<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>jspwiki-user@incubator.apache.org Archives</title>
<link rel="self" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/?format=atom"/>
<link href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/"/>
<id>http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/</id>
<updated>2009-12-09T18:28:01Z</updated>
<entry>
<title>Re: How do you set $inlinedimages</title>
<author><name>Lana Frost &lt;Lana.Frost@Sun.COM&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c4B1CEDE9.3010801@sun.com%3e"/>
<id>urn:uuid:%3c4B1CEDE9-3010801@sun-com%3e</id>
<updated>2009-12-07T11:58:33Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Got it, thanks Foster.

Foster Schucker wrote:
&gt; There is a line in the property file that sets it.  Look around line 
&gt; 300 or so...
&gt;
&gt; Ours looks like this:
&gt;
&gt; jspwiki.translatorReader.inlinePattern.1 = *.jpg
&gt; jspwiki.translatorReader.inlinePattern.2 = *.JPG
&gt; jspwiki.translatorReader.inlinePattern.3 = *.gif
&gt; jspwiki.translatorReader.inlinePattern.4 = *.GIF
&gt; jspwiki.translatorReader.inlinePattern.5 = *.png
&gt; jspwiki.translatorReader.inlinePattern.6 = *.PNG
&gt;
&gt; Lana Frost wrote:
&gt;
&gt;&gt; Hi,
&gt;&gt;
&gt;&gt; Our wiki currently supports .png format only for inlined images.  I 
&gt;&gt; can't find where we set this variable so that we can upload .gif as 
&gt;&gt; well.
&gt;&gt;
&gt;&gt; Thanks for your help,
&gt;&gt; Lana
&gt;&gt;
&gt;&gt;
&gt;&gt;
&gt;



</pre>
</div>
</content>
</entry>
<entry>
<title>Re: How do you set $inlinedimages</title>
<author><name>Foster Schucker &lt;Foster@Schucker.org&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c4B1CEDB6.5000809@Schucker.org%3e"/>
<id>urn:uuid:%3c4B1CEDB6-5000809@Schucker-org%3e</id>
<updated>2009-12-07T11:57:42Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
There is a line in the property file that sets it.  Look around line 300 
or so...

Ours looks like this:

jspwiki.translatorReader.inlinePattern.1 = *.jpg
jspwiki.translatorReader.inlinePattern.2 = *.JPG
jspwiki.translatorReader.inlinePattern.3 = *.gif
jspwiki.translatorReader.inlinePattern.4 = *.GIF
jspwiki.translatorReader.inlinePattern.5 = *.png
jspwiki.translatorReader.inlinePattern.6 = *.PNG

Lana Frost wrote:

&gt; Hi,
&gt;
&gt; Our wiki currently supports .png format only for inlined images.  I 
&gt; can't find where we set this variable so that we can upload .gif as well.
&gt;
&gt; Thanks for your help,
&gt; Lana
&gt;
&gt;
&gt;



</pre>
</div>
</content>
</entry>
<entry>
<title>How do you set $inlinedimages</title>
<author><name>Lana Frost &lt;Lana.Frost@Sun.COM&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c4B1CEBC8.4020601@sun.com%3e"/>
<id>urn:uuid:%3c4B1CEBC8-4020601@sun-com%3e</id>
<updated>2009-12-07T11:49:28Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Hi,

Our wiki currently supports .png format only for inlined images.  I 
can't find where we set this variable so that we can upload .gif as well.

Thanks for your help,
Lana


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Can you update a JSPWiki page from outside the JSPWiki application?</title>
<author><name>Janne Jalkanen &lt;Janne.Jalkanen@ecyrd.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3cB3582E34-FAB4-4D8A-A02C-6D7396CA7F74@ecyrd.com%3e"/>
<id>urn:uuid:%3cB3582E34-FAB4-4D8A-A02C-6D7396CA7F74@ecyrd-com%3e</id>
<updated>2009-12-07T09:26:23Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>

Yes, they should be.  Again, since Lucene has its own update queue,  
which is not run immediately, it may take a few seconds for the  
results to update.

/Janne

On Dec 6, 2009, at 23:19 , Maduranga Kannangara wrote:

&gt; When you do changes to a certain page, directly from file system,  
&gt; does the Lucene indexes get updated?
&gt; i.e.: Does search results change, reflecting new changes?
&gt;
&gt; Thanks
&gt; Madu
&gt;
&gt; -----Original Message-----
&gt; From: Frank.Fitch@Sun.COM [mailto:Frank.Fitch@Sun.COM]
&gt; Sent: Saturday, 5 December 2009 4:02 AM
&gt; To: jspwiki-user@incubator.apache.org
&gt; Subject: Re: Can you update a JSPWiki page from outside the JSPWiki  
&gt; application?
&gt;
&gt; Carlson, Eric R wrote:
&gt;&gt; Is it possible to update a page within JSPWiki from an application  
&gt;&gt; outside of JSPWiki and have the new, modified page show up for
&gt;&gt; JSPWiki users?
&gt;
&gt; Yes. I do it all the time.
&gt;
&gt; Just create the page content with the wiki source syntax (or good  
&gt; old html if your wiki has html enabled). Copy the page into the
&gt; wiki content dir.
&gt;
&gt; You can modify an existing page or create new pages this way. If you  
&gt; create a new page, be sure the file name starts with an upper
&gt; case letter and ends with ".txt". this is required because of a flaw  
&gt; in the wiki.
&gt;
&gt; The wiki recognizes the changes immediately.
&gt;
&gt; You may want to make it clear in the source code comments and the  
&gt; page content that the page is automatically generated from an
&gt; external source. Your colleagues may become annoyed if their changes  
&gt; disappear. :)
&gt;
&gt; Regards,
&gt; -Frank



</pre>
</div>
</content>
</entry>
<entry>
<title>RE: Can you update a JSPWiki page from outside the JSPWiki application?</title>
<author><name>Maduranga Kannangara &lt;mkannangara@infomedia.com.au&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c5BFC50994978BD45AA5C557D45B4B8600EC8D95A87@exchsydmbx1.syd.infomedia.com.au%3e"/>
<id>urn:uuid:%3c5BFC50994978BD45AA5C557D45B4B8600EC8D95A87@exchsydmbx1-syd-infomedia-com-au%3e</id>
<updated>2009-12-06T21:19:14Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
When you do changes to a certain page, directly from file system, does the Lucene indexes get
updated?
i.e.: Does search results change, reflecting new changes?

Thanks
Madu

-----Original Message-----
From: Frank.Fitch@Sun.COM [mailto:Frank.Fitch@Sun.COM] 
Sent: Saturday, 5 December 2009 4:02 AM
To: jspwiki-user@incubator.apache.org
Subject: Re: Can you update a JSPWiki page from outside the JSPWiki application?

Carlson, Eric R wrote:
&gt; Is it possible to update a page within JSPWiki from an application outside of JSPWiki
and have the new, modified page show up for
&gt; JSPWiki users?

Yes. I do it all the time.

Just create the page content with the wiki source syntax (or good old html if your wiki has
html enabled). Copy the page into the 
wiki content dir.

You can modify an existing page or create new pages this way. If you create a new page, be
sure the file name starts with an upper 
case letter and ends with ".txt". this is required because of a flaw in the wiki.

The wiki recognizes the changes immediately.

You may want to make it clear in the source code comments and the page content that the page
is automatically generated from an 
external source. Your colleagues may become annoyed if their changes disappear. :)

Regards,
-Frank


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Statisticts on user activity</title>
<author><name>Harry Metske &lt;harry.metske@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c3a6c97f00912060540k49980e01w1f19d4ec27972289@mail.gmail.com%3e"/>
<id>urn:uuid:%3c3a6c97f00912060540k49980e01w1f19d4ec27972289@mail-gmail-com%3e</id>
<updated>2009-12-06T13:40:42Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
WikPageStatPlugin gets all his information from PageManager and
AttachmentManager, and is not very usefull for the type of statistics you
are looking for.
But I'd be happy to share the code.

A user list is already available in the SessionsPlugin.
Information about user edits is not stored anywhere now, but this could be
an enhancement (please file a JIRA issue at
https://issues.apache.org/jira/browse/JSPWIKI )

regards,
Harry

2009/12/5 lgilardoni61@gmail.com &lt;lgilardoni61@gmail.com&gt;

