Hi All,

We noticed $subject. I don't think this is valid because IS User Portal and
Carbon management console should be treated as two SPs. So user portal
reading the audience from authenticator.xml is wrong. Also it reads it even
if SAML2 SSO authenticator is disabled. So this will create even more
problems when both User Portal and Carbon management console is enabled for
SSO. Correct way of validating audience should be by defining the audience
in auth_config.json in the dashboard webapp.

Can we please fix this for IS 5.4.0?

Thanks & Regards,
Johann.

-- 

*Johann Dilantha Nallathamby*
Senior Lead Solutions Engineer
WSO2, Inc.
lean.enterprise.middleware

Mobile - *+94777776950*
Blog - *http://nallaa.wordpress.com <http://nallaa.wordpress.com>*
_______________________________________________
Dev mailing list
[email protected]
http://wso2.org/cgi-bin/mailman/listinfo/dev

Reply via email to