registered with the same e-mail as U1.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"ccfcc9cdac54ff816e3f36ea51084e0c82dfbd25","unresolved":false,"context_lines":[{"line_number":183,"context_line":"This has the benefit of not needing to write any Launchpad/UbuntuOne"},{"line_number":184,"context_line":"OpenID support code, but has a drawback of the initial database"},{"line_number":185,"context_line":"mapping being potentially incomplete/inexact, so there might be"},{"line_number":186,"context_line":"rectifications that need to be done."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Help Improve Launchpad/UbuntuOne"},{"line_number":189,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_02b524ee","line":186,"updated":"2020-06-25 14:04:58.000000000","message":"Yes, we discussed it at the PTG as well, a number of the options (including Keycloak) would probably allow us to prevent accounts with duplicate addresses for the most part. I can still think of slightly pathological scenarios where that\u0027s not preventable though (for example I authenticate to Keycloak and confirm my E-mail address, then log into Gerrit with that ID, later I change my E-mail address for that Keycloak ID but also log into Keycloak again autocreating a new ID not associated with the original and set the earlier address, then log into Gerrit again with that, resulting in autocreated accounts in Gerrit with different Keycloak IDs but colliding E-mail addresses). It\u0027s also possible newer versions of Gerrit have gotten better about refusing to autocreate an account when the same address is already associated with an existing account.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"192b2e59e0c98605173f3c781b6cb09dcd4e13b1","unresolved":false,"context_lines":[{"line_number":183,"context_line":"This has the benefit of not needing to write any Launchpad/UbuntuOne"},{"line_number":184,"context_line":"OpenID support code, but has a drawback of the initial database"},{"line_number":185,"context_line":"mapping being potentially incomplete/inexact, so there might be"},{"line_number":186,"context_line":"rectifications that need to be done."},{"line_number":187,"context_line":""},{"line_number":188,"context_line":"Help Improve Launchpad/UbuntuOne"},{"line_number":189,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_5ae6eae9","line":186,"in_reply_to":"bf51134e_d6049c17","updated":"2020-06-25 08:07:38.000000000","message":"I\u0027d say Keycloak offers a solution for this, as it allows users to link accounts: https://www.keycloak.org/docs/latest/server_admin/index.html#automatically-link-existing-first-login-flow\n\nThus keycloak would handle the problem of multiple OpenIDs for the same email.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"dcbaeef6b00586027086a9d7cad6b611fa063366","unresolved":false,"context_lines":[{"line_number":188,"context_line":"Help Improve Launchpad/UbuntuOne"},{"line_number":189,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Development seems to have stalled years ago, so we would likely be"},{"line_number":192,"context_line":"left carrying a fork best case. Also, while technically open source,"},{"line_number":193,"context_line":"running our own rebranded version of this would be next to"},{"line_number":194,"context_line":"impossible. On top of that, it\u0027s a source of truth for identity, and"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_1dab4c1e","line":191,"range":{"start_line":191,"start_character":0,"end_line":191,"end_character":43},"updated":"2020-06-11 13:18:21.000000000","message":"Is there anybody we can contact about this? See if we can help UbuntuOne with supporting newer standards?","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":188,"context_line":"Help Improve Launchpad/UbuntuOne"},{"line_number":189,"context_line":"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~"},{"line_number":190,"context_line":""},{"line_number":191,"context_line":"Development seems to have stalled years ago, so we would likely be"},{"line_number":192,"context_line":"left carrying a fork best case. Also, while technically open source,"},{"line_number":193,"context_line":"running our own rebranded version of this would be next to"},{"line_number":194,"context_line":"impossible. On top of that, it\u0027s a source of truth for identity, and"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_36087826","line":191,"updated":"2020-06-24 18:46:29.000000000","message":"We\u0027ve tried in the past, and if someone would like to reach out to Canonical again that\u0027s cool with me, though they\u0027ve seemed content to only ever touch the codebase when changes are needed for supporting their own products, and there has been repeated exodus of developers from the project leaving it at times with basically no caretakers whatsoever... I do not know its current state of maintenance however.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"dcbaeef6b00586027086a9d7cad6b611fa063366","unresolved":false,"context_lines":[{"line_number":240,"context_line":""},{"line_number":241,"context_line":"There are four options for implementation:"},{"line_number":242,"context_line":""},{"line_number":243,"context_line":"* Ipsilon"},{"line_number":244,"context_line":"* Dex"},{"line_number":245,"context_line":"* Hydra"},{"line_number":246,"context_line":"* Write our own"},{"line_number":247,"context_line":""},{"line_number":248,"context_line":"We probably shouldn\u0027t write our own from scratch."