&gt; Harry
&gt;
&gt;
&gt; Harry Metske wrote:
&gt;
&gt;&gt; LG,
&gt;&gt;
&gt;&gt; not quite sure what kind of stats you are looking for, but I wrote a
&gt;&gt; plugin
&gt;&gt; a few months ago that gathers page statistics, including a summary.
&gt;&gt; Here you can see an example just to give you an idea :
&gt;&gt; http://www.computerhok.nl/JSPWiki/Wiki.jsp?page=TestWikiPageStatPlugin
&gt;&gt;
&gt;&gt;
&gt;&gt;
&gt; mor or less ... I'm more interested in statistics biased towards users
&gt; (e.g. user list, number of edits etc more than page list)
&gt; but the data is there.
&gt;
&gt;  It sure is not production ready, I would not run it on a very large wiki
&gt;&gt; (although it caches results).
&gt;&gt;
&gt;&gt;
&gt; I would be happy to give it a try - and possibly work on it if needed. Is
&gt; it already shared?
&gt;
&gt; Luca
&gt;
&gt; last ... 3.0? I'm still on 2.8
&gt;
&gt;  regards,
&gt;&gt; Harry
&gt;&gt;
&gt;&gt; 2009/12/4 lgilardoni61@gmail.com &lt;lgilardoni61@gmail.com&gt;
&gt;&gt;
&gt;&gt;
&gt;&gt;
&gt;&gt;&gt; Hi, is it possible (i.e. anthing already done) to get statistics about
&gt;&gt;&gt; usage (page changed) by users?
&gt;&gt;&gt; The info is there (from the page info one can see the whole history of
&gt;&gt;&gt; changes) but is there any plugin/code snippet already available or to
&gt;&gt;&gt; start
&gt;&gt;&gt; from?
&gt;&gt;&gt;
&gt;&gt;&gt; Tx in advance
&gt;&gt;&gt;
&gt;&gt;&gt; LG
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;
&gt;&gt;
&gt;&gt;
&gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Statisticts on user activity</title>
<author><name>&quot;lgilardoni61@gmail.com&quot; &lt;lgilardoni61@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c4B1A63DD.1010101@gmail.com%3e"/>
<id>urn:uuid:%3c4B1A63DD-1010101@gmail-com%3e</id>
<updated>2009-12-05T13:45:01Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Harry

Harry Metske wrote:
&gt; LG,
&gt;
&gt; not quite sure what kind of stats you are looking for, but I wrote a plugin
&gt; a few months ago that gathers page statistics, including a summary.
&gt; Here you can see an example just to give you an idea :
&gt; http://www.computerhok.nl/JSPWiki/Wiki.jsp?page=TestWikiPageStatPlugin
&gt;
&gt;   
mor or less ... I'm more interested in statistics biased towards users 
(e.g. user list, number of edits etc more than page list)
but the data is there.
&gt; It sure is not production ready, I would not run it on a very large wiki
&gt; (although it caches results).
&gt;   
I would be happy to give it a try - and possibly work on it if needed. 
Is it already shared?

Luca

last ... 3.0? I'm still on 2.8
&gt; regards,
&gt; Harry
&gt;
&gt; 2009/12/4 lgilardoni61@gmail.com &lt;lgilardoni61@gmail.com&gt;
&gt;
&gt;   
&gt;&gt; Hi, is it possible (i.e. anthing already done) to get statistics about
&gt;&gt; usage (page changed) by users?
&gt;&gt; The info is there (from the page info one can see the whole history of
&gt;&gt; changes) but is there any plugin/code snippet already available or to start
&gt;&gt; from?
&gt;&gt;
&gt;&gt; Tx in advance
&gt;&gt;
&gt;&gt; LG
&gt;&gt;
&gt;&gt;     
&gt;
&gt;   



</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Can you update a JSPWiki page from outside the JSPWiki application?</title>
<author><name>Janne Jalkanen &lt;janne.jalkanen@ecyrd.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3cFEC9E1EB-610C-4D3C-8534-DAB6992A8C8D@ecyrd.com%3e"/>
<id>urn:uuid:%3cFEC9E1EB-610C-4D3C-8534-DAB6992A8C8D@ecyrd-com%3e</id>
<updated>2009-12-05T12:50:13Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
&gt; The wiki recognizes the changes immediately.

To be specific, if you are using CachingProvider, it should happen within 30 seconds.

Note that the repository format will change in 3.0.

/Janne

</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Bocking Google Bot access</title>
<author><name>Harry Metske &lt;harry.metske@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c3a6c97f00912050204m4c20686fkc65899b8dacc7434@mail.gmail.com%3e"/>
<id>urn:uuid:%3c3a6c97f00912050204m4c20686fkc65899b8dacc7434@mail-gmail-com%3e</id>
<updated>2009-12-05T10:04:51Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
did you place robots.txt in the root of the web site hierarchy ?
Meaning the url for the robots.txt must be something like
http://mywonderfulsite.somewhere.org/robots.txt, and not ttp://
mywonderfulsite.somewhere.org/JSPWiki/robots.txt
Did you look at you access.log to see if robots.txt is asked for ?

/Harry

2009/12/5 Robert FORBES &lt;rforbes@highlinecorp.com&gt;

&gt; I don't want Google to index my pages, but I cannot find any means to block
&gt; it.  As a last ditch effort, I have put the JSPWiki installation behind a
&gt; firewall, but this is defeating the purpose for which it is intended.
&gt;
&gt; I am using Tomcat right now as the app server, and I have a robots.txt file
&gt; in the WebApps folder, the folder below that (where Wiki.jsp is), the
&gt; WEB_INF folder, and anywhere else I can think of.  The robots file looks
&gt; like this:
&gt;
&gt; User-agent: *
&gt; Disallow: /
&gt;
&gt; But it is not working.  Am I missing something obvious ? (likely)
&gt;
&gt; Robert
&gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Bocking Google Bot access</title>
<author><name>&quot;Robert FORBES&quot; &lt;rforbes@highlinecorp.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c007701ca7542$cc78a370$6569ea50$@com%3e"/>
<id>urn:uuid:%3c007701ca7542$cc78a370$6569ea50$@com%3e</id>
<updated>2009-12-05T00:35:08Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
I don't want Google to index my pages, but I cannot find any means to block it.  As a last
ditch effort, I have put the JSPWiki installation behind a firewall, but this is defeating
the purpose for which it is intended.

I am using Tomcat right now as the app server, and I have a robots.txt file in the WebApps
folder, the folder below that (where Wiki.jsp is), the WEB_INF folder, and anywhere else I
can think of.  The robots file looks like this:

User-agent: *
Disallow: /

But it is not working.  Am I missing something obvious ? (likely)

Robert



</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Statisticts on user activity</title>
<author><name>Harry Metske &lt;harry.metske@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c3a6c97f00912041253k77e0264ayf56dee945c6e03a8@mail.gmail.com%3e"/>
<id>urn:uuid:%3c3a6c97f00912041253k77e0264ayf56dee945c6e03a8@mail-gmail-com%3e</id>
<updated>2009-12-04T20:53:01Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
LG,

not quite sure what kind of stats you are looking for, but I wrote a plugin
a few months ago that gathers page statistics, including a summary.
Here you can see an example just to give you an idea :
http://www.computerhok.nl/JSPWiki/Wiki.jsp?page=TestWikiPageStatPlugin

It sure is not production ready, I would not run it on a very large wiki
(although it caches results).

regards,
Harry

2009/12/4 lgilardoni61@gmail.com &lt;lgilardoni61@gmail.com&gt;

&gt; Hi, is it possible (i.e. anthing already done) to get statistics about
&gt; usage (page changed) by users?
&gt; The info is there (from the page info one can see the whole history of
&gt; changes) but is there any plugin/code snippet already available or to start
&gt; from?
&gt;
&gt; Tx in advance
&gt;
&gt; LG
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Statisticts on user activity</title>
<author><name>&quot;lgilardoni61@gmail.com&quot; &lt;lgilardoni61@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c4B1943CE.2080604@gmail.com%3e"/>
<id>urn:uuid:%3c4B1943CE-2080604@gmail-com%3e</id>
<updated>2009-12-04T17:15:58Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Hi, is it possible (i.e. anthing already done) to get statistics about 
usage (page changed) by users?
The info is there (from the page info one can see the whole history of 
changes) but is there any plugin/code snippet already available or to 
start from?

Tx in advance

LG


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Can you update a JSPWiki page from outside the JSPWiki application?</title>
<author><name>Frank Fitch &lt;Frank.Fitch@Sun.COM&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c4B194074.9050002@sun.com%3e"/>
<id>urn:uuid:%3c4B194074-9050002@sun-com%3e</id>
<updated>2009-12-04T17:01:40Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Carlson, Eric R wrote:
&gt; Is it possible to update a page within JSPWiki from an application outside of JSPWiki
and have the new, modified page show up for
&gt; JSPWiki users?

Yes. I do it all the time.

Just create the page content with the wiki source syntax (or good old html if your wiki has
html enabled). Copy the page into the 
wiki content dir.

You can modify an existing page or create new pages this way. If you create a new page, be
sure the file name starts with an upper 
case letter and ends with ".txt". this is required because of a flaw in the wiki.

The wiki recognizes the changes immediately.

You may want to make it clear in the source code comments and the page content that the page
is automatically generated from an 
external source. Your colleagues may become annoyed if their changes disappear. :)

Regards,
-Frank


</pre>
</div>
</content>
</entry>
<entry>
<title>Can you update a JSPWiki page from outside the JSPWiki application?</title>
<author><name>&quot;Carlson, Eric R&quot; &lt;eric.carlson@kroger.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200912.mbox/%3c69D10C85DEEC6F4A9A939E41AD81151B86240E9661@N060XBOXPCMS05.kroger.com%3e"/>
<id>urn:uuid:%3c69D10C85DEEC6F4A9A939E41AD81151B86240E9661@N060XBOXPCMS05-kroger-com%3e</id>
<updated>2009-12-04T16:26:46Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Is it possible to update a page within JSPWiki from an application outside of JSPWiki and have
the new, modified page show up for JSPWiki users?

What I'm doing is using JSPWiki as a framework to deliver reports to users.  I have a page
that essentially shows a calendar with dates that have valid reports showing up as links,
and those that do not have valid reports showing up as un-clickable text.  This calendar page
consists of lots of inline HTML in a JSPWiki page, with links to individual JSPWiki pages
for each date.  Those individual 'date' pages consist of a list of links to the reports, which
are external to JSPWiki.

