Bug 3410 (infra-ipsilon) - [RFE] Adapt Ipsilon to rpmfusion
Summary: [RFE] Adapt Ipsilon to rpmfusion
Status: RESOLVED FIXED
Alias: infra-ipsilon
Product: Infrastructure
Classification: Unclassified
Component: General (show other bugs)
Version: NA
Hardware: All GNU/Linux
: P5 normal
Assignee: Nicolas Chauvet
URL:
Depends on:
Blocks:
 
Reported: 2014-11-15 07:42 CET by Michael Cronenworth
Modified: 2016-09-29 09:01 CEST (History)
7 users (show)

See Also:
namespace:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Cronenworth 2014-11-15 07:42:02 CET
Pkgdb2 authenticates using OpenID. We need an FedOAuth instance running to auth against an FAS instance.
Comment 1 Nicolas Chauvet 2014-11-15 15:05:53 CET
Thx for your report.
Do we really need to use FedOAuth or can't we use the previous authentication method instead with either pkgdb2/bodhi ?

One need to run pkgdb2 in a Virtual Machine an do testing, specially about how interactions goes with fas/bugzilla/others (probably to be found with ansible
Comment 2 Michael Cronenworth 2014-11-15 15:51:15 CET
The reason I created this bug was because I created a VM for implementing all of these services. Pkgdb2 only authenticates against an OpenID system.

There is currently an issue with the FedOAuth setup and I'm waiting to hear back from the author.
Comment 3 Michael Cronenworth 2014-11-16 22:49:24 CET
After fixing the FedOAuth setup I've learned it is going away. We need to move to Ipsilon, which is being released tomorrow.

http://patrick.uiterwijk.org/2014/11/14/fedoauth-ipsilon-merge-complete/
Comment 4 Pierre-Yves C. 2015-04-29 11:17:27 CEST
Ipsilon 1.0 will be released on early May (roadmap says May 8th) and fedoauth official support will stop ~2 months after that.
Comment 5 Patrick Uiterwijk 2015-04-29 11:31:12 CEST
I would suggest to deploy Ipsilon for new instances, as FedOAuth will no longer get any new features (security and bug fixes will continue for at least two months after Ipsilon 1.0, any longer are non-public patches).

Note that the current Ipsilon release (0.6.0) has a bug with the OpenID support and needs a small fix[1], but this has been merged upstream and will be fixed in any future releases.

If any help is needed for Ipsilon setup or usage, please let me know.



[1]: https://git.fedorahosted.org/cgit/ipsilon.git/commit/?id=ba45934659346510966ca6c58a01dbba3eca7d2f
Comment 6 Till Maas 2015-11-02 19:09:10 CET
Why is it not possible to use Fedora's ipsilon instance? The only potential problem I can see is that it requires everyone to have a FAS account as well.
Comment 7 Michael Cronenworth 2015-11-02 19:15:59 CET
Administrative ACLs are kept in RPMFusion's FAS instance. It is also permissible to be a RPMFusion packager but not a Fedora packager.
Comment 8 Nicolas Chauvet 2016-09-29 09:01:55 CEST
Ipsilon is available but it requires an updated fas to work with.
We will either migrate FAS to fas2 or fas3 once the machine will be migrated to the new instance.