},{"line_number":249,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_7849b65e","line":246,"range":{"start_line":243,"start_character":0,"end_line":246,"end_character":15},"updated":"2020-06-11 13:18:21.000000000","message":"+1 for adding Keycloak","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":20366,"name":"Neal Gompa","display_name":"Conan Kudo (ニール・ゴンパ)","email":"ngompa13@gmail.com","username":"ngompa"},"change_message_id":"8e0a2db6fb031ddc9cebe2b017ab11f289d8315c","unresolved":false,"context_lines":[{"line_number":250,"context_line":"Ipsilon seems to be more focused on SAML and integration with"},{"line_number":251,"context_line":"FreeIPA since the last time we looked at it. On the backend they"},{"line_number":252,"context_line":"currently support authenticating against GSSAPI and PAM, so we\u0027d"},{"line_number":253,"context_line":"have to write the bits to auth against other things."},{"line_number":254,"context_line":""},{"line_number":255,"context_line":"https://ipsilon-project.org/doc/intro.html"},{"line_number":256,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_6db3040b","line":253,"updated":"2020-06-07 06:52:32.000000000","message":"This is definitely not true. Ipsilon works perfectly fine with regular LDAP systems and is commonly used to provide OpenID service. It also has GSSAPI and PAM info/auth plugins in the source tree. And the latest sources[0] contain theming support, with Fedora Account System and openSUSE Login themes currently present in-tree.\n\nFedora[1], RPM Fusion[2], and GNOME[3] do use Ipsilon with FreeIPA, but openSUSE[4] uses it with OpenLDAP.\n\n[0]: https://pagure.io/ipsilon\n[1]: https://id.fedoraproject.org\n[2]: https://id.rpmfusion.org\n[3]: https://id.gnome.org\n[4]: https://id.opensuse.org","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":250,"context_line":"Ipsilon seems to be more focused on SAML and integration with"},{"line_number":251,"context_line":"FreeIPA since the last time we looked at it. On the backend they"},{"line_number":252,"context_line":"currently support authenticating against GSSAPI and PAM, so we\u0027d"},{"line_number":253,"context_line":"have to write the bits to auth against other things."},{"line_number":254,"context_line":""},{"line_number":255,"context_line":"https://ipsilon-project.org/doc/intro.html"},{"line_number":256,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_160bb423","line":253,"updated":"2020-06-24 18:46:29.000000000","message":"We had an Ipsilon PoC circa 2015 as our first attempt at solving this problem, and so much of the prose here was taken from E-mail discussions several years old now. Thanks for the corrections!\n\nWould it be accurate to say though that Ipsilon expects some sort of user database (whether that\u0027s provided by FreeIPA, OpenLDAP, et cetera) and can\u0027t act merely as an ID passthrough/aggregation for other external IDPs?","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"dcbaeef6b00586027086a9d7cad6b611fa063366","unresolved":false,"context_lines":[{"line_number":297,"context_line":"https://github.com/davido/gerrit-oauth-provider/tree/master/src/main/java/com/googlesource/gerrit/plugins/oauth"},{"line_number":298,"context_line":""},{"line_number":299,"context_line":"One of the options it already supports is CoreOS Dex, so if we go"},{"line_number":300,"context_line":"that route we should be able to integrate with Gerrit. If we go"},{"line_number":301,"context_line":"Ipsilon or Hydra, we might need to work with gerrit-oauth-provider"},{"line_number":302,"context_line":"maintainers to make a more generic OAuth2 driver or something."},{"line_number":303,"context_line":""},{"line_number":304,"context_line":"Assignee(s)"},{"line_number":305,"context_line":"-----------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"ff570b3c_f8cae69e","line":302,"range":{"start_line":300,"start_character":55,"end_line":302,"end_character":62},"updated":"2020-06-11 13:18:21.000000000","message":"I think it already supports generic OAuth2 setups. but if not, adding support would be rather straightforward based on existing ones.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"27b3f55ee163a0591ff39cb686399361ffd87528","unresolved":false,"context_lines":[{"line_number":299,"context_line":"One of the options it already supports is CoreOS Dex, so if we go"},{"line_number":300,"context_line":"that route we should be able to integrate with Gerrit. If we go"},{"line_number":301,"context_line":"Ipsilon or Hydra, we might need to work with gerrit-oauth-provider"},{"line_number":302,"context_line":"maintainers to make a more generic OAuth2 driver or something."},{"line_number":303,"context_line":""},{"line_number":304,"context_line":"Assignee(s)"},{"line_number":305,"context_line":"-----------"}],"source_content_type":"text/x-rst","patch_set":1,"id":"bf51134e_7615d03f","line":302,"updated":"2020-06-24 18:46:29.000000000","message":"Thanks, I\u0027ll note this.","commit_id":"e82f124f9bb63855810b9fd930a3e29d90089508"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"87144361c1decd1f70bf6f9183b8992ce1e57a33","unresolved":false,"context_lines":[{"line_number":35,"context_line":"affiliation and CCLA tracking."