I have a routine to produce the reports on a daily basis and move them to their final destination
and I would like to automate the updating of the calendar to add each new date as I create
the reports, and to create a new 'date' page for the new reports.  The programming to update
the calendar and create the new date page are straightforward, and I don't need any help with
that.  I'm just wondering if JSPWiki will recognize the updated page, or if there is something
I need to do to refresh it.

Eric R. Carlson
Eric.Carlson@kroger.com
(513)-387-7739


________________________________
This e-mail message, including any attachments, is for the sole use of the intended recipient(s)
and may contain information that is confidential and protected by law from unauthorized disclosure.
Any unauthorized review, use, disclosure or distribution is prohibited. If you are not the
intended recipient, please contact the sender by reply e-mail and destroy all copies of the
original message.


</pre>
</div>
</content>
</entry>
<entry>
<title>JSPWiki 2.8.3</title>
<author><name>Janne Jalkanen &lt;Janne.Jalkanen@ecyrd.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200911.mbox/%3cCAF2A438-A370-4A88-9D5B-86FD0FDA87D2@ecyrd.com%3e"/>
<id>urn:uuid:%3cCAF2A438-A370-4A88-9D5B-86FD0FDA87D2@ecyrd-com%3e</id>
<updated>2009-11-17T20:40:46Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Folks,

we just rolled a new release of JSPWiki 2.8.3, available from the  
usual location at http://www.jspwiki.org/wiki/JSPWikiDownload/

JSPWiki 2.8.3 is a security and stability update to 2.8.x-series.  All  
users
are encouraged to upgrade.

The full log of any issues fixed can be found at:
https://issues.apache.org/jira/secure/IssueNavigator.jspa?reset=true&amp;pid=12310732&amp;fixfor=12313766

This is the first major version of JSPWiki which is released  
completely under
the Apache License.  This is done as a part of the transition to the
Apache Incubation.

However, this is NOT an Apache release - JSPWiki 3.0 will be the first
official Apache release.

Please report any issues at https://issues.apache.org/jira/browse/JSPWIKI

UPDATES SINCE 2.8.2
===================

The full list is available in the ChangeLog file.  Highlights include

* Improved logging

* JDK6 compilation support

* Brazilian Portuguese translation, thanks to Paulo Amaral

* Addition of new PageViewPlugin

* Numerous bugfixes, esp. in sorting.



</pre>
</div>
</content>
</entry>
<entry>
<title>Looking for right-to-left guinea pigs</title>
<author><name>Murray Altheim &lt;murray09@altheim.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200911.mbox/%3c4B006F4E.1080002@altheim.com%3e"/>
<id>urn:uuid:%3c4B006F4E-1080002@altheim-com%3e</id>
<updated>2009-11-15T21:14:54Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
[apologies for cross-posting; please respond only to the mailing list
in which you are a member, and if both, please post to jspwiki-dev]

Hello. The developer group recently learned that JSPWiki was passed up
by Sun Microsystems' OpenSolaris community wiki due to a number of
putative failings.  One of these is a lack of support for right-to-left
(RTL) text, such as Arabic, Hebrew, Punjabi, or Kashmiri. We'd like to
remedy that, but need some help, as none of our developers speak or
write an RTL language (to my knowledge).

If you or your organisation's wiki are currently using a right-to-left
script and are willing to provide us with feedback on any failings in
JSPWiki's implementation, we'd be very happy to work with you on fixing
those bugs. It would benefit the JSPWiki community as well as improving 
JSPWiki's support for your language. You can help contribute to world
happiness.

If you'd prefer not to provide that help on the public mailing list,
you can also contact me directly at:  murray09 at altheim dot com.

Thanks much for any help,

Murray

...........................................................................
Murray Altheim &lt;murray09 at altheim dot com&gt;                       ===  = =
http://www.altheim.com/murray/                                     = =  ===
SGML Grease Monkey, Banjo Player, Wantanabe Zen Monk               = =  = =

       Boundless wind and moon - the eye within eyes,
       Inexhaustible heaven and earth - the light beyond light,
       The willow dark, the flower bright - ten thousand houses,
       Knock at any door - there's one who will respond.
                                       -- The Blue Cliff Record


</pre>
</div>
</content>
</entry>
<entry>
<title>RE: ACL questions</title>
<author><name>Maduranga Kannangara &lt;mkannangara@infomedia.com.au&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c5BFC50994978BD45AA5C557D45B4B8600EC86020C4@exchsydmbx1.syd.infomedia.com.au%3e"/>
<id>urn:uuid:%3c5BFC50994978BD45AA5C557D45B4B8600EC86020C4@exchsydmbx1-syd-infomedia-com-au%3e</id>
<updated>2009-10-28T00:46:19Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Workaround I would use for this (Dirty way, of course..):
[{ALLOW upload Familie}]


-----Original Message-----
From: Harry Metske [mailto:harry.metske@gmail.com] 
Sent: Tuesday, 27 October 2009 5:42 AM
To: jspwiki-user@incubator.apache.org
Subject: Re: ACL questions

Harald,

are you sure this is not a browser caching issue, this problem has been
reported before : https://issues.apache.org/jira/browse/JSPWIKI-361

Also, can you reproduce the problem on http://sandbox.jspwiki.org ?

regards,
Harry

2009/10/26 Harald Krammer &lt;Harald.Krammer@hkr.at&gt;

&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt; Hash: SHA256
&gt;
&gt; Hello,
&gt; I am again. I played around with the permission concept e.g. [{ALLOW
&gt; edit harald}] and following questions are unclear for me.
&gt;
&gt; *) When I set page permissions, attachments are not
&gt; considered. e.g.  I made a side with permissions
&gt; [{ALLOW edit  hk}] and [{ALLOW view  Familie}] on side
&gt; https://xen.hkr.at/wiki/Wiki.jsp?page=secret
&gt; Permissions are fine, but a direct link to attachments on side secrete
&gt; works without any restrictions.
&gt; e.g.: https://xen.hkr.at/wiki/attach/Secret/non-public.txt
&gt;
&gt; Is that a limitation, a known issue, a bug or a wrong user usage?
&gt;
&gt; *) Exits an overview plug-in about permissions of all sides?
&gt; Currently I do it around with a shell script. I know it's the wrong way,
&gt; but easy for me to check permissions problems.
&gt;
&gt; *) Usage of if-plugin
&gt;
&gt; Currently I use the ifplugin, because it's easy to use. Exits a way to
&gt; disable 'view page source' for e.g. non authenticated users?
&gt;
&gt;
&gt; Nice greetings,
&gt; Harald
&gt;
&gt;
&gt; - --
&gt;
&gt; Harald Krammer
&gt; Brucknerstrasse 33
&gt; A - 4020  Linz
&gt; AUSTRIA
&gt;
&gt; Mobil +43.(0) 664. 130 59 58
&gt; Mail: Harald.Krammer (at) hkr.at
&gt; -----BEGIN PGP SIGNATURE-----
&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;
&gt; iEYEAREIAAYFAkrl60oACgkQ9QlAsubHO9tZdACg4iRRAaXN82thHPc5tClLah4b
&gt; QIAAni+/qATdb9f66KpAaIZ7Wkh079EQ
&gt; =J6Cn
&gt; -----END PGP SIGNATURE-----
&gt;

</pre>
</div>
</content>
</entry>
<entry>
<title>Re: ACL questions</title>
<author><name>Harald Krammer &lt;Harald.Krammer@hkr.at&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c4AE5F62C.60802@hkr.at%3e"/>
<id>urn:uuid:%3c4AE5F62C-60802@hkr-at%3e</id>
<updated>2009-10-26T19:19:08Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello Harry,
you are right. It's a browser issue.

When I clear the cache by hand in my browser then it works as expected.
Strange...  The refresh button did not work....

Here a few parts in the http-header:
If-Modified-Since: Mon, 26 Oct 2009 17:40:29 GMT
Cache-Control:max-age=0

If I can trust firebug then every refresh increases the cache expires
time!? ( I use firefox 3.0)

Nice greetings,
Harald

Harry Metske schrieb:
&gt; Harald,
&gt; 
&gt; are you sure this is not a browser caching issue, this problem has been
&gt; reported before : https://issues.apache.org/jira/browse/JSPWIKI-361
&gt; 
&gt; Also, can you reproduce the problem on http://sandbox.jspwiki.org ?
&gt; 
&gt; regards,
&gt; Harry
&gt; 
&gt; 2009/10/26 Harald Krammer &lt;Harald.Krammer@hkr.at&gt;
&gt; 
&gt; Hello,
&gt; I am again. I played around with the permission concept e.g. [{ALLOW
&gt; edit harald}] and following questions are unclear for me.
&gt; 
&gt; *) When I set page permissions, attachments are not
&gt; considered. e.g.  I made a side with permissions
&gt; [{ALLOW edit  hk}] and [{ALLOW view  Familie}] on side
&gt; https://xen.hkr.at/wiki/Wiki.jsp?page=secret
&gt; Permissions are fine, but a direct link to attachments on side secrete
&gt; works without any restrictions.
&gt; e.g.: https://xen.hkr.at/wiki/attach/Secret/non-public.txt
&gt; 
&gt; Is that a limitation, a known issue, a bug or a wrong user usage?
&gt; 
&gt; *) Exits an overview plug-in about permissions of all sides?
&gt; Currently I do it around with a shell script. I know it's the wrong way,
&gt; but easy for me to check permissions problems.
&gt; 
&gt; *) Usage of if-plugin
&gt; 
&gt; Currently I use the ifplugin, because it's easy to use. Exits a way to
&gt; disable 'view page source' for e.g. non authenticated users?
&gt; 
&gt; 
&gt; Nice greetings,
&gt; Harald
&gt; 
&gt; 
&gt;&gt;

