Re: [Architecture] Analytics Filter for Microgateway

2018-06-19 Thread Dinusha Dissanayake
Hi Sinthuja, What we are trying to do here is, persist the events coming from micro-gateway so that events would not be lost when publishing them to analytics. Microgateway should be able to run on its own. If analytics server is not present at the moment we are invoking APIs in microgateway, ther

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Amalka Subasinghe
Hi all, We tested following - Private key jwt authentication - OIDC login/logout flow - OIDC Hybrid flow with "code id_token" response type No blocking issues found. Hence +1 for the release Thanks Amalka On Wed, Jun 20, 2018 at 11:08 AM Ayesha Dissanayaka wrote: > Hi All, > > I have tested f

Re: [Architecture] Rethinking Product Analytics Architecture

2018-06-19 Thread Sinthuja Rajendran
Hi Rukshan, On Wed, Jun 20, 2018 at 9:40 AM Rukshan Premathunga wrote: > Hi Sinthuja, > > Per min summary within local node will be fine and reduce the traffic to > Analyzer. But can we grantee that, Siddhi apps will not slow down other > functionalities(gateway request)? > IMHO it should not s

Re: [Architecture] Rethinking Product Analytics Architecture

2018-06-19 Thread Sinthuja Rajendran
Hi Fazlan, Yes, would reduce some events 3 times, but still, I think in the new approach we need to send at least one event per gateway request to analytics server. Which means, based on the TPS values (load) of APIM server, we need to scale up analytics nodes as well. Basically, our requirement i

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Ayesha Dissanayaka
Hi All, I have tested following Identity Management Scenarios. User Self Registration Username Recovery Password Self Recovery via Email via Challenge Questions Admin Forced Password reset via Email link via OTP in Email via Offline OTP Email Notifications Resend Account Verification li

[Architecture] SAML Artifact Binding - Server Side Implementations

2018-06-19 Thread Vihanga Liyanage
Hi all, I've started working on the server-side implementation of SAML Artifact Binding. The basic idea is as follows. When authentication is done via SAML, SAML assertion is sent to the user agent (browser) as a direct response from the IDP. One disadvantage of this method is the possibility of

Re: [Architecture] Rethinking Product Analytics Architecture

2018-06-19 Thread Fazlan Nazeem
Hi Sinthuja, There is an ongoing effort to combine request, response and execution time event streams into a single stream and publish a single event instead of 3 events to the Stream processor. This is targeted for the Q3 release and can bring down the traffic by 3 times to the analytics server.

Re: [Architecture] Rethinking Product Analytics Architecture

2018-06-19 Thread Rukshan Premathunga
Hi Sinthuja, Per min summary within local node will be fine and reduce the traffic to Analyzer. But can we grantee that, Siddhi apps will not slow down other functionalities(gateway request)? This can be try out in ballerina based gateway since streams is already in there. But if we take c4 based

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Madawa Soysa
Hi All, I have tested the following, - Generating MP-JWT 1.0 compatible token. - Microprofile JWT Sample No blocking issues found. Hence +1 for the release. On Tue, Jun 19, 2018 at 5:08 PM Biruntha Gnaneswaran wrote: > Hi All, > > I have tested the following, > > Create service provider

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Biruntha Gnaneswaran
Hi All, I have tested the following, Create service provider and tested OAuth flow with playground when hashing access tokens, refresh tokens, client secrets, and authorization codes feature enabled. No blocking issues found. [+] Stable - go ahead and release Thanks, On Tue, Jun 19, 2018 at 4

[Architecture] Rethinking Product Analytics Architecture

2018-06-19 Thread Sinthuja Rajendran
Hi, With my recent work with metrics and other monitoring systems, I'm thinking whether our model of sending everything and calculate in the analytics server side is correct. Basically IMHO, the majority of the product analytics use cases are statistics calculation. For example, in APIM, we are c

