Multiple domains suppot in LDAP backend with Domain specific tree

Registered by Sahdev Zala

In Grizzly release of OpenStack, a somewhat support was provided for domains in the Keystone LDAP backend. We increasingly finding out that there are many users out there who uses multiple domains in their LDAP implementation with a Domain specific sub-tree. Currently Keystone does not support such feature. An URL to a doc is provided with current design and proposed design. The proposed design was discussed with many attendees at the recent OpenStack summit, April 15-18, with many positive feedback. It is still under discussion and will be updated as necessary.

Blueprint information

Status:
Complete
Approver:
None
Priority:
Undefined
Drafter:
None
Direction:
Needs approval
Assignee:
Sahdev Zala
Definition:
Obsolete
Series goal:
None
Implementation:
Unknown
Milestone target:
None
Completed by
Dolph Mathews

Related branches

Sprints

Whiteboard

(?)

Work Items

Dependency tree

* Blueprints in grey have been implemented.

This blueprint contains Public information 
Everyone can see this information.