- --

Harald Krammer
Brucknerstrasse 33
A - 4020  Linz
AUSTRIA

Mobil +43.(0) 664. 130 59 58
Mail: Harald.Krammer (at) hkr.at
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEAREIAAYFAkrl9icACgkQ9QlAsubHO9td+ACfWrhnEvxa7YAqdRZrjZYteaKD
xOwAn1QANqIE3dy07a0f8/jpbCNgIDg1
=EY8Z
-----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: ACL questions</title>
<author><name>Harry Metske &lt;harry.metske@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c3a6c97f00910261142me39279iad1ae29ed5f1feca@mail.gmail.com%3e"/>
<id>urn:uuid:%3c3a6c97f00910261142me39279iad1ae29ed5f1feca@mail-gmail-com%3e</id>
<updated>2009-10-26T18:42:18Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Harald,

are you sure this is not a browser caching issue, this problem has been
reported before : https://issues.apache.org/jira/browse/JSPWIKI-361

Also, can you reproduce the problem on http://sandbox.jspwiki.org ?

regards,
Harry

2009/10/26 Harald Krammer &lt;Harald.Krammer@hkr.at&gt;

&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt; Hash: SHA256
&gt;
&gt; Hello,
&gt; I am again. I played around with the permission concept e.g. [{ALLOW
&gt; edit harald}] and following questions are unclear for me.
&gt;
&gt; *) When I set page permissions, attachments are not
&gt; considered. e.g.  I made a side with permissions
&gt; [{ALLOW edit  hk}] and [{ALLOW view  Familie}] on side
&gt; https://xen.hkr.at/wiki/Wiki.jsp?page=secret
&gt; Permissions are fine, but a direct link to attachments on side secrete
&gt; works without any restrictions.
&gt; e.g.: https://xen.hkr.at/wiki/attach/Secret/non-public.txt
&gt;
&gt; Is that a limitation, a known issue, a bug or a wrong user usage?
&gt;
&gt; *) Exits an overview plug-in about permissions of all sides?
&gt; Currently I do it around with a shell script. I know it's the wrong way,
&gt; but easy for me to check permissions problems.
&gt;
&gt; *) Usage of if-plugin
&gt;
&gt; Currently I use the ifplugin, because it's easy to use. Exits a way to
&gt; disable 'view page source' for e.g. non authenticated users?
&gt;
&gt;
&gt; Nice greetings,
&gt; Harald
&gt;
&gt;
&gt; - --
&gt;
&gt; Harald Krammer
&gt; Brucknerstrasse 33
&gt; A - 4020  Linz
&gt; AUSTRIA
&gt;
&gt; Mobil +43.(0) 664. 130 59 58
&gt; Mail: Harald.Krammer (at) hkr.at
&gt; -----BEGIN PGP SIGNATURE-----
&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;
&gt; iEYEAREIAAYFAkrl60oACgkQ9QlAsubHO9tZdACg4iRRAaXN82thHPc5tClLah4b
&gt; QIAAni+/qATdb9f66KpAaIZ7Wkh079EQ
&gt; =J6Cn
&gt; -----END PGP SIGNATURE-----
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>ACL questions</title>
<author><name>Harald Krammer &lt;Harald.Krammer@hkr.at&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c4AE5EB54.6070300@hkr.at%3e"/>
<id>urn:uuid:%3c4AE5EB54-6070300@hkr-at%3e</id>
<updated>2009-10-26T18:32:52Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello,
I am again. I played around with the permission concept e.g. [{ALLOW
edit harald}] and following questions are unclear for me.

*) When I set page permissions, attachments are not
considered. e.g.  I made a side with permissions
[{ALLOW edit  hk}] and [{ALLOW view  Familie}] on side
https://xen.hkr.at/wiki/Wiki.jsp?page=secret
Permissions are fine, but a direct link to attachments on side secrete
works without any restrictions.
e.g.: https://xen.hkr.at/wiki/attach/Secret/non-public.txt

Is that a limitation, a known issue, a bug or a wrong user usage?

*) Exits an overview plug-in about permissions of all sides?
Currently I do it around with a shell script. I know it's the wrong way,
but easy for me to check permissions problems.

*) Usage of if-plugin

Currently I use the ifplugin, because it's easy to use. Exits a way to
disable 'view page source' for e.g. non authenticated users?


Nice greetings,
Harald


- --

Harald Krammer
Brucknerstrasse 33
A - 4020  Linz
AUSTRIA

Mobil +43.(0) 664. 130 59 58
Mail: Harald.Krammer (at) hkr.at
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEAREIAAYFAkrl60oACgkQ9QlAsubHO9tZdACg4iRRAaXN82thHPc5tClLah4b
QIAAni+/qATdb9f66KpAaIZ7Wkh079EQ
=J6Cn
-----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cACA8456D-2707-4D56-9143-641430CEC343@gmail.com%3e"/>
<id>urn:uuid:%3cACA8456D-2707-4D56-9143-641430CEC343@gmail-com%3e</id>
<updated>2009-10-25T11:15:00Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
...you check out the trunk and look at the javadocs, which are  
extremely well-documented.

Sorry my reply came as a serialization... I did it one-handed on the  
iPhone and fat-fingered TWICE.

Andrew

On Oct 25, 2009, at 7:10, Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;  
wrote:

&gt; Sorry-- I fat-fingered the send button!
&gt;
&gt; Anyhow, with the LdapUserDatabase you won't need to provision or  
&gt; deprovision because everything will be in LDAP. We will keep some  
&gt; data locally (user prefs) but that's it.
&gt;
&gt; At this point, if you still have concerns I'd recommend yo
&gt;
&gt; On Oct 25, 2009, at 7:04, Andrew Jaquith   
&gt; &lt;andrew.r.jaquith@gmail.com&gt; wrote:
&gt;
&gt;&gt; I should not have used the magic word "provision" in my last post.  
&gt;&gt; The important concept is that when the LdapUserDatabase is used,  
&gt;&gt; LDAP *is* the user database
&gt;&gt;
&gt;&gt; On Oct 25, 2009, at 6:38, Jim Willeke &lt;jim@willeke.com&gt; wrote:
&gt;&gt;
&gt;&gt;&gt; But what about de-provisioning users?
&gt;&gt;&gt;
&gt;&gt;&gt; The issue with putting users in yet another database in the  
&gt;&gt;&gt; enterprise world
&gt;&gt;&gt; central provisioning, de-provisioning and RBAC are the strategic  
&gt;&gt;&gt; directions
&gt;&gt;&gt; with no desire to mange users in remote stores.
&gt;&gt;&gt;
&gt;&gt;&gt; And why would someone want to put in information into the WIKI  
&gt;&gt;&gt; when it is
&gt;&gt;&gt; already been add to the user in LDAP via the enterprise portal?
&gt;&gt;&gt;
&gt;&gt;&gt; I will agree the local "groups" concept is necessary, but it  
&gt;&gt;&gt; should be an
&gt;&gt;&gt; agumnetation to container managed security that most enterprises  
&gt;&gt;&gt; would
&gt;&gt;&gt; utilize.
&gt;&gt;&gt;
&gt;&gt;&gt; So users in the role (perhaps by department) "Sales" would always  
&gt;&gt;&gt; be able to
&gt;&gt;&gt; view any pages with "Sales":
&gt;&gt;&gt;
&gt;&gt;&gt; Then the local "groups" would be done to perform "teaming"  
&gt;&gt;&gt; arrangements as
&gt;&gt;&gt; would be done in a project that would cross departmental lines.
&gt;&gt;&gt;
&gt;&gt;&gt; -jim
&gt;&gt;&gt; Jim Willeke
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; On Sat, Oct 24, 2009 at 11:12 AM, Andrew Jaquith &lt;andrew.r.jaquith@gmail.com
&gt;&gt;&gt;&gt; wrote:
&gt;&gt;&gt;
&gt;&gt;&gt;&gt; JSPWiki 3.0 trunk already has an LdapUserDatabase and  
&gt;&gt;&gt;&gt; LdapAuthorizer,
&gt;&gt;&gt;&gt; which means that it can obtain user profiles on a read-only basis  
&gt;&gt;&gt;&gt; from
&gt;&gt;&gt;&gt; LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
&gt;&gt;&gt;&gt; users will be "provisioned" in JSPWiki automatically. This should
&gt;&gt;&gt;&gt; solve the user-experience problem you described.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; The upcoming 3.0 LDAP features have been developed and tested with
&gt;&gt;&gt;&gt; Active Directory and OpenLDAP. It is configured via the GUI at
&gt;&gt;&gt;&gt; install-time.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; With respect to permissions and group memberships: these are good
&gt;&gt;&gt;&gt; suggestions. We still have some work to do for the GUI for ACLs for
&gt;&gt;&gt;&gt; 3.0. I agree that we should be validating user names when users  
&gt;&gt;&gt;&gt; create
&gt;&gt;&gt;&gt; the ACLs. Same for adding users to groups. These suggestions will  
&gt;&gt;&gt;&gt; be
&gt;&gt;&gt;&gt; incorporated into how the ACL GUIs work -- likely via AJAX in
&gt;&gt;&gt;&gt; real-time.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt  
&gt;&gt;&gt;&gt; &lt;te@zama.org&gt; wrote:
&gt;&gt;&gt;&gt;&gt; The group and permission system in the jspwiki is rather  
&gt;&gt;&gt;&gt;&gt; dynamic, and
&gt;&gt;&gt;&gt; ldaps
&gt;&gt;&gt;&gt;&gt; tends to be readonly except for a groups of administrators.  
&gt;&gt;&gt;&gt;&gt; There for
&gt;&gt;&gt;&gt; there
&gt;&gt;&gt;&gt;&gt; is still need for the user.xml and group.xml. But in my opinion  
&gt;&gt;&gt;&gt;&gt; the
&gt;&gt;&gt;&gt; user.xml
&gt;&gt;&gt;&gt;&gt; needs to be automatically updated when a new ldap user is logged  
&gt;&gt;&gt;&gt;&gt; in.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Otherwise granting and managing jspwiki permissions i a  
&gt;&gt;&gt;&gt;&gt; nightmare, this
&gt;&gt;&gt;&gt; also
&gt;&gt;&gt;&gt;&gt; enhanced since there is no check on if a user exist - when  
&gt;&gt;&gt;&gt;&gt; adding users
&gt;&gt;&gt;&gt; to
&gt;&gt;&gt;&gt;&gt; wiki group or setting a page permission.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; I think the following should be changed.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; - First time a new user is logged in - the user should be added  
&gt;&gt;&gt;&gt;&gt; to the
&gt;&gt;&gt;&gt; the
&gt;&gt;&gt;&gt;&gt; user.xml and redirect to the profile page for setting additional
&gt;&gt;&gt;&gt; information
&gt;&gt;&gt;&gt;&gt; (email, full name and section edition etc)
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; - Adding page permission should lookup if the group or the user  
&gt;&gt;&gt;&gt;&gt; exist.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; - Adding users to a wiki group should only be possible for  
&gt;&gt;&gt;&gt;&gt; existing
&gt;&gt;&gt;&gt; users.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; /Thomas
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Why allow people to eliminate the user.xml?
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Why not allow the use of LDAP for the user profile?
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Enterprises have no desire to maintain another separate user  
&gt;&gt;&gt;&gt;&gt;&gt; store of
&gt;&gt;&gt;&gt;&gt;&gt; information. Many already have a central LDAP store.
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; -jim
&gt;&gt;&gt;&gt;&gt;&gt; Jim Willeke
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt  
&gt;&gt;&gt;&gt;&gt;&gt; &lt;te@zama.org&gt;
&gt;&gt;&gt;&gt; wrote:
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; time.
&gt;&gt;&gt;&gt; the
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; of problem
&gt;&gt;&gt;&gt;&gt;&gt;&gt; when
&gt;&gt;&gt;&gt;&gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; user
&gt;&gt;&gt;&gt; isn't
&gt;&gt;&gt;&gt;&gt;&gt;&gt; created.
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; If a user creates a user profile after logging into the  
&gt;&gt;&gt;&gt;&gt;&gt;&gt; container, he
&gt;&gt;&gt;&gt; or
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If
a  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; full name
&gt;&gt;&gt;&gt; is
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that
point
&gt;&gt;&gt;&gt; forward.
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at