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Nadeeshani Pathirennehelage
Hi All, +1 from Platform Security Team. Thank You, Nadeeshani. On Tue, Jun 19, 2018 at 4:42 PM, Ashen Weerathunga wrote: > Hi All, > > I have tested the following and found no issues. > >- Consent Management for Self Sign Up. >- Creating Users with the Ask Password Option. >- Passw

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Ashen Weerathunga
Hi All, I have tested the following and found no issues. - Consent Management for Self Sign Up. - Creating Users with the Ask Password Option. - Password pattern validation. - SAML SSO with Consent Management. [+] Stable - go ahead and release Thanks, Ashen On Tue, Jun 19, 2018 at

Re: [Architecture] Additional roles on top of Active Directory

2018-06-19 Thread Ishara Karunarathna
Hi Jørgen. On Mon, Jun 18, 2018 at 3:31 AM Jørgen Østergaard wrote: > Hi, > > > > We are using an Secure LDAP connection to Active Directory as a user > store. We need some additional functionality on top of the existing AD > structure, which requires changes in the existing setup / application.

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Ishara Karunarathna
Hi All, Tested the IS 5.6.0-RC3 integration with IS-Analytics-5.6.0 And check the session analytics reports. No blocking issues found. [+] Stable Thanks, Ishara On Tue, Jun 19, 2018 at 3:48 PM Isuri Anuradha wrote: > Hi all, > > I've tested following scenarios on the IS 5.6.0-RC3 pack. >

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Thanuja Jayasinghe
Hi All, Tested user account association scenarios. No blocking issues found. [+] Stable - Go ahead and release Thanks, Thanuja On Tue, Jun 19, 2018 at 3:48 PM Isuri Anuradha wrote: > Hi all, > > I've tested following scenarios on the IS 5.6.0-RC3 pack. > >- SAML to SAML federation flow. >

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Isuri Anuradha
Hi all, I've tested following scenarios on the IS 5.6.0-RC3 pack. - SAML to SAML federation flow. - Publish and Update XACML policies. - OAuth token revocation. No blocking issues found. [+] Stable Thanks Isuri. On Tue, Jun 19, 2018 at 3:34 PM, Omindu Rathnaweera wrote: > Hi All, >

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Omindu Rathnaweera
Hi All, Tested SCIM 2.0 basic operations. No blocking issues found [+] Stable - Go ahead and release Regards, Omindu. On Tue, Jun 19, 2018 at 3:14 PM Nipuni Bhagya wrote: > Hi all, > > I've tested following scenarios on the IS 5.6.0-RC3 pack. > >- Configuring Single-Sign-On with SAML2

[Architecture] Prompt for user input during the authentication flow

2018-06-19 Thread Maduranga Siriwardena
Hi all, We are working on a feature to prompt for user input during the authentication flow. This is a part of the conditional authentication implementation. Consider the identifier first login flow implementation, where the user first enter the username first and then Identity Server prompt for

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Nipuni Bhagya
Hi all, I've tested following scenarios on the IS 5.6.0-RC3 pack. - Configuring Single-Sign-On with SAML2 - Configuring Single-Sign-On with OIDC - Configuring Multi-Factor Authentication - Configuring Twitter as a Federated Authenticator - Setting up Self-Signup - Creating a wo

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Pulasthi Mahawithana
Hi, Tested SSO with Multi step/multi option authentication, Google and Twitter authenticators No blocking issues found. [+] Stable - Go ahead and release On Tue, Jun 19, 2018 at 2:59 PM Hasanthi Purnima Dissanayake < hasan...@wso2.com> wrote: > Hi, > > Tested below scenarios on IS 5.6.0-RC3 p

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Senthalan Kanagalingam
Hi all, I have tested the following, Create service provider and tested oAuth flow with playground. multi-authentication with facebook. Configure TOTP Authenticator. No blocking issues found. [+] Stable - Go ahead and release thanks, On Tue, Jun 19, 2018 at 1:44 PM Sathya Bandara wrote: > H

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Isura Karunaratne
Hi, Tested followed scenarios in super tenant, primary user store. - Account Locking - Self Registration with email confirmation. - Self-care portal operations. - Password reset through a notification. - Password reset through challenge questions. - Account Recovery. - Passw

