Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-5265

FIWARE.Request.Tech.Security.IDM-KeyRock.FIWARE.Tech.Assistance

    Details

    • Type: extRequest
    • Status: Closed
    • Priority: Major
    • Resolution: Done
    • Fix Version/s: 2021
    • Component/s: FIWARE-TECH-HELP
    • Labels:
      None

      Description

      Hello from Greece,

      I am a developer and i have a setup in fiware lab with 2 VMs. One VM for
      IDM, PEP Proxy and Authorization PDP and one for the Context Broker.
      Everything works fine except Authorization PDP (AuthZForce). In fact i
      cannot find a way to synchronize the roles and permissions of the IDM
      (KeyRock) with the AuthZForce (now AuthZForce is allowing every request).
      I found something about Docker, but I realy want to setup my own custom
      system.
      I would appreciate your help since i did not found anything in
      StackOverflow (except the Docker solution). Thank you in advance.

      George

      Since January 1st, old domains won't be supported and messages sent to any domain different to @lists.fiware.org will be lost.
      Please, send your messages using the new domain (Fiware-lab-help@lists.fiware.org) instead of the old one.
      _______________________________________________
      Fiware-lab-help mailing list
      Fiware-lab-help@lists.fiware.org
      https://lists.fiware.org/listinfo/fiware-lab-help
      [Created via e-mail received from: =?UTF-8?B?zpPOuc+Oz4HOs86/z4IgzqfOsc+BzrnPhM6szrrOt8+C?= <chgiorgos13@gmail.com>]

        Activity

        Transition Time In Source Status Execution Times Last Executer Last Execution Date
        Open Open In Progress In Progress
        7h 22m 1 Cyril Dangerville 12/Nov/15 6:33 PM
        In Progress In Progress Answered Answered
        16h 6m 1 Cyril Dangerville 13/Nov/15 10:39 AM
        Answered Answered Closed Closed
        52s 1 Cyril Dangerville 13/Nov/15 10:40 AM
        fla Fernando Lopez made changes -
        Fix Version/s 2021 [ 12600 ]
        mev Manuel Escriche made changes -
        HD-Enabler KeyRock [ 10889 ]
        HD-Chapter Security [ 10841 ]
        mev Manuel Escriche made changes -
        Sender Email chgiorgos13@gmail.com
        mev Manuel Escriche made changes -
        Summary FIWARE.Request.Lab.Security.IDM-KeyRock.FIWARE Lab Assistance FIWARE.Request.Tech.Security.IDM-KeyRock.FIWARE.Tech.Assistance
        aalonsog Alvaro Alonso made changes -
        Summary [Fiware-lab-help] FIWARE Lab Assistance FIWARE.Request.Lab.Security.IDM-KeyRock.FIWARE Lab Assistance
        Hide
        cdangerville Cyril Dangerville added a comment -

        He replied by email indeed to the external user. I just copy-pasted his reply here. Sorry for the misunderstanding.

        Show
        cdangerville Cyril Dangerville added a comment - He replied by email indeed to the external user. I just copy-pasted his reply here. Sorry for the misunderstanding.
        Hide
        mev Manuel Escriche added a comment -

        Álvaro, you cannot simply write the comment. Please, be aware this issue come from an external user, so you have to email it. Right? Thanks

        Show
        mev Manuel Escriche added a comment - Álvaro, you cannot simply write the comment. Please, be aware this issue come from an external user, so you have to email it. Right? Thanks
        cdangerville Cyril Dangerville made changes -
        Resolution Done [ 10000 ]
        Status Answered [ 10104 ] Closed [ 6 ]
        cdangerville Cyril Dangerville made changes -
        Assignee Cyril Dangerville [ cyril.dangerville ] Alvaro Alonso [ aalonsog ]
        Hide
        cdangerville Cyril Dangerville added a comment -

        Answer from KeyRock IdM owner:

        Hi,

        as Cyril has comment, Keyrock (Horizon specifically) sets the permissions in the AuthZForce when a user configures them in the GUI.