&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; &gt;
&gt;&gt;&gt;&gt; wrote:
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP
and  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; it runs
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20,
OpenJDK  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; 6).
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing.
I  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; get only
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name
in the  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; change
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; misconfiguration?
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/

&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; HrqMiWfZ
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c36677059-DBA7-40D0-B9CC-5719F5D80C88@gmail.com%3e"/>
<id>urn:uuid:%3c36677059-DBA7-40D0-B9CC-5719F5D80C88@gmail-com%3e</id>
<updated>2009-10-25T11:10:36Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Sorry-- I fat-fingered the send button!

Anyhow, with the LdapUserDatabase you won't need to provision or  
deprovision because everything will be in LDAP. We will keep some data  
locally (user prefs) but that's it.

At this point, if you still have concerns I'd recommend yo

On Oct 25, 2009, at 7:04, Andrew Jaquith  &lt;andrew.r.jaquith@gmail.com&gt;  
wrote:

&gt; I should not have used the magic word "provision" in my last post.  
&gt; The important concept is that when the LdapUserDatabase is used,  
&gt; LDAP *is* the user database
&gt;
&gt; On Oct 25, 2009, at 6:38, Jim Willeke &lt;jim@willeke.com&gt; wrote:
&gt;
&gt;&gt; But what about de-provisioning users?
&gt;&gt;
&gt;&gt; The issue with putting users in yet another database in the  
&gt;&gt; enterprise world
&gt;&gt; central provisioning, de-provisioning and RBAC are the strategic  
&gt;&gt; directions
&gt;&gt; with no desire to mange users in remote stores.
&gt;&gt;
&gt;&gt; And why would someone want to put in information into the WIKI when  
&gt;&gt; it is
&gt;&gt; already been add to the user in LDAP via the enterprise portal?
&gt;&gt;
&gt;&gt; I will agree the local "groups" concept is necessary, but it should  
&gt;&gt; be an
&gt;&gt; agumnetation to container managed security that most enterprises  
&gt;&gt; would
&gt;&gt; utilize.
&gt;&gt;
&gt;&gt; So users in the role (perhaps by department) "Sales" would always  
&gt;&gt; be able to
&gt;&gt; view any pages with "Sales":
&gt;&gt;
&gt;&gt; Then the local "groups" would be done to perform "teaming"  
&gt;&gt; arrangements as
&gt;&gt; would be done in a project that would cross departmental lines.
&gt;&gt;
&gt;&gt; -jim
&gt;&gt; Jim Willeke
&gt;&gt;
&gt;&gt;
&gt;&gt; On Sat, Oct 24, 2009 at 11:12 AM, Andrew Jaquith &lt;andrew.r.jaquith@gmail.com
&gt;&gt;&gt; wrote:
&gt;&gt;
&gt;&gt;&gt; JSPWiki 3.0 trunk already has an LdapUserDatabase and  
&gt;&gt;&gt; LdapAuthorizer,
&gt;&gt;&gt; which means that it can obtain user profiles on a read-only basis  
&gt;&gt;&gt; from
&gt;&gt;&gt; LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
&gt;&gt;&gt; users will be "provisioned" in JSPWiki automatically. This should
&gt;&gt;&gt; solve the user-experience problem you described.
&gt;&gt;&gt;
&gt;&gt;&gt; The upcoming 3.0 LDAP features have been developed and tested with
&gt;&gt;&gt; Active Directory and OpenLDAP. It is configured via the GUI at
&gt;&gt;&gt; install-time.
&gt;&gt;&gt;
&gt;&gt;&gt; With respect to permissions and group memberships: these are good
&gt;&gt;&gt; suggestions. We still have some work to do for the GUI for ACLs for
&gt;&gt;&gt; 3.0. I agree that we should be validating user names when users  
&gt;&gt;&gt; create
&gt;&gt;&gt; the ACLs. Same for adding users to groups. These suggestions will be
&gt;&gt;&gt; incorporated into how the ACL GUIs work -- likely via AJAX in
&gt;&gt;&gt; real-time.
&gt;&gt;&gt;
&gt;&gt;&gt; Andrew
&gt;&gt;&gt;
&gt;&gt;&gt; On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt &lt;te@zama.org&gt;  
&gt;&gt;&gt; wrote:
&gt;&gt;&gt;&gt; The group and permission system in the jspwiki is rather dynamic,  
&gt;&gt;&gt;&gt; and
&gt;&gt;&gt; ldaps
&gt;&gt;&gt;&gt; tends to be readonly except for a groups of administrators. There  
&gt;&gt;&gt;&gt; for
&gt;&gt;&gt; there
&gt;&gt;&gt;&gt; is still need for the user.xml and group.xml. But in my opinion the
&gt;&gt;&gt; user.xml
&gt;&gt;&gt;&gt; needs to be automatically updated when a new ldap user is logged  
&gt;&gt;&gt;&gt; in.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Otherwise granting and managing jspwiki permissions i a  
&gt;&gt;&gt;&gt; nightmare, this
&gt;&gt;&gt; also
&gt;&gt;&gt;&gt; enhanced since there is no check on if a user exist - when adding  
&gt;&gt;&gt;&gt; users
&gt;&gt;&gt; to
&gt;&gt;&gt;&gt; wiki group or setting a page permission.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; I think the following should be changed.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; - First time a new user is logged in - the user should be added  
&gt;&gt;&gt;&gt; to the
&gt;&gt;&gt; the
&gt;&gt;&gt;&gt; user.xml and redirect to the profile page for setting additional
&gt;&gt;&gt; information
&gt;&gt;&gt;&gt; (email, full name and section edition etc)
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; - Adding page permission should lookup if the group or the user  
&gt;&gt;&gt;&gt; exist.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; - Adding users to a wiki group should only be possible for existing
&gt;&gt;&gt; users.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; /Thomas
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Why allow people to eliminate the user.xml?
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Why not allow the use of LDAP for the user profile?
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Enterprises have no desire to maintain another separate user  
&gt;&gt;&gt;&gt;&gt; store of
&gt;&gt;&gt;&gt;&gt; information. Many already have a central LDAP store.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; -jim
&gt;&gt;&gt;&gt;&gt; Jim Willeke
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt;
&gt;&gt;&gt; wrote:
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first  
&gt;&gt;&gt;&gt;&gt;&gt; time.
&gt;&gt;&gt; the
&gt;&gt;&gt;&gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of 