},{"line_number":36,"context_line":""},{"line_number":37,"context_line":"* We want a central single sign-on system for OpenDev services"},{"line_number":38,"context_line":"* We may want distinct realms for different Zuul tenants"},{"line_number":39,"context_line":"* We do not want it to directly handle authentication credentials"},{"line_number":40,"context_line":"* We want the SSO infrastructure operated within OpenDev"},{"line_number":41,"context_line":"* We want OpenStackID to be one of the available federated IDPs"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_3a1056a8","line":38,"updated":"2020-06-25 08:18:59.000000000","message":"FYI: implemented by this change https://review.opendev.org/#/c/735586/","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"b3b8b3ce773471290bd792fe9236d6655abaec50","unresolved":false,"context_lines":[{"line_number":261,"context_line":"Options"},{"line_number":262,"context_line":"-------"},{"line_number":263,"context_line":""},{"line_number":264,"context_line":"There are four options for implementation:"},{"line_number":265,"context_line":""},{"line_number":266,"context_line":"* Ipsilon"},{"line_number":267,"context_line":"* Dex"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_5c45426f","line":264,"updated":"2020-06-25 13:47:14.000000000","message":"Three shall be the number of the counting and the number of the counting shall be three. ;)\n\nBut sure, I\u0027ll correct this on the next revision.","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":7186,"name":"Matthieu Huin","email":"mhuin@redhat.com","username":"mhu"},"change_message_id":"87144361c1decd1f70bf6f9183b8992ce1e57a33","unresolved":false,"context_lines":[{"line_number":261,"context_line":"Options"},{"line_number":262,"context_line":"-------"},{"line_number":263,"context_line":""},{"line_number":264,"context_line":"There are four options for implementation:"},{"line_number":265,"context_line":""},{"line_number":266,"context_line":"* Ipsilon"},{"line_number":267,"context_line":"* Dex"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_3a85f6cf","line":264,"range":{"start_line":264,"start_character":10,"end_line":264,"end_character":14},"updated":"2020-06-25 08:18:59.000000000","message":"five :)","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"3967777ac757d887606417fa17ef8f86547fa20e","unresolved":false,"context_lines":[{"line_number":318,"context_line":"It does not support OpenID for authentication or brokering, so we"},{"line_number":319,"context_line":"would potentially need to add this. It\u0027s also a large Java"},{"line_number":320,"context_line":"application, but then again we have a fair amount of experience"},{"line_number":321,"context_line":"running these lately anyway (Gerrit, Zanata, Zookeeper...)."},{"line_number":322,"context_line":""},{"line_number":323,"context_line":"Gerrit Integration"},{"line_number":324,"context_line":"------------------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_b96d6233","line":321,"updated":"2020-07-16 18:22:51.000000000","message":"One key bit that came out of the virtual PTG is that we can likely use something like https://simplesamlphp.org/ to act as a go between an identity broker that supports saml auth and launchpad/ubuntuone with its openid v1 auth.\n\nI think this is worth calling out somewhere in the spec since this particular issue has historically been the major hangup for making any progress on this idea.","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"3967777ac757d887606417fa17ef8f86547fa20e","unresolved":false,"context_lines":[{"line_number":333,"context_line":"Keycloak, Gluu, Ipsilon or Hydra, we might need to work with"},{"line_number":334,"context_line":"gerrit-oauth-provider maintainers to make a more generic OAuth2"},{"line_number":335,"context_line":"driver or something, though this probably works already or would at"},{"line_number":336,"context_line":"worst be straightforward to add."},{"line_number":337,"context_line":""},{"line_number":338,"context_line":"It\u0027s worth noting, StoryBoard already contains OIDC support (and has"},{"line_number":339,"context_line":"been tested with the OIDC implementation in OpenStackID), so this is"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_790bca7b","line":336,"updated":"2020-07-16 18:22:51.000000000","message":"Gerrit\u0027s oauth plugin supports keycloak starting in the 2.14 version. We run 2.13 but plan to upgrade and chances are we could backport keycloak support to 2.13 is absolutely necessary.