[Fiware-security] FICORE - Security Chapter - Openstack Summit Summary

Álvaro Alonso aalonsog at dit.upm.es
Tue Nov 11 18:25:11 CET 2014


Hi all, 

as probably many of you already know, the Openstack Summit 2014 was held in Paris last week. As some other FIWARE partners, we (DIT-UPM) attended the meeting, in order to keep in contact with the Openstack community and improve the alignment of our developments with the general line of Opensack projects. 

Regarding Security chapter, as you know and as a part of the first releases of FICORE, we are working on the new release of Keyrock IdM as an extension of Openstack Keystone. We think this is the first step to start the alignment with the community. And we have detected two main lines in the current Keystone development that will benefit FIWARE Identity and Access Control tasks. 

In order to manage the identity of users from different regions and countries, we will perform the distribution and federation of Keyrock among different nodes. The community is working in the federation using SAML protocol and the communication with external identity providers.

On the other hand and related with AC, they are improving the roles and policies management by centralizing them in Keystone and by refining the policies sets that until now were only strings. We can take advantage of this by merging it with our current role management. 

In the next weeks we will evaluate if it makes sense to work in their direction and also if we make an action plan to align with them. If you have any insights or suggestions about it, we would appreciate if you share them in the list. 

Many thanks and best regards.
-- 
Álvaro & Joaquín

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.fiware.org/private/fiware-security/attachments/20141111/3f1fc861/attachment.html>


More information about the Fiware-security mailing list

You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy   Cookies policy