&gt;&gt;&gt;&gt;&gt;&gt; problem
&gt;&gt;&gt;&gt;&gt;&gt; when
&gt;&gt;&gt;&gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the  
&gt;&gt;&gt;&gt;&gt;&gt; user
&gt;&gt;&gt; isn't
&gt;&gt;&gt;&gt;&gt;&gt; created.
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; If a user creates a user profile after logging into the  
&gt;&gt;&gt;&gt;&gt;&gt; container, he
&gt;&gt;&gt; or
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a 

&gt;&gt;&gt;&gt;&gt;&gt;&gt; full name
&gt;&gt;&gt; is
&gt;&gt;&gt;&gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that point
&gt;&gt;&gt; forward.
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer  
&gt;&gt;&gt;&gt;&gt;&gt;&gt; &lt;Harald.Krammer@hkr.at&gt;
&gt;&gt;&gt; wrote:
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP
and  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; it runs
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; 6).
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing.
I  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; get only
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; change
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or  
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; misconfiguration?
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/

&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; HrqMiWfZ
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cF1462798-89B3-4C51-92AF-C3B684559DF9@gmail.com%3e"/>
<id>urn:uuid:%3cF1462798-89B3-4C51-92AF-C3B684559DF9@gmail-com%3e</id>
<updated>2009-10-25T11:04:51Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
I should not have used the magic word "provision" in my last post. The  
important concept is that when the LdapUserDatabase is used, LDAP *is*  
the user database

On Oct 25, 2009, at 6:38, Jim Willeke &lt;jim@willeke.com&gt; wrote:

&gt; But what about de-provisioning users?
&gt;
&gt; The issue with putting users in yet another database in the  
&gt; enterprise world
&gt; central provisioning, de-provisioning and RBAC are the strategic  
&gt; directions
&gt; with no desire to mange users in remote stores.
&gt;
&gt; And why would someone want to put in information into the WIKI when  
&gt; it is
&gt; already been add to the user in LDAP via the enterprise portal?
&gt;
&gt; I will agree the local "groups" concept is necessary, but it should  
&gt; be an
&gt; agumnetation to container managed security that most enterprises would
&gt; utilize.
&gt;
&gt; So users in the role (perhaps by department) "Sales" would always be  
&gt; able to
&gt; view any pages with "Sales":
&gt;
&gt; Then the local "groups" would be done to perform "teaming"  
&gt; arrangements as
&gt; would be done in a project that would cross departmental lines.
&gt;
&gt; -jim
&gt; Jim Willeke
&gt;
&gt;
&gt; On Sat, Oct 24, 2009 at 11:12 AM, Andrew Jaquith &lt;andrew.r.jaquith@gmail.com
&gt;&gt; wrote:
&gt;
&gt;&gt; JSPWiki 3.0 trunk already has an LdapUserDatabase and LdapAuthorizer,
&gt;&gt; which means that it can obtain user profiles on a read-only basis  
&gt;&gt; from
&gt;&gt; LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
&gt;&gt; users will be "provisioned" in JSPWiki automatically. This should
&gt;&gt; solve the user-experience problem you described.
&gt;&gt;
&gt;&gt; The upcoming 3.0 LDAP features have been developed and tested with
&gt;&gt; Active Directory and OpenLDAP. It is configured via the GUI at
&gt;&gt; install-time.
&gt;&gt;
&gt;&gt; With respect to permissions and group memberships: these are good
&gt;&gt; suggestions. We still have some work to do for the GUI for ACLs for
&gt;&gt; 3.0. I agree that we should be validating user names when users  
&gt;&gt; create
&gt;&gt; the ACLs. Same for adding users to groups. These suggestions will be
&gt;&gt; incorporated into how the ACL GUIs work -- likely via AJAX in
&gt;&gt; real-time.
&gt;&gt;
&gt;&gt; Andrew
&gt;&gt;
&gt;&gt; On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt &lt;te@zama.org&gt;  
&gt;&gt; wrote:
&gt;&gt;&gt; The group and permission system in the jspwiki is rather dynamic,  
&gt;&gt;&gt; and
&gt;&gt; ldaps
&gt;&gt;&gt; tends to be readonly except for a groups of administrators. There  
&gt;&gt;&gt; for
&gt;&gt; there
&gt;&gt;&gt; is still need for the user.xml and group.xml. But in my opinion the
&gt;&gt; user.xml
&gt;&gt;&gt; needs to be automatically updated when a new ldap user is logged in.
&gt;&gt;&gt;
&gt;&gt;&gt; Otherwise granting and managing jspwiki permissions i a nightmare,  
&gt;&gt;&gt; this
&gt;&gt; also
&gt;&gt;&gt; enhanced since there is no check on if a user exist - when adding  
&gt;&gt;&gt; users
&gt;&gt; to
&gt;&gt;&gt; wiki group or setting a page permission.
&gt;&gt;&gt;
&gt;&gt;&gt; I think the following should be changed.
&gt;&gt;&gt;
&gt;&gt;&gt; - First time a new user is logged in - the user should be added to  
&gt;&gt;&gt; the
&gt;&gt; the
&gt;&gt;&gt; user.xml and redirect to the profile page for setting additional
&gt;&gt; information
&gt;&gt;&gt; (email, full name and section edition etc)
&gt;&gt;&gt;
&gt;&gt;&gt; - Adding page permission should lookup if the group or the user  
&gt;&gt;&gt; exist.
&gt;&gt;&gt;
&gt;&gt;&gt; - Adding users to a wiki group should only be possible for existing
&gt;&gt; users.
&gt;&gt;&gt;
&gt;&gt;&gt; /Thomas
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Why allow people to eliminate the user.xml?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Why not allow the use of LDAP for the user profile?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Enterprises have no desire to maintain another separate user  
&gt;&gt;&gt;&gt; store of
&gt;&gt;&gt;&gt; information. Many already have a central LDAP store.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; -jim
&gt;&gt;&gt;&gt; Jim Willeke
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt;
&gt;&gt; wrote:
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first  
&gt;&gt;&gt;&gt;&gt; time.
&gt;&gt; the
&gt;&gt;&gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of  
&gt;&gt;&gt;&gt;&gt; problem
&gt;&gt;&gt;&gt;&gt; when
&gt;&gt;&gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the  
&gt;&gt;&gt;&gt;&gt; user
&gt;&gt; isn't
&gt;&gt;&gt;&gt;&gt; created.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; If a user creates a user profile after logging into the  
&gt;&gt;&gt;&gt;&gt; container, he
&gt;&gt; or
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a  
&gt;&gt;&gt;&gt;&gt;&gt; full name
&gt;&gt; is
&gt;&gt;&gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that point
&gt;&gt; forward.
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt;
&gt;&gt; wrote:
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; it runs
&gt;&gt;&gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK
6).
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing. I
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; get only
&gt;&gt;&gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the 

&gt;&gt;&gt;&gt;&gt;&gt;&gt; change
&gt;&gt;&gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or  
&gt;&gt;&gt;&gt;&gt;&gt;&gt; misconfiguration?
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt;&gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cB697404A-9E61-4DB7-A14A-2BF092EC658C@gmail.com%3e"/>
<id>urn:uuid:%3cB697404A-9E61-4DB7-A14A-2BF092EC658C@gmail-com%3e</id>
<updated>2009-10-25T11:01:02Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
It is still too early. I don't have an estimate of when you can start  
testing. We would Iike to get an alpha out soon, obviously.

On Oct 25, 2009, at 5:30, Harald Krammer &lt;Harald.Krammer@hkr.at&gt; wrote:

&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt; Hash: SHA256
&gt;
&gt; That sounds interesting.
&gt; It is noted that the trunk is heavily under construction and the  
&gt; code is
&gt; broken. Does it make sense to test current trunk version or is it  
&gt; too early?
&gt;
&gt; Greetings,
&gt; Harald
&gt;
&gt; Andrew Jaquith schrieb:
&gt;&gt; JSPWiki 3.0 trunk already has an LdapUserDatabase and LdapAuthorizer,
&gt;&gt; which means that it can obtain user profiles on a read-only basis  
&gt;&gt; from
&gt;&gt; LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
&gt;&gt; users will be "provisioned" in JSPWiki automatically. This should
&gt;&gt; solve the user-experience problem you described.
&gt;&gt;
&gt;&gt; The upcoming 3.0 LDAP features have been developed and tested with
&gt;&gt; Active Directory and OpenLDAP. It is configured via the GUI at
&gt;&gt; install-time.
&gt;&gt;
&gt;&gt; With respect to permissions and group memberships: these are good
&gt;&gt; suggestions. We still have some work to do for the GUI for ACLs for
&gt;&gt; 3.0. I agree that we should be validating user names when users  
&gt;&gt; create
&gt;&gt; the ACLs. Same for adding users to groups. These suggestions will be
&gt;&gt; incorporated into how the ACL GUIs work -- likely via AJAX in
&gt;&gt; real-time.
&gt;&gt;
&gt;&gt; Andrew
&gt;&gt;
&gt;&gt; On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt &lt;te@zama.org&gt;  
&gt;&gt; wrote:
&gt;&gt;&gt; The group and permission system in the jspwiki is rather dynamic,  
&gt;&gt;&gt; and ldaps
&gt;&gt;&gt; tends to be readonly except for a groups of administrators. There  
&gt;&gt;&gt; for there
&gt;&gt;&gt; is still need for the user.xml and group.xml. But in my opinion  
&gt;&gt;&gt; the user.xml
&gt;&gt;&gt; needs to be automatically updated when a new ldap user is logged in.
&gt;&gt;&gt;
&gt;&gt;&gt; Otherwise granting and managing jspwiki permissions i a nightmare,  
&gt;&gt;&gt; this also
&gt;&gt;&gt; enhanced since there is no check on if a user exist - when adding  
&gt;&gt;&gt; users to
&gt;&gt;&gt; wiki group or setting a page permission.
&gt;&gt;&gt;
&gt;&gt;&gt; I think the following should be changed.
&gt;&gt;&gt;
&gt;&gt;&gt; - First time a new user is logged in - the user should be added to  
&gt;&gt;&gt; the the
&gt;&gt;&gt; user.xml and redirect to the profile page for setting additional  
&gt;&gt;&gt; information
&gt;&gt;&gt; (email, full name and section edition etc)
&gt;&gt;&gt;
&gt;&gt;&gt; - Adding page permission should lookup if the group or the user  
&gt;&gt;&gt; exist.
&gt;&gt;&gt;
&gt;&gt;&gt; - Adding users to a wiki group should only be possible for  
&gt;&gt;&gt; existing users.
&gt;&gt;&gt;
&gt;&gt;&gt; /Thomas
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Why allow people to eliminate the user.xml?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Why not allow the use of LDAP for the user profile?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Enterprises have no desire to maintain another separate user  
&gt;&gt;&gt;&gt; store of
&gt;&gt;&gt;&gt; information. Many already have a central LDAP store.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; -jim
&gt;&gt;&gt;&gt; Jim Willeke
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt  
&gt;&gt;&gt;&gt; &lt;te@zama.org&gt; wrote:
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first  
&gt;&gt;&gt;&gt;&gt; time.  the
&gt;&gt;&gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of  
&gt;&gt;&gt;&gt;&gt; problem
&gt;&gt;&gt;&gt;&gt; when
&gt;&gt;&gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the  
&gt;&gt;&gt;&gt;&gt; user isn't
&gt;&gt;&gt;&gt;&gt; created.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; If a user creates a user profile after logging into the  
&gt;&gt;&gt;&gt;&gt; container, he or
&gt;&gt;&gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a  
&gt;&gt;&gt;&gt;&gt;&gt; full name is
&gt;&gt;&gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that point 

&gt;&gt;&gt;&gt;&gt;&gt; forward.
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer  
&gt;&gt;&gt;&gt;&gt;&gt; &lt;Harald.Krammer@hkr.at&gt; wrote:
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; it runs
&gt;&gt;&gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK
6).
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing. I
 
&gt;&gt;&gt;&gt;&gt;&gt;&gt; get only
&gt;&gt;&gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the 

&gt;&gt;&gt;&gt;&gt;&gt;&gt; change
&gt;&gt;&gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or  
&gt;&gt;&gt;&gt;&gt;&gt;&gt; misconfiguration?
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt;&gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;
&gt;
&gt;
&gt; - --
&gt;
&gt; Harald Krammer
&gt; Brucknerstrasse 33
&gt; A - 4020  Linz
&gt; AUSTRIA
&gt;
&gt; Mobil +43.(0) 664. 130 59 58
&gt; Mail: Harald.Krammer (at) hkr.at
&gt; -----BEGIN PGP SIGNATURE-----
&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;
&gt; iEYEAREIAAYFAkrkGqEACgkQ9QlAsubHO9vsYACgriH34OZiGCZq6Ac2DayNJnd3
&gt; SKQAni/X1DtibeNEbZKtnzNAe+OHUwt2
&gt; =KwyM
&gt; -----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Jim Willeke &lt;jim@willeke.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cb662a94e0910250338w4fb0e4bdjbc11eaab63143cf6@mail.gmail.com%3e"/>
<id>urn:uuid:%3cb662a94e0910250338w4fb0e4bdjbc11eaab63143cf6@mail-gmail-com%3e</id>
<updated>2009-10-25T10:38:10Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
But what about de-provisioning users?

The issue with putting users in yet another database in the enterprise world
central provisioning, de-provisioning and RBAC are the strategic directions
with no desire to mange users in remote stores.

And why would someone want to put in information into the WIKI when it is
already been add to the user in LDAP via the enterprise portal?

I will agree the local "groups" concept is necessary, but it should be an
agumnetation to container managed security that most enterprises would
utilize.

So users in the role (perhaps by department) "Sales" would always be able to
view any pages with "Sales":

Then the local "groups" would be done to perform "teaming" arrangements as
would be done in a project that would cross departmental lines.

-jim
Jim Willeke


On Sat, Oct 24, 2009 at 11:12 AM, Andrew Jaquith &lt;andrew.r.jaquith@gmail.com
&gt; wrote:

&gt; JSPWiki 3.0 trunk already has an LdapUserDatabase and LdapAuthorizer,
&gt; which means that it can obtain user profiles on a read-only basis from
&gt; LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
&gt; users will be "provisioned" in JSPWiki automatically. This should
&gt; solve the user-experience problem you described.
&gt;
&gt; The upcoming 3.0 LDAP features have been developed and tested with
&gt; Active Directory and OpenLDAP. It is configured via the GUI at
&gt; install-time.
&gt;
&gt; With respect to permissions and group memberships: these are good
&gt; suggestions. We still have some work to do for the GUI for ACLs for
&gt; 3.0. I agree that we should be validating user names when users create
&gt; the ACLs. Same for adding users to groups. These suggestions will be
&gt; incorporated into how the ACL GUIs work -- likely via AJAX in
&gt; real-time.
&gt;
&gt; Andrew
&gt;
&gt; On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt &lt;te@zama.org&gt; wrote:
&gt; &gt; The group and permission system in the jspwiki is rather dynamic, and
&gt; ldaps
&gt; &gt; tends to be readonly except for a groups of administrators. There for
&gt; there
&gt; &gt; is still need for the user.xml and group.xml. But in my opinion the
&gt; user.xml
&gt; &gt; needs to be automatically updated when a new ldap user is logged in.
&gt; &gt;
&gt; &gt; Otherwise granting and managing jspwiki permissions i a nightmare, this
&gt; also
&gt; &gt; enhanced since there is no check on if a user exist - when adding users
&gt; to
&gt; &gt; wiki group or setting a page permission.
&gt; &gt;
&gt; &gt; I think the following should be changed.
&gt; &gt;
&gt; &gt; - First time a new user is logged in - the user should be added to the
&gt; the
&gt; &gt; user.xml and redirect to the profile page for setting additional
&gt; information
&gt; &gt; (email, full name and section edition etc)
&gt; &gt;
&gt; &gt; - Adding page permission should lookup if the group or the user exist.
&gt; &gt;
&gt; &gt; - Adding users to a wiki group should only be possible for existing
&gt; users.
&gt; &gt;
&gt; &gt; /Thomas
&gt; &gt;
&gt; &gt;
&gt; &gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt; &gt;
&gt; &gt;&gt; Why allow people to eliminate the user.xml?
&gt; &gt;&gt;
&gt; &gt;&gt; Why not allow the use of LDAP for the user profile?
&gt; &gt;&gt;
&gt; &gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt; &gt;&gt;
&gt; &gt;&gt; Enterprises have no desire to maintain another separate user store of
&gt; &gt;&gt; information. Many already have a central LDAP store.
&gt; &gt;&gt;
&gt; &gt;&gt; -jim
&gt; &gt;&gt; Jim Willeke
&gt; &gt;&gt;
&gt; &gt;&gt;
&gt; &gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt;
&gt; wrote:
&gt; &gt;&gt;
&gt; &gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first time.
&gt;  the
&gt; &gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of problem
&gt; &gt;&gt;&gt; when
&gt; &gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the user
&gt; isn't
&gt; &gt;&gt;&gt; created.
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; If a user creates a user profile after logging into the container, he
&gt; or
&gt; &gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a full name
&gt; is
&gt; &gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that point
&gt; forward.
&gt; &gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt; Andrew
&gt; &gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt;
&gt; wrote:
&gt; &gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; Hello,
&gt; &gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and it
runs
&gt; &gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing. I get
only
&gt; &gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the change
&gt; &gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt; &gt;&gt;&gt;&gt;&gt; Harald
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; - --
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt; &gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt; &gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt; &gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt; &gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt; &gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt; &gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt; &gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt; &gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt; &gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt; &gt;&gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;&gt;
&gt; &gt;&gt;&gt;
&gt; &gt;
&gt; &gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Harald Krammer &lt;Harald.Krammer@hkr.at&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c4AE41AAB.5000108@hkr.at%3e"/>
<id>urn:uuid:%3c4AE41AAB-5000108@hkr-at%3e</id>
<updated>2009-10-25T09:30:19Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

That sounds interesting.
It is noted that the trunk is heavily under construction and the code is
broken. Does it make sense to test current trunk version or is it too early?