\n\nhttps://gerrit.googlesource.com/plugins/oauth/+/refs/heads/stable-2.14/README.md","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"3967777ac757d887606417fa17ef8f86547fa20e","unresolved":false,"context_lines":[{"line_number":357,"context_line":"Work Items"},{"line_number":358,"context_line":"----------"},{"line_number":359,"context_line":""},{"line_number":360,"context_line":"* Decide if Launchpad/UbuntuOne support is absolutely required"},{"line_number":361,"context_line":"* See what needs to be added to StoryBoard for more modern protocols"},{"line_number":362,"context_line":"* Figure out what software to use or what we need to write"},{"line_number":363,"context_line":"* TODO: lots more once the above is settled"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_d94776a2","line":360,"updated":"2020-07-16 18:22:51.000000000","message":"I don\u0027t think anyone was happy with dropping ubuntu one support at least at the beginning of this process. Doing so would almost certainly require user unfriendly processes to get things mapped up in the new account system properly.","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"3967777ac757d887606417fa17ef8f86547fa20e","unresolved":false,"context_lines":[{"line_number":358,"context_line":"----------"},{"line_number":359,"context_line":""},{"line_number":360,"context_line":"* Decide if Launchpad/UbuntuOne support is absolutely required"},{"line_number":361,"context_line":"* See what needs to be added to StoryBoard for more modern protocols"},{"line_number":362,"context_line":"* Figure out what software to use or what we need to write"},{"line_number":363,"context_line":"* TODO: lots more once the above is settled"},{"line_number":364,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_f9e19a9c","line":361,"updated":"2020-07-16 18:22:51.000000000","message":"Is this still necessary? On line 338 above you mention OIDC support is tested and working with storyboard. Tools like keycloak tend to support oauth v2, oidc, and saml.","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"3967777ac757d887606417fa17ef8f86547fa20e","unresolved":false,"context_lines":[{"line_number":359,"context_line":""},{"line_number":360,"context_line":"* Decide if Launchpad/UbuntuOne support is absolutely required"},{"line_number":361,"context_line":"* See what needs to be added to StoryBoard for more modern protocols"},{"line_number":362,"context_line":"* Figure out what software to use or what we need to write"},{"line_number":363,"context_line":"* TODO: lots more once the above is settled"},{"line_number":364,"context_line":""},{"line_number":365,"context_line":"Repositories"}],"source_content_type":"text/x-rst","patch_set":2,"id":"bf51134e_79e74aad","line":362,"updated":"2020-07-16 18:22:51.000000000","message":"In our PTG conversations there seemed to be very good reasons to use Keycloak + SimpleSMLphp as a compat layer for ubuntu one.\n\nMaybe we should update the spec to include this as the suggested path forward so that we can properly evaluate it?","commit_id":"97b6cb67fd86256af88550aba0c97d4d9b85a218"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"8972a709d83533b9d2a06c284b432c86c2e41e4b","unresolved":false,"context_lines":[{"line_number":104,"context_line":"support in basically none of the options still available to us. This"},{"line_number":105,"context_line":"may mean we need to more strongly consider a less seamless"},{"line_number":106,"context_line":"migration, and plan to not include it as one of the available IDPs"},{"line_number":107,"context_line":"for OpenDevID."},{"line_number":108,"context_line":""},{"line_number":109,"context_line":"Alternatives"},{"line_number":110,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":3,"id":"9f560f44_bf8e802f","line":107,"updated":"2020-08-18 16:56:29.000000000","message":"Agreed, I\u0027ll update this paragraph to make these points clearer. Thanks!","commit_id":"34484d23a89ba7977e3c4cdc99e3a097721889b2"},{"author":{"_account_id":1,"name":"James E. Blair","email":"jim@acmegating.com","username":"corvus"},"change_message_id":"35f41f1aa965ba7027f5e5d7f547b1fd9aec56ac","unresolved":false,"context_lines":[{"line_number":104,"context_line":"support in basically none of the options still available to us. This"},{"line_number":105,"context_line":"may mean we need to more strongly consider a less seamless"},{"line_number":106,"context_line":"migration, and plan to not include it as one of the available IDPs"},{"line_number":107,"context_line":"for OpenDevID."},{"line_number":108,"context_line":""},{"line_number":109,"context_line":"Alternatives"},{"line_number":110,"context_line":"------------"}],"source_content_type":"text/x-rst","patch_set":3,"id":"9f560f44_f23a01e5","line":107,"updated":"2020-08-17 20:36:06.000000000","message":"I feel like the conclusion here (unsure what software) dosen\u0027t quite match the conclusion below (kinda looks like keycloak).  But I get that they do both agree that we\u0027re not sure yet, and below we\u0027re saying let\u0027s test keycloak and see if it works.  Not sure if any text actually warrants changing.  :)\n\nI think some kind of support for launchpad/openidv1 is relatively important and would prefer we do that (either direct implementation or saml shim) rather than ETL or similar.  If we end up with anything other than upstreamed openidv1 support, then I think treating that as a 6-month temporary situation is reasonable; if we do get upstream support, then I think we could continue to support launchpad indefinitely.  Not sure if this warrants an explicit mention.  Could probably wait until after the POC.","commit_id":"34484d23a89ba7977e3c4cdc99e3a097721889b2"}]}