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Hasanthi Purnima Dissanayake
Hi, Tested below scenarios on IS 5.6.0-RC3 pack, - Register a service provider - Obtain an access token using JWT grant type - Invoke user info endpoint using the token. No blocking issues found. [+] Stable - Go ahead and release Thanks, Hasanthi On Tue, Jun 19, 2018 at 2:44 PM, Dewni Weerama

Re: [Architecture] Micro Gateway CLI - Hashing Resources (APIs/Policies) for change detection

2018-06-19 Thread Nuwan Dias
When we do WUM updates to the distribution (Microgateway Toolkit), we may have to force build the runtime even if there aren't changes to the API and Policy definitions. In that case we may need a flag to force build. On Tue, Jun 19, 2018 at 2:41 PM, Isuru Haththotuwa wrote: > +1 for this approa

Re: [Architecture] [Dev] [VOTE] Release of WSO2 API Manager 2.5.0 RC3

2018-06-19 Thread Chamin Dias
Hi, We are closing the vote due to the above issue. We will fix the issue and release another release candidate as soon as possible. Thanks. On Tue, Jun 19, 2018 at 2:03 PM, Thilini Shanika wrote: > Hi All, > > Found [1] while testing the distributed deployment of APIM. Hence -1 for > RC3. > >

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Dewni Weeraman
Hi, Tested below scenarios on IS 5.6.0-RC3 pack, - Invoke the OAuth Introspection Endpoint. - OAuth token revocation. - Entitlement policy creation using write policy in xml and publishing. - Using REST APIs via XACML to manage entitlement. - Create, update, get, delete an OAuth ap

Re: [Architecture] Micro Gateway CLI - Hashing Resources (APIs/Policies) for change detection

2018-06-19 Thread Isuru Haththotuwa
+1 for this approach. On Tue, Jun 19, 2018 at 1:47 PM, Malintha Amarasinghe wrote: > + IsuruH > > On Tue, Jun 19, 2018 at 12:41 PM, Malintha Amarasinghe > wrote: > >> List of fields planned to be added as of now; kindly let me know if any >> field is missing. >> >> *API* >> name >> context >> v

Re: [Architecture] [Dev] [VOTE] Release of WSO2 API Manager 2.5.0 RC3

2018-06-19 Thread Thilini Shanika
Hi All, Found [1] while testing the distributed deployment of APIM. Hence -1 for RC3. [1] https://github.com/wso2/product-apim/issues/3459 On Tue, Jun 19, 2018 at 11:11 AM, Dinusha Dissanayake wrote: > Hi all, > > Tested the following. > > Different user creations. ( admin, publisher and s

Re: [Architecture] Micro Gateway CLI - Hashing Resources (APIs/Policies) for change detection

2018-06-19 Thread Malintha Amarasinghe
+ IsuruH On Tue, Jun 19, 2018 at 12:41 PM, Malintha Amarasinghe wrote: > List of fields planned to be added as of now; kindly let me know if any > field is missing. > > *API* > name > context > version > apiDefinition > responseCaching > isDefaultVersion > type - (http vs ws) > transport - (http

Re: [Architecture] [Dev] [VOTE] Release of WSO2 Identity Server 5.6.0 RC3

2018-06-19 Thread Sathya Bandara
Hi all, I've tested following scenarios on the IS 5.6.0-RC3 pack. User management (add/update/remove users). User management in secondary userstores (Read-Write LDAP). Consent Management in SAML SSO. SAML to SAML federation. Creating workflows definitions for primary userstore users. Engaging/Dis

Re: [Architecture] Micro Gateway CLI - Hashing Resources (APIs/Policies) for change detection

2018-06-19 Thread Malintha Amarasinghe
List of fields planned to be added as of now; kindly let me know if any field is missing. *API* name context version apiDefinition responseCaching isDefaultVersion type - (http vs ws) transport - (http/https) endpointConfig endpointSecurity corsConfiguration authorizationHeader *SubscriptionThro