        To configure the host where AuthZForce is running you have to use this Horizon setting:

        https://github.com/ging/horizon/blob/master/openstack_dashboard/local/local_settings.py.example#L624

        BR

        Álvaro

        Show
        cdangerville Cyril Dangerville added a comment - Answer from KeyRock IdM owner: Hi, as Cyril has comment, Keyrock (Horizon specifically) sets the permissions in the AuthZForce when a user configures them in the GUI. To configure the host where AuthZForce is running you have to use this Horizon setting: https://github.com/ging/horizon/blob/master/openstack_dashboard/local/local_settings.py.example#L624 BR – Álvaro
        cdangerville Cyril Dangerville made changes -
        Comment [ Answer from KeyRock IdM owner:

        Hi,

        as Cyril has comment, Keyrock (Horizon specifically) sets the permissions in the AuthZForce when a user configures them in the GUI.

        To configure the host where AuthZForce is running you have to use this Horizon setting:

        https://github.com/ging/horizon/blob/master/openstack_dashboard/local/local_settings.py.example#L624

        BR
        --
        Álvaro
        ]
        cdangerville Cyril Dangerville made changes -
        Status In Progress [ 3 ] Answered [ 10104 ]
        cdangerville Cyril Dangerville made changes -
        Status Open [ 1 ] In Progress [ 3 ]
        Hide
        cdangerville Cyril Dangerville added a comment -

        Hello,
        I am the GE owner of Authzforce. I received your request below. As far as I know, it is the responsibility of the IdM to push the role and permissions to Authzforce, so I will ask the IdM owner.

        Regards,
        Cyril

        ----------------
        Hello from Greece,

        I am a developer and i have a setup in fiware lab with 2 VMs. One VM for
        IDM, PEP Proxy and Authorization PDP and one for the Context Broker.
        Everything works fine except Authorization PDP (AuthZForce). In fact i
        cannot find a way to synchronize the roles and permissions of the IDM
        (KeyRock) with the AuthZForce (now AuthZForce is allowing every request).
        I found something about Docker, but I realy want to setup my own custom
        system.
        I would appreciate your help since i did not found anything in
        StackOverflow (except the Docker solution). Thank you in advance.

        George

        Since January 1st, old domains won't be supported and messages sent to any domain different to @lists.fiware.org will be lost.
        Please, send your messages using the new domain (Fiware-lab-help@lists.fiware.org) instead of the old one.
        _______________________________________________
        Fiware-lab-help mailing list
        Fiware-lab-help@lists.fiware.org
        https://lists.fiware.org/listinfo/fiware-lab-help
        [Created via e-mail received from: =?UTF-8?B?zpPOuc+Oz4HOs86/z4IgzqfOsc+BzrnPhM6szrrOt8+C?= <chgiorgos13@gmail.com>]

        Show
        cdangerville Cyril Dangerville added a comment - Hello, I am the GE owner of Authzforce. I received your request below. As far as I know, it is the responsibility of the IdM to push the role and permissions to Authzforce, so I will ask the IdM owner. Regards, Cyril ---------------- Hello from Greece, I am a developer and i have a setup in fiware lab with 2 VMs. One VM for IDM, PEP Proxy and Authorization PDP and one for the Context Broker. Everything works fine except Authorization PDP (AuthZForce). In fact i cannot find a way to synchronize the roles and permissions of the IDM (KeyRock) with the AuthZForce (now AuthZForce is allowing every request). I found something about Docker, but I realy want to setup my own custom system. I would appreciate your help since i did not found anything in StackOverflow (except the Docker solution). Thank you in advance. George Since January 1st, old domains won't be supported and messages sent to any domain different to @lists.fiware.org will be lost. Please, send your messages using the new domain (Fiware-lab-help@lists.fiware.org) instead of the old one. _______________________________________________ Fiware-lab-help mailing list Fiware-lab-help@lists.fiware.org https://lists.fiware.org/listinfo/fiware-lab-help [Created via e-mail received from: =?UTF-8?B?zpPOuc+Oz4HOs86/z4IgzqfOsc+BzrnPhM6szrrOt8+C?= <chgiorgos13@gmail.com>]
        mev Manuel Escriche made changes -
        Component/s FIWARE-TECH-HELP [ 10278 ]
        Component/s FIWARE-LAB-HELP [ 10279 ]
        alfopietro Pietropaolo Alfonso made changes -
        Assignee Cyril Dangerville [ cyril.dangerville ]
        backlogmanager Backlog Manager made changes -
        Field Original Value New Value
        Component/s FIWARE-LAB-HELP [ 10279 ]
        fw.ext.user FW External User created issue -

          People

          • Assignee:
            aalonsog Alvaro Alonso
            Reporter:
            fw.ext.user FW External User
          • Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: