Re: [Dev] Help required for fixing error when running wso2 5.10.0 in docker container

2020-07-23 Thread Ruwan Abeykoon
he > default OAuth token issuer will be used. No custom token generator is set. > > TID: [-1234] [] [2020-07-23 04:01:14,547] [] INFO > {org.wso2.identity.apps.common.internal.AppsCommonServiceComponent} - > Identity apps common service component activated successfully. > > T

Re: [Dev] Help required for fixing error when running wso2 5.10.0 in docker container

2020-07-22 Thread Ruwan Abeykoon
for User and Identity) > instead of default H2 database. > The same configurations work fine when we run locally but fails when we > deploy the same in docker. > > Any help on this will be much appreciated. > > Thanks & Regards, > Prayag Pavithran > > --

Re: [Dev] Help required for fixing error when running wso2 5.10.0 in docker container

2020-07-22 Thread Ruwan Abeykoon
324) > > With the same configurations wso2 is runs fine locally . Could you please > help me in solving the above said issue in docker. > > > Thanks & Regards, > Prayag Pavithran > > > > > ___ > Dev mailing list > Dev@wso2.org > http://wso2.org/cgi-bin/

[Dev] [IAM] Exception in git integration, when network is not reachable

2019-12-01 Thread Ruwan Abeykoon
) at org.eclipse.jgit.transport.TransportHttp.connect(TransportHttp.java:501) ... 17 more Cheers, Ruwan A -- Ruwan Abeykoon | Director/Architect | WSO2 Inc. (w) +947435800 | Email: ruw...@wso2.com ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] WSO2 Identity Server clustering in docker architecture

2019-10-25 Thread Ruwan Abeykoon
a new WSO2 docker image when needed. Did I understand correctly? > > Thank you > Angelo > > Il giorno ven 18 ott 2019 alle ore 15:59 Ruwan Abeykoon > ha scritto: > >> Hi Angelo, >> >> if you see the Dockerfile, you would see "Kubenetes membership" files are

Re: [Dev] [IAM] User association during Adaptive authentication

2019-10-22 Thread Ruwan Abeykoon
Hi Sameera, Looks like the business case has security issue. You create a rogue user in federated IdP (e.g. Facebook) add the email claim and then you can login to your system. Cheers, Ruwan A On Tue, Oct 22, 2019 at 10:26 AM Sameera Wickramasekara wrote: > Hi Ashen, > > Thanks for the

Re: [Dev] [IAM] Username and Claims are null in Adaptive authentication script when authenticating again

2019-10-22 Thread Ruwan Abeykoon
Hi Sameera, Best practice is to use local claims, which is translated to local dialect as much as possible. Cheers, Ruwan A On Tue, Oct 22, 2019 at 10:45 AM Sameera Wickramasekara wrote: > Hi Devs, > > I am using an adaptive authentication script similar to one below in a > federated

Re: [Dev] WSO2 Identity Server clustering in docker architecture

2019-10-18 Thread Ruwan Abeykoon
Hi Angelo, if you see the Dockerfile, you would see "Kubenetes membership" files are being added as you need to enable kubernetes membership scheme when it is running in Kubernetes. The WKA scheme is not a good fit for containers. Yes, you need a central volume only if you have multi tenant

[Dev] [IAM] Removing "samples-is" from incubator

2019-10-14 Thread Ruwan Abeykoon
s Cheers, Ruwan A -- Ruwan Abeykoon | Director/Architect | WSO2 Inc. (w) +947435800 | Email: ruw...@wso2.com ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] Issue with adaptive authentication function method signature in java 11

2019-09-27 Thread Ruwan Abeykoon
inue with java 8. There > won't be any changes needed. Please raise if you have any concerns. > > [1] - > https://docs.wso2.com/display/IS580/Configuring+User-Age-Based+Adaptive+Authentication > > Thanks, > Senthalan > -- > Senthalan Kanagalingam | Senior Software Engineer | WSO2 Inc. > (m) +94 (0) 77 18 77 466 | (w) +94117435800 | (e) sentha...@wso2.com > > <http://wso2.com/signature> > > -- Ruwan Abeykoon | Director/Architect | WSO2 Inc. (w) +947435800 | Email: ruw...@wso2.com ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] [IAM] No way to track back the application when the token request fails with the Missing parameters

2019-09-18 Thread Ruwan Abeykoon
un(TaskThread.java:61) > at java.lang.Thread.run(Thread.java:748) > > Sample req to reproduce : curl -k -d "grant_type=refresh_token" -H > "Authorization: Basic SFNmNFJmOWw1UUczWbVdwTl9mZm9meldZYTpB" -H > "Content-Type: application/x-www-form-urlencoded" > https://localhost:9443/oauth2/token > > Thanks, > Prakhash > -- > *Prakhash Sivakumar | Senior Software Engineer | WSO2 Inc* > *+94771510080 | prakh...@wso2.com > | https://medium.com/@PrakhashS <https://medium.com/@PrakhashS>* > -- Ruwan Abeykoon | Director/Architect | WSO2 Inc. (w) +947435800 | Email: ruw...@wso2.com ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] [Rest API] [User Management] Profile support for user management Rest API

2019-08-15 Thread Ruwan Abeykoon
; IAM Domain > WSO2 Lanka (pvt) Ltd. > Web: http://wso2.com/ > Email : gdrdabar...@gmail.com > LinkedIn <https://lk.linkedin.com/in/dinalidabarera> > Mobile: +94770198933 > > > > > <https://lk.linkedin.com/in/dinalidabarera> > > > > > > >

Re: [Dev] HumanTask listing doesn't work when exposed as REST via a webapp in IS-5.9.0 on kernel-4.5.0-M4

2019-08-09 Thread Ruwan Abeykoon
.org/ns/bpel4people/ws-humantask/types/200803;> >> >> >> >> >> >> READY >> RESERVED >> COMPLETED >> CLAIMABLE >> >> >>

Re: [Dev] [DEV] [IAM] Updating the password of an authenticated user in SCIM2

2019-08-06 Thread Ruwan Abeykoon
atchUserMe >> >> Thanks and Best Regards. >> -- >> *Brion Silva* | Software Engineer | WSO2 Inc. >> (m) +94777933830 | (e) br...@wso2.com >> >> <https://wso2.com/signature> >> > > > -- > *Brion Silva* | Software Engineer | WSO2 Inc. >

Re: [Dev] Tomcat 9 upgrade for kernel 4.5.x

2019-07-19 Thread Ruwan Abeykoon
features like HTTP/2 support, TLS > virtual hosting and multiple certificate support for connectors. We can > also look into the possibilities of using these new features as well. We > tomcat 9 have contains configuration changes. I will update this mail with > the list of config ch

Re: [Dev] [Architecture][IAM] Moving File Based Artifacts to Artifact Store

2019-07-03 Thread Ruwan Abeykoon
think Ruwan's reply contains the answer. > > Regards, > Johann. > > On Thu, Jul 4, 2019 at 8:48 AM Johann Nallathamby wrote: > >> Hi Isura, >> >> On Fri, Jun 7, 2019 at 9:16 AM Isura Karunaratne wrote: >> >>> >>> >>> On Wed, Jun 5, 201

Re: [Dev] How does the cache expire in WSO2 products

2019-06-23 Thread Ruwan Abeykoon
etween the two based on a config? >>>> >>>> Thanks, >>>> NuwanD. >>>> >>>> -- >>>> *Nuwan Dias* | Director | WSO2 Inc. >>>> (m) +94 777 775 729 | (e) nuw...@wso2.com >>>> [image: Signature.jpg] >>>

[Dev] [IAM] Shall we move "carbon-identity-gateway" to attic ?

2019-06-18 Thread Ruwan Abeykoon
. WDYT? [1] https://github.com/wso2/carbon-identity-gateway Cheers, Ruwan A -- Ruwan Abeykoon | Director/Architect | WSO2 Inc. (w) +947435800 | Email: ruw...@wso2.com ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] [Architecture][IAM] Moving File Based Artifacts to Artifact Store

2019-06-04 Thread Ruwan Abeykoon
in the database). So when using a clustered setup >> those artifacts should be shared among all the nodes by using one of the >> following file sharing mechanisms. >> >>- Dep Sync >>- rSync >>- Shared File System >> >> >> *Solution * >>

Re: [Dev] Will WSO2 IS 5.3.0 reconnect if postgres is down for some time

2019-05-28 Thread Ruwan Abeykoon
Hi Shiva, There are few configurations you need to do to recover from Database down time. You need to analyze and select optimal parameters for your case. The following doc may help [1] [1] https://docs.wso2.com/display/ADMIN44x/Performance+Tuning#PerformanceTuning-JDBCpoolconfiguration On

Re: [Dev] -DworkerNode option while running WSO2 IS 5.3.0 failed to start

2019-05-17 Thread Ruwan Abeykoon
a:624) > at java.lang.Thread.run(Thread.java:748) > [2019-05-17 17:22:15,468] ERROR > {org.apache.catalina.core.StandardContext} - One or more Filters failed > to start. Full details will be found in the appropriate container log file > [2019-05-17 17:22:15,46

Re: [Dev] Remove war files of unused features in identity server 5.3.0

2019-05-14 Thread Ruwan Abeykoon
Hi Shiva Kumar, Yes, You can remove unwanted war archives. You need to test all of your use cases are completely achieved after removal of war. There will be no issue if it works for you. Cheers, Ruwan A On Tue, May 14, 2019 at 11:50 PM Shiva Kumar K R wrote: > Hi All, > Is it possible to

Re: [Dev] Nginx config to loadbalance wso2 IS

2019-05-12 Thread Ruwan Abeykoon
Hi Praveen, Better to ask this question form a relevant NGinx forum. The problem and solution is not WSO2 specific. Hence your question needs to be formulated as "how to configure NginX when generic backend service goes down" or something along that when posting to nginx forum. Cheers, Ruwan A

Re: [Dev] Differentiating signature algorithm in JWKS endpoint

2019-05-08 Thread Ruwan Abeykoon
decode the signature. But ideally, we should read the value from > identity.xml and expose it in the JWKS endpoint. If that the case then > which algorithm we should read from identity.xml? or Do we have to expose > different keysets for different algorithms (eg: 3 different keysets if all > of

Re: [Dev] Traefik configuration for wso2 identity server 5.3.0

2019-05-06 Thread Ruwan Abeykoon
Hi Praveen, Using traefix should be easy when identity server us used. All you need to do is to define the port 9443 (this is the default port all services are exposed) in traefic "reverse-proxy" configuration. Please consult traefic documentation of how to do this. The process is similar to

Re: [Dev] Authenticate to provision a user with OAuth with sufficient privileges fails

2019-04-24 Thread Ruwan Abeykoon
e. >> >> Hope I understood your concerns and hope I clarified them. >> >> Thanks & Regards, >> Johann. >> >> >>> >>>> >>>> Secondly, I think if the use case contains secondary user stores and >>>> client ex

Re: [Dev] Authenticate to provision a user with OAuth with sufficient privileges fails

2019-04-24 Thread Ruwan Abeykoon
Hi All, Is that mean we use the same token to authentication(of the app) and authorization (for the resource), both? Cheers, Ruwan A On Wed, Apr 24, 2019 at 1:49 PM Malithi Edirisinghe wrote: > > > On Wed, Apr 24, 2019 at 1:31 PM Farasath Ahamed > wrote: > >> >> >> On Wed, Apr 24, 2019 at

Re: [Dev] Removing PKCE column check during OAuth data persistence

2019-04-11 Thread Ruwan Abeykoon
http://wso2.com >> Mobile: (+94) 715 360 421 <+94%2071%20411%205032> >> >> <+94%2071%20411%205032> >> > > > -- > Farasath Ahamed > Senior Software Engineer, WSO2 Inc.; http://wso2.com > Mobile: +94777603866 > Blog: https://farasath.blogspot.com

Re: [Dev] Tenant OIDC logout fails with 'ID token signature validation failed.' error

2019-04-04 Thread Ruwan Abeykoon
carbon.identity.oidc.session/src/main/java/org/wso2/carbon/identity/oidc/session/servlet/OIDCLogoutServlet.java#L331 > Thanks, > Sathya > -- > Sathya Bandara > Senior Software Engineer > Blog: https://medium.com/@technospace > WSO2 Inc. http://wso2.com > Mobile: (+94) 715 360 421 <+94%2071%20411%205032> > > <+94%2071%20411%205032> > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signature> * *lean.enterprise.middleware.* ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] Failed to store SAML assertion when Assertion Query Request profile enabled

2019-03-26 Thread Ruwan Abeykoon
Hi Isuranga, There are two easy solutions for this. a) Use compression to store the text field on DB b) Increase the column size Both requires we do not have index for the respective column. Cheers, Ruwan A On Tue, Mar 26, 2019 at 12:45 PM Isuranga Perera wrote: > Hi All, > > As observed in

Re: [Dev] How to set query parameters in Adaptive Authentication

2019-03-14 Thread Ruwan Abeykoon
daptive scripts ? > > Thanks > -- > Prakhash Sivakumar > Senior Software Engineer | WSO2 Inc > Platform Security Team > Mobile : +94771510080 > Blog : https://medium.com/@PrakhashS > ___ > Dev mailing list > Dev@wso2.org &g

Re: [Dev] Enable client_id and client_secret based authentication to Introspection endpoint

2019-03-12 Thread Ruwan Abeykoon
thub.com/wso2-extensions/identity-carbon-auth-rest/pull/67 > > Best Regards > Isuranga Perera > ___ > Dev mailing list > Dev@wso2.org > http://wso2.org/cgi-bin/mailman/listinfo/dev > -- *Ruwan Abeykoon* *Associate Director/Architect

Re: [Dev] APIM IP white list

2019-02-25 Thread Ruwan Abeykoon
Hi All, Would not it better to change the name "Whitelist" to something else, such as "IP filtered throttling" or "Throttling with IP rules". "Whitelist" has exact meaning which is different with the what it means by throttling . Cheers, Ruwan On Tue, Feb 26, 2019 at 12:11 PM Maneesha

Re: [Dev] WSO2 Identity server "code mismatch" error when conditional script (Adaptive authentication) execution

2019-02-06 Thread Ruwan Abeykoon
Hi Prayang, The entire retry needs to be configured with adaptive script when you enable the script by typing in your own logic. The reason is to give you all the flexibility and provide alternative path when any number of retry fails according to your requirement. There is another thread [1]

Re: [Dev] Regarding the dash “-----” Format of Begin of Certificate/ End of Certificate in a PEM file

2019-02-06 Thread Ruwan Abeykoon
Hi Piraveena, This may related to [1] "Message Encapsulation" Reads as "an encapsulation boundary (EB) is defined as a line in the message which starts with a dash (decimal code 45, "-"). Initially, no restriction is placed on the length of the encapsulation boundary, or on the characters that

Re: [Dev] Using Tensor Flow in Risk Based Adaptive Authentication

2019-02-05 Thread Ruwan Abeykoon
tKnownSubject.username; >>>>> >>>>> httpGet('http://127.0.0.1:5000/evaluate?username=' + username, { >>>>> >>>>> onSuccess : function(context, data) { >>>>> >>>>> Log.info('--- Rece

Re: [Dev] authnContextClassRef

2019-01-27 Thread Ruwan Abeykoon
Hi Rabarto, Not sure about the Shibboleth Service Provider does. I hope below documentation (Draft) will help. This will be added to WSO2 Documentation in near future. Authentication Context Class Reference (ACR) and Authentication Method Reference (AMR) What is ACR? Authentication Context

Re: [Dev] Fw: authentication method

2019-01-16 Thread Ruwan Abeykoon
Hi Roberto, You may be able to use following script snippet to read the authnContextClassRef sent by your application (SP) at the adaptive authentication. The you can make the decision based on that. var authnContextClassRef = context.requestedAcr Cheers, Ruwan On Tue, Jan 15, 2019 at 4:43 PM

Re: [Dev] [IAM] Loading Function Libraries to Authentication Scripts

2018-10-11 Thread Ruwan Abeykoon
Hi Anuradha, I think require() [1] function better suited for this. Reason is that many other dynamic language based on JS uses it and seems intuitive. [1] https://stackoverflow.com/questions/9901082/what-is-this-javascript-require Cheers, Ruwan ___

Re: [Dev] [IS 560] Adaptive authentication - How to handle retry scenarios

2018-10-11 Thread Ruwan Abeykoon
gt;> [2018-10-10 15:26:01,362] ERROR >>>> {org.wso2.carbon.identity.application.authentication.framework.handler.request.impl.DefaultRequestCoordinator} >>>> - Exception in Authentication Framework >>>> java.lang.NullPointerException >>>> a

Re: [Dev] Upgrading C4 OSGi to support Java 10

2018-10-10 Thread Ruwan Abeykoon
ven repo >>>>>>>>>>>>>>>>>> using "wso2" as a prefix for the group ids of the artifacts. >>>>>>>>>>>>>>>>>> Then I updated >>>>>>>>>>>&

Re: [Dev] charon github issue #134

2018-09-18 Thread Ruwan Abeykoon
xception. > > Best regards > Pascal Knüppel > > ___ > Dev mailing list > Dev@wso2.org > http://wso2.org/cgi-bin/mailman/listinfo/dev > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signature> * *lean.enterprise.middl

Re: [Dev] [Architecture] [VOTE] Release WSO2 Identity Server 5.7.0 RC2

2018-09-13 Thread Ruwan Abeykoon
- go ahead and release >>>>> >>>>>[-] Broken - do not release (explain why) >>>>> >>>>> >>>>> >>>>> Thanks, >>>>> >>>>> - WSO2 Identity and Access Management Team - >>&g

Re: [Dev] [IS] Architecture - API to Retrieve Authentication Session Information

2018-09-04 Thread Ruwan Abeykoon
age >>>> wrote: >>>> >>>>> Hi Chuhaashanan, >>>>> >>>>> How is this SessionID generated? Is it same as the value of >>>>> commonauthId cookie? >>>>> >>>>> Thanks, >>>>&g

Re: [Dev] iat, exp and nbf values of token introspection when 'token_string' is a JWT

2018-09-04 Thread Ruwan Abeykoon
t; >> I would like you know your opinion on what these values should based on. >> Should it be same as the access tokens iat, exp, and nbf or should they be >> based on the generation time the JWT it self ? >> >> [1] - https://tools.ietf.org/html

Re: [Dev] [IS] Architecture - API to Retrieve Authentication Session Information

2018-09-03 Thread Ruwan Abeykoon
- In *Session* table, details of *Browser, OS* and *Location* will not >be used in query. So we can store this information as JSON object. > > > Regards > > -- > Chuhaashanan > Intern - Software Engineering > > > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signature> * *lean.enterprise.middleware.* ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] JIT provisioning with conditional authentication

2018-08-29 Thread Ruwan Abeykoon
Hi Gayan, This looks to be a bug. Thanks for reporting. Can you create a github issue for this please. Cheers, Ruwan On Wed, Aug 29, 2018 at 11:02 AM gayan gunawardana wrote: > Hi Devs, > > Is there any reason to stop JIT provisioning [1] in case of > GraphBasedSequenceHandler ? I couldn't

Re: [Dev] Removing noisy info logs in HazelcastClusterMessageListener

2018-08-13 Thread Ruwan Abeykoon
t; > *Darshana Gunawardana*Technical Lead > WSO2 Inc.; http://wso2.com > > *E-mail: darsh...@wso2.com * > *Mobile: +94718566859*Lean . Enterprise . Middleware > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signatu

Re: [Dev] What is the standard health check URL for Identity Server ?

2018-08-02 Thread Ruwan Abeykoon
[1] is an option. Do we have a standard URL? >>>> >>>> >>>> [1] - https://localhost:9443/carbon/admin/login.jsp >>>> >>>> -- >>>> *Best Regards* >>>> >>>> *Rushmin Fernando* >>>> *Technical Lead*

Re: [Dev] IAM: Error while uploading the metadata file in Sp creation.

2018-07-23 Thread Ruwan Abeykoon
AccessLogValve.java:962) >>> at >>> org.wso2.carbon.tomcat.ext.valves.CarbonContextCreatorValve.invoke(CarbonContextCreatorValve.java:57) >>> at >>> org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:116) >>>

Re: [Dev] Changes to IS profiles

2018-05-29 Thread Ruwan Abeykoon
*Pulasthi Mahawithana* > Associate Technical Lead > WSO2 Inc., http://wso2.com/ > Mobile: +94-71-5179022 > Blog: https://medium.com/@pulasthi7/ > > <https://wso2.com/signature> > > ___ > Dev mailing list > Dev@wso2.org >

Re: [Dev] [IS] Adding conditional authentication script programatically

2018-05-20 Thread Ruwan Abeykoon
gt; again and again for testing. > > Thanks! > > > ___ > Dev mailing list > Dev@wso2.org > http://wso2.org/cgi-bin/mailman/listinfo/dev > > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <

Re: [Dev] Forget me tool is going into an infinite loop while executing on improved audit logs

2018-04-08 Thread Ruwan Abeykoon
Hi All, We need to fix two things. 1. We do not want to annonymize admin login attempts. As admin login failure is a security concers and overrides privacy concerns. so we need to remove this pattern. (This is a business case) 2. We need to detect regex infinite loop cases and break. (This is a

Re: [Dev] WSO2 EI - ESB statistics and/vs tracing

2018-04-02 Thread Ruwan Abeykoon
And also tracing needs to be discouraged in production as it may log/reveal sensitive information, such as Phone Numbers, Account credentials, tokens, etc. The world is moving more towards privacy these days. Cheers, Ruwan On Mon, Apr 2, 2018 at 5:37 AM, Gihan Anuruddha wrote:

Re: [Dev] [Architecture] [IAM] Service Provider Standard Claim Dialects

2018-03-26 Thread Ruwan Abeykoon
gt; Appreciate your suggestions and comments on the above approach. > Thanks and Regards > -- > Indunil Upeksha Rathnayake > Software Engineer | WSO2 Inc > Emailindu...@wso2.com > Mobile 0772182255 > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http

Re: [Dev] DOCS wrrtien for .NEt agents

2018-03-15 Thread Ruwan Abeykoon
[+Dev] Hi Charan, Will you be able to make them in Markdown (md) format in the respective location. It should be enough. Cheers, Ruwan On Fri, Mar 16, 2018 at 9:16 AM, Chiran Wijesekara < chirankavinda...@gmail.com> wrote: > Hi, > > Hope you are doing good. The $subject is currently available

Re: [Dev] Processing Big/Huge/Large files in wso2 using vfs.Facing issues

2018-03-14 Thread Ruwan Abeykoon
Hi Adithya, Can you try this without the log mediator. Log mediator is usually tries to decode the payload. We call that a content aware mediator. The content aware mediators has the issue decoding large payloads. Cheers, Ruwan On Wed, Mar 14, 2018 at 6:43 PM, aditya shivankar <

Re: [Dev] IS installation error

2018-03-13 Thread Ruwan Abeykoon
Hi Asanka, Looks similar to [1] [1] https://bugs.java.com/bugdatabase/view_bug.do?bug_id=8029679 Cheers, Ruwan On Tue, Mar 13, 2018 at 4:46 PM, Asanka Anthony wrote: > > Hi, > Following error occurred when i trying to start IS in first time.Here i > attached bug file as

Re: [Dev] [Architecture] [IAM] eIDAS profile support for SAML

2018-03-11 Thread Ruwan Abeykoon
Hi Indunil, Please make sure this behavior is properly explained in the documentation, with references to the spec. Cheers, Ruwan On Mon, Mar 12, 2018 at 10:30 AM, Indunil Upeksha Rathnayake < indu...@wso2.com> wrote: > > > On Wed, Feb 28, 2018 at 5:15 PM, Dulanja Liyanage >

Re: [Dev] Error : java.lang.NoClassDefFoundError: org/testng/IAlterSuiteListener when upgrading the carbon versions

2018-03-09 Thread Ruwan Abeykoon
se reply to the sender indicating > that fact and delete the copy you received and in addition, you should not > print, copy, retransmit, disseminate, or otherwise use the information > contained in this communication. Internet communications cannot be > guaranteed to be timely, secure, error or virus-free. The sender does

Re: [Dev] [IAM] Password policy per role

2018-02-22 Thread Ruwan Abeykoon
Hi Gayan, Looks like this is an invalid requirement. A person usually have more than one role. It is complex to set the password policy per role, as one can not define which policy to be taken effect in this case. Password policy is to protect user account/credential leak. So it does not matter

Re: [Dev] [IS 5.5.0] Shall we get rid of DB backward compatibility code related to PKCE Support

2018-02-18 Thread Ruwan Abeykoon
ity code too)? > > > -- > *Best Regards* > > *Rushmin Fernando* > *Technical Lead* > > WSO2 Inc. <http://wso2.com/> - Lean . Enterprise . Middleware > > mobile : +94775615183 > > > -- *Ruwan Abeykoon* *Associate Director/Architect**,*

Re: [Dev] Metrics databases for IS and EI

2018-02-16 Thread Ruwan Abeykoon
Hi Lahiru, Regarding Metrics on IS, Is there any support issue we could solve or any issue we could have done better with having Metrics. I am asking because, I have not seen much importance on metics. But only saw issues when Metrics DB per each node needs to be created and configured over the

Re: [Dev] Disabling JNDI Binding in Carbon Datsources SPI On Demand

2018-02-14 Thread Ruwan Abeykoon
Hi Jayanga, +1. This is something we need to seamlessly integrate offline tools, which uses the same Datasource XML. I propose removing singleton on DatasourceManager, and pass a Properties to the constructor. Cheers, Ruwan On Wed, Feb 14, 2018 at 2:50 PM, Jayanga Kaushalya

Re: [Dev] [Architecture] Personal information export API

2018-02-08 Thread Ruwan Abeykoon
asons, we are planing to use base 64 encoded >>>>>>> fully qualified username as the userId in the above request. >>>>>>> >>>>>> >>>>>> Would like to know the rationale behind base64 encoding the username. >>>>>>

Re: [Dev] Bug # IDENTITY-7317

2018-02-06 Thread Ruwan Abeykoon
mpatibility is not provided. > > > > > > Shall I log issue on this?? > > > > > > > > *From:* Chiran Wijesekara [mailto:chir...@wso2.com] > *Sent:* 07 February 2018 09:04 > *To:* Ruwan Abeykoon <ruw...@wso2.com> > *Cc:* Pooja Gupta <pooja.gu...@edifecs.com>; De

Re: [Dev] Bug # IDENTITY-7317

2018-02-06 Thread Ruwan Abeykoon
Hi Deepak/Pooja, Thanks for the detailed report on IDENTITY-7317. We will certainly go through this and provide you the update ASAP. Cheers, Ruwan On Tue, Feb 6, 2018 at 2:09 PM, Pooja Gupta wrote: > + Deepak > > > > *From:* Pooja Gupta > *Sent:* 06 February 2018 14:09

Re: [Dev] Upgrade from wso2 5.40.0 to wso2 5.4.0-update-4

2018-01-23 Thread Ruwan Abeykoon
Hi Deepak, I believe you refer WSO2 IS 5.4.0. There is no specific update requirement. WSO2 IS 5.4.0 Update4 supposed to be a drop-in replacement for IS 5.4.0. You need to copy all your customized configs, extensions, etc to the updated location. The file relative locations are unchanged. Please

Re: [Dev] [Architecture] Personal information export API

2018-01-22 Thread Ruwan Abeykoon
Hi Hasintha, We do not need to export anything we do not keep in our databases. Could you please explain further if we need to do anything extra for Federated case. Cheers, Ruwan On Mon, Jan 22, 2018 at 5:33 PM, Hasintha Indrajee wrote: > Just a quick question. How are we

Re: [Dev] [Architecture][IS 5.5.0] Conditional steps based on HTTP context

2018-01-22 Thread Ruwan Abeykoon
} > } > }); > } > } > } > }); > } > > > In the above script, we define a cookie called *testcookie*. At the > initial authentication stage, the user has to go through both s

Re: [Dev] Common Parent for AbstractUserStoreManger, JDBCAuthorizationManager and HybridRoleManager

2018-01-19 Thread Ruwan Abeykoon
Hi Rushmin, Yes, that is valid point. how about AbstractSecuredIdentityManager ? Cheers, Ruwan On Fri, Jan 19, 2018 at 8:07 PM, Rushmin Fernando wrote: > I'm concerned thinking that whether there is a real is-a relationship here. > > The parent class name is

Re: [Dev] [Architecture][IS 5.5.0] Conditional steps based on HTTP context

2018-01-17 Thread Ruwan Abeykoon
Hi Sathya, We can enhance the DefaultRequestCoordinator itself, rather than extending and creating new coordinator, as there is no functional change done by adding the "request" and "response" to authentication context. Cheers, Ruwan On Wed, Jan 17, 2018 at 10:40 AM, Sathya Bandara

Re: [Dev] Problem with extracting a value in a SOAP response through a shell script

2018-01-15 Thread Ruwan Abeykoon
oach Nipuni. > > You have nicely solved the dependency problem. > > On Tue, Jan 16, 2018 at 9:43 AM, Nipuni Bhagya <nipu...@wso2.com> wrote: > >> Hi Ruwan, >> >> Thank you so much for the quick feedback. I sure will add that to the >> code. >> >>

Re: [Dev] Problem with extracting a value in a SOAP response through a shell script

2018-01-15 Thread Ruwan Abeykoon
ering Intern* >>> *WSO2* >>> >>> >>> >>> *Mobile : +94 0779028904 <+94%2077%20767%201807>* >>> >> >> >> >> -- >> *Best Regards* >> >> *Rushmin Fernando* >> *Technical Lead* >> >> WSO2

Re: [Dev] Problem with extracting a value in a SOAP response through a shell script

2018-01-08 Thread Ruwan Abeykoon
;>>>> >>>>> So I would really appreciate if someone of you could help me to find a >>>>> better way to achieve this task. >>>>> >>>>> Thank you in advance, >>>>> -- >>>>> >>>>> >>&

Re: [Dev] IS migration client usage of class.forName()

2017-11-24 Thread Ruwan Abeykoon
Hi Rasika, The problem this needs to address are, 1. The IS new version connected to old schema on database. The server should/can not start until migration completes. 2. Migration should only happen when the "migration client jar" is present (and the jvm parameter present-in new way) 3. Migration

Re: [Dev] API-Proxy for Single Page Application

2017-11-16 Thread Ruwan Abeykoon
20767%201807>94 774553167* >>> Web: <http://goog_716986954>http://wso2.com >>> >>> <http://wso2.com/signature> >>> >>> >>> ___ >>> Dev mailing list >>> Dev@wso2.org >>> http://wso2.org/cgi-bin/mailman/listinfo/d

Re: [Dev] Exposing WorkflowImplService as a OSGi service

2017-11-13 Thread Ruwan Abeykoon
+1 On Mon, Nov 13, 2017 at 6:50 PM, Thanuja Jayasinghe wrote: > Hi All, > > Is it possible to register WorkflowImplService[1] as OSGi service? It will > be really useful when we write custom workflow templates. > > [1] - https://github.com/wso2-extensions/identity-workflow- >

Re: [Dev] [IS] Multiple stubs version in 5.4.0 pack

2017-11-11 Thread Ruwan Abeykoon
t; Twitter: http://twitter.com/harshathirimann > Linked-In: linked-in: http://www.linkedin.com/pub/ > harsha-thirimanna/10/ab8/122 > <http://wso2.com/signature> > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signature> *

Re: [Dev] Remove provisioning-config.xml

2017-11-10 Thread Ruwan Abeykoon
r; WSO2 Inc.; http://wso2.com/ > Email: ga...@wso2.com > Mobile: +94 (71) 8020933 > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signature> * *lean.enterprise.middleware.* ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

[Dev] [C4] Question on Java9 support on Carbon 4 products

2017-11-10 Thread Ruwan Abeykoon
Hi Devs, What do we need to do to get ${subject}. I changed "wso2server.sh" jdk_17=`$JAVA_HOME/bin/java -version 2>&1 | grep "[(1.7)|(1.8)|9]"` if [ "$jdk_17" = "" ]; then echo " Starting WSO2 Carbon (in unsupported JDK)" echo " [ERROR] CARBON is supported only on JDK 1.7, 1.8 or 1.9" fi

Re: [Dev] Deperecated sign methods in JWT generation flows.

2017-11-09 Thread Ruwan Abeykoon
HI All, We should not remove extensibility. We need to look for an alternative way on this do any improvement while keeping extensibility. Cheers, Ruwan On Thu, Nov 9, 2017 at 3:28 PM, Danushka Fernando wrote: > Hi All > In released IS 5.3.0 we have capability of extending

Re: [Dev] Missing Attributes in Token Introspection Response

2017-08-21 Thread Ruwan Abeykoon
na <ga...@wso2.com> wrote: > >> >> >> On Mon, Aug 21, 2017 at 1:21 PM, Ruwan Abeykoon <ruw...@wso2.com> wrote: >> >>> Hi All, >>> I think we need to add them in introspection result, since they were >>> anyway present in AuthenticationRe

Re: [Dev] Missing Attributes in Token Introspection Response

2017-08-21 Thread Ruwan Abeykoon
Hi All, I think we need to add them in introspection result, since they were anyway present in AuthenticationResponse inside JWT. @Gayan, How about the acr, amr ? Cheers, Ruwan On Mon, Aug 21, 2017 at 11:08 AM, Gayan Gunawardana wrote: > Hi Indunil, > > Form token

Re: [Dev] [IDENTITY-3355] Better if only warning is shown for signature verification failures

2017-07-28 Thread Ruwan Abeykoon
gt;>> l/src/main/java/org/wso2/carbon/identity/sso/saml/util/SAMLS >>> SOUtil.java#L882 >>> >>> Thanks. >>> >>> Regards, >>> *R. Sugirjan* >>> Software Engineering - Intern | WSO2 >>> >>> Email: sugir...@w

Re: [Dev] [Swagger] swagger2cxf-maven-plugin to generate server stub for CXF

2017-07-05 Thread Ruwan Abeykoon
lly its skeleton. > > We are not just committing auto generated code to VCS. We will use auto > generated skeletons to do implementation and commit it to VCS. This is how > we use it. But you can decide what to do with your components. > > Thanks, > sanjeewa. > > > On Wed, Jul 5, 2

Re: [Dev] [Swagger] swagger2cxf-maven-plugin to generate server stub for CXF

2017-07-05 Thread Ruwan Abeykoon
dd our code). So we can add class comments there. > > On Wed, Jul 5, 2017 at 1:42 PM, Ruwan Abeykoon <ruw...@wso2.com> wrote: > >> Hi Isura, >> >> On Wed, Jul 5, 2017 at 1:04 PM, Isura Karunaratne <is...@wso2.com> wrote: >> >>> Hi Indunil, >

Re: [Dev] [Swagger] swagger2cxf-maven-plugin to generate server stub for CXF

2017-07-05 Thread Ruwan Abeykoon
Hi Isura, On Wed, Jul 5, 2017 at 1:04 PM, Isura Karunaratne wrote: > Hi Indunil, > > On Wed, Jul 5, 2017 at 11:35 AM, Indunil Upeksha Rathnayake < > indu...@wso2.com> wrote: > >> Hi, >> >> I have used the Swagger Codegen to generation the server stubs from a >> Swagger

Re: [Dev] [GSoC][SCIM] SCIM 2.0 Test Dependencies

2017-07-04 Thread Ruwan Abeykoon
or the dynamic nature of the test suite, I guess we will need to > adjust the test suite at runtime to a certain degree since we are testing > the schema extensions. We cannot test the nature of those extended > attributes unless we adjust the test suite according to schema. > > Regards,

Re: [Dev] [GSoC][SCIM] SCIM 2.0 Test Dependencies

2017-07-02 Thread Ruwan Abeykoon
> >>> <https://www.facebook.com/vindula.jayawardana> >>> <http://lk.linkedin.com/pub/vindula-jayawardana/a7/315/53b> >>> <https://plus.google.com/u/0/+VindulaJayawardana/posts> >>> <https://twitter.com/vindulajay> >>> >>>

Re: [Dev] Security using IS 5.3.0

2017-05-23 Thread Ruwan Abeykoon
abble.com/Security-using-IS-5-3-0-tp149117.html > Sent from the WSO2 Development mailing list archive at Nabble.com. > ___ > Dev mailing list > Dev@wso2.org > http://wso2.org/cgi-bin/mailman/listinfo/dev > -- *Ruwan Abeykoon* *Associat

Re: [Dev] Clarification on 'Use tenant domain in local subject identifier' attribute

2017-05-09 Thread Ruwan Abeykoon
ior of this attribute is something >>>> different. >>>> >>> Yes. That is the behavior of 'Use tenant domain in local subject >>> identifier" attribute. >>> >>> Thanks >>> Isura. >>> >>>> >>>

Re: [Dev] Using Multiple PreparedStatements with a single ResultSet

2017-04-25 Thread Ruwan Abeykoon
Hi All, I think we should mark these methods as Deprecated and remove all references from IS and user-code side. They promote careless mistakes, which are difficult to detect by human or automated tools. public static void closeAllConnections(Connection dbConnection, PreparedStatement...

Re: [Dev] [IDENTITY-5131] A solution for the possible deadlock due to session cleanup task

2017-04-24 Thread Ruwan Abeykoon
gt;> WSO2 Lanka (pvt) Ltd. >> Web: http://wso2.com/ >> Email : gdrdabar...@gmail.com >> LinkedIn <https://lk.linkedin.com/in/dinalidabarera> >> Mobile: +94770198933 <+94%2077%20019%208933> >> >> >> >> >> <ht

Re: [Dev] Configure the subject claim and set a default value only if no value is configured in IdP configuration

2017-04-19 Thread Ruwan Abeykoon
Vivekananthan Sivanayagam >> Software Engineer | WSO2 >> E:vivekanant...@wso2.com >> M:+94752786138 <+94%2075%20278%206138> >> >> On Wed, Apr 19, 2017 at 11:23 AM, Ruwan Abeykoon <ruw...@wso2.com> wrote: >> >>> Hi All, >>> Thanks Vive

Re: [Dev] Configure the subject claim and set a default value only if no value is configured in IdP configuration

2017-04-18 Thread Ruwan Abeykoon
2145300 >> Skype : malaka.sampath.silva >> LinkedIn : http://www.linkedin.com/pub/malaka-silva/6/33/77 >> Blog : http://mrmalakasilva.blogspot.com/ >> >> WSO2, Inc. >> lean . enterprise . middleware >> https://wso2.com/signature >> http://www.wso2.com/about/team/malaka-silva/ >> <http://wso2.com/about/team/malaka-silva/> >> https://store.wso2.com/store/ >> >> Don't make Trees rare, we should keep them with care >> > > > > -- > > Best Regards, > > Nuwandi Wickramasinghe > > Software Engineer > > WSO2 Inc. > > Web : http://wso2.com > > Mobile : 0719214873 > -- *Ruwan Abeykoon* *Associate Director/Architect**,* *WSO2, Inc. http://wso2.com <https://wso2.com/signature> * *lean.enterprise.middleware.* ___ Dev mailing list Dev@wso2.org http://wso2.org/cgi-bin/mailman/listinfo/dev

Re: [Dev] How can we add multi language support in javascript files

2017-03-25 Thread Ruwan Abeykoon
WDYT > ? > >> >> >> On Fri, Mar 24, 2017 at 8:40 AM, Nuwandi Wickramasinghe < >> nuwan...@wso2.com> wrote: >> >> >> >> On Fri, Mar 24, 2017 at 1:49 PM, Nuwan Dias <nuw...@wso2.com> wrote: >> >> >> >> On Fri, Mar

Re: [Dev] How can we add multi language support in javascript files

2017-03-24 Thread Ruwan Abeykoon
. Cheers, Ruwan On Fri, Mar 24, 2017 at 2:10 PM, Nuwandi Wickramasinghe <nuwan...@wso2.com> wrote: > > > On Fri, Mar 24, 2017 at 1:49 PM, Nuwan Dias <nuw...@wso2.com> wrote: > >> >> >> On Fri, Mar 24, 2017 at 1:23 PM, Ruwan Abeykoon <ruw...@wso2.com

Re: [Dev] How can we add multi language support in javascript files

2017-03-24 Thread Ruwan Abeykoon
;>>>>>>>> javascript ? Does the UUF has the capability of facilitating this ? >>>>>>>>>> You >>>>>>>>>> inputs are highly appreciated. >>>>>>>>>> >>>>>>>>&

Re: [Dev] [Identity Server] Creating a server configuration Identity.yaml vs component wise yaml files and Reading the server configurations

2017-01-19 Thread Ruwan Abeykoon
Hi All, @Johann I think security questions/account recovery options should not be treated as server-configurations. I would rather consider them as the runtime data much like the SP/IdP data. Hence single server config does not apply for this case IMO. >>Each component must pass its own

  1   2   3   >