Greetings,
Harald

Andrew Jaquith schrieb:
&gt; JSPWiki 3.0 trunk already has an LdapUserDatabase and LdapAuthorizer,
&gt; which means that it can obtain user profiles on a read-only basis from
&gt; LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
&gt; users will be "provisioned" in JSPWiki automatically. This should
&gt; solve the user-experience problem you described.
&gt; 
&gt; The upcoming 3.0 LDAP features have been developed and tested with
&gt; Active Directory and OpenLDAP. It is configured via the GUI at
&gt; install-time.
&gt; 
&gt; With respect to permissions and group memberships: these are good
&gt; suggestions. We still have some work to do for the GUI for ACLs for
&gt; 3.0. I agree that we should be validating user names when users create
&gt; the ACLs. Same for adding users to groups. These suggestions will be
&gt; incorporated into how the ACL GUIs work -- likely via AJAX in
&gt; real-time.
&gt; 
&gt; Andrew
&gt; 
&gt; On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt &lt;te@zama.org&gt; wrote:
&gt;&gt; The group and permission system in the jspwiki is rather dynamic, and ldaps
&gt;&gt; tends to be readonly except for a groups of administrators. There for there
&gt;&gt; is still need for the user.xml and group.xml. But in my opinion the user.xml
&gt;&gt; needs to be automatically updated when a new ldap user is logged in.
&gt;&gt;
&gt;&gt; Otherwise granting and managing jspwiki permissions i a nightmare, this also
&gt;&gt; enhanced since there is no check on if a user exist - when adding users to
&gt;&gt; wiki group or setting a page permission.
&gt;&gt;
&gt;&gt; I think the following should be changed.
&gt;&gt;
&gt;&gt; - First time a new user is logged in - the user should be added to the the
&gt;&gt; user.xml and redirect to the profile page for setting additional information
&gt;&gt; (email, full name and section edition etc)
&gt;&gt;
&gt;&gt; - Adding page permission should lookup if the group or the user exist.
&gt;&gt;
&gt;&gt; - Adding users to a wiki group should only be possible for existing users.
&gt;&gt;
&gt;&gt; /Thomas
&gt;&gt;
&gt;&gt;
&gt;&gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt;&gt;
&gt;&gt;&gt; Why allow people to eliminate the user.xml?
&gt;&gt;&gt;
&gt;&gt;&gt; Why not allow the use of LDAP for the user profile?
&gt;&gt;&gt;
&gt;&gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt;&gt;&gt;
&gt;&gt;&gt; Enterprises have no desire to maintain another separate user store of
&gt;&gt;&gt; information. Many already have a central LDAP store.
&gt;&gt;&gt;
&gt;&gt;&gt; -jim
&gt;&gt;&gt; Jim Willeke
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt; wrote:
&gt;&gt;&gt;
&gt;&gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first time.  the
&gt;&gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of problem
&gt;&gt;&gt;&gt; when
&gt;&gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the user isn't
&gt;&gt;&gt;&gt; created.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; If a user creates a user profile after logging into the container, he or
&gt;&gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a full name
is
&gt;&gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that point forward.
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt;
wrote:
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and it runs
&gt;&gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing. I get
only
&gt;&gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the change
&gt;&gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;&gt;
&gt;&gt;
&gt; 


- --

Harald Krammer
Brucknerstrasse 33
A - 4020  Linz
AUSTRIA

Mobil +43.(0) 664. 130 59 58
Mail: Harald.Krammer (at) hkr.at
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEAREIAAYFAkrkGqEACgkQ9QlAsubHO9vsYACgriH34OZiGCZq6Ac2DayNJnd3
SKQAni/X1DtibeNEbZKtnzNAe+OHUwt2
=KwyM
-----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cb90102160910240812j1c208235pe817f6f42be597bf@mail.gmail.com%3e"/>
<id>urn:uuid:%3cb90102160910240812j1c208235pe817f6f42be597bf@mail-gmail-com%3e</id>
<updated>2009-10-24T15:12:27Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
JSPWiki 3.0 trunk already has an LdapUserDatabase and LdapAuthorizer,
which means that it can obtain user profiles on a read-only basis from
LDAP, and obtain roles from LDAP groups. So if you use LDAP, your
users will be "provisioned" in JSPWiki automatically. This should
solve the user-experience problem you described.

The upcoming 3.0 LDAP features have been developed and tested with
Active Directory and OpenLDAP. It is configured via the GUI at
install-time.

With respect to permissions and group memberships: these are good
suggestions. We still have some work to do for the GUI for ACLs for
3.0. I agree that we should be validating user names when users create
the ACLs. Same for adding users to groups. These suggestions will be
incorporated into how the ACL GUIs work -- likely via AJAX in
real-time.

Andrew

On Sat, Oct 24, 2009 at 7:25 AM, Thomas Engelschmidt &lt;te@zama.org&gt; wrote:
&gt; The group and permission system in the jspwiki is rather dynamic, and ldaps
&gt; tends to be readonly except for a groups of administrators. There for there
&gt; is still need for the user.xml and group.xml. But in my opinion the user.xml
&gt; needs to be automatically updated when a new ldap user is logged in.
&gt;
&gt; Otherwise granting and managing jspwiki permissions i a nightmare, this also
&gt; enhanced since there is no check on if a user exist - when adding users to
&gt; wiki group or setting a page permission.
&gt;
&gt; I think the following should be changed.
&gt;
&gt; - First time a new user is logged in - the user should be added to the the
&gt; user.xml and redirect to the profile page for setting additional information
&gt; (email, full name and section edition etc)
&gt;
&gt; - Adding page permission should lookup if the group or the user exist.
&gt;
&gt; - Adding users to a wiki group should only be possible for existing users.
&gt;
&gt; /Thomas
&gt;
&gt;
&gt; On Oct 24, 2009, at 10:57 , Jim Willeke wrote:
&gt;
&gt;&gt; Why allow people to eliminate the user.xml?
&gt;&gt;
&gt;&gt; Why not allow the use of LDAP for the user profile?
&gt;&gt;
&gt;&gt; Allow mapping the LDAP attributes to the profile values?
&gt;&gt;
&gt;&gt; Enterprises have no desire to maintain another separate user store of
&gt;&gt; information. Many already have a central LDAP store.
&gt;&gt;
&gt;&gt; -jim
&gt;&gt; Jim Willeke
&gt;&gt;
&gt;&gt;
&gt;&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt; wrote:
&gt;&gt;
&gt;&gt;&gt; I would suggest a change, if a ldap user is logging the first time.  the
&gt;&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of problem
&gt;&gt;&gt; when
&gt;&gt;&gt; adding a ldap user to a wiki group, since it possible that the user isn't
&gt;&gt;&gt; created.
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;&gt;
&gt;&gt;&gt; If a user creates a user profile after logging into the container, he or
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a full name is
&gt;&gt;&gt;&gt; supplied, it will be used in page histories etc from that point forward.
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Andrew
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt; wrote:
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and it runs
&gt;&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing. I get only
&gt;&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the change
&gt;&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Thomas Engelschmidt &lt;te@zama.org&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c61AD76FD-079B-42D3-AB42-A9820EEE45E2@zama.org%3e"/>
<id>urn:uuid:%3c61AD76FD-079B-42D3-AB42-A9820EEE45E2@zama-org%3e</id>
<updated>2009-10-24T11:25:22Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
The group and permission system in the jspwiki is rather dynamic, and  
ldaps tends to be readonly except for a groups of administrators.  
There for there is still need for the user.xml and group.xml. But in  
my opinion the user.xml needs to be automatically updated when a new  
ldap user is logged in.

Otherwise granting and managing jspwiki permissions i a nightmare,  
this also enhanced since there is no check on if a user exist - when  
adding users to wiki group or setting a page permission.

I think the following should be changed.

- First time a new user is logged in - the user should be added to the  
the user.xml and redirect to the profile page for setting additional  
information (email, full name and section edition etc)

- Adding page permission should lookup if the group or the user exist.

- Adding users to a wiki group should only be possible for existing  
users.

/Thomas


On Oct 24, 2009, at 10:57 , Jim Willeke wrote:

&gt; Why allow people to eliminate the user.xml?
&gt;
&gt; Why not allow the use of LDAP for the user profile?
&gt;
&gt; Allow mapping the LDAP attributes to the profile values?
&gt;
&gt; Enterprises have no desire to maintain another separate user store of
&gt; information. Many already have a central LDAP store.
&gt;
&gt; -jim
&gt; Jim Willeke
&gt;
&gt;
&gt; On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt;  
&gt; wrote:
&gt;
&gt;&gt; I would suggest a change, if a ldap user is logging the first  
&gt;&gt; time.  the
&gt;&gt; Wiki should create the user in the user.xml - it gives a lot of  
&gt;&gt; problem when
&gt;&gt; adding a ldap user to a wiki group, since it possible that the user  
&gt;&gt; isn't
&gt;&gt; created.
&gt;&gt;
&gt;&gt;
&gt;&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;&gt;
&gt;&gt; If a user creates a user profile after logging into the container,  
&gt;&gt; he or
&gt;&gt;&gt; she will have an opportunity to specify a "full name." If a full  
&gt;&gt;&gt; name is
&gt;&gt;&gt; supplied, it will be used in page histories etc from that point  
&gt;&gt;&gt; forward.
&gt;&gt;&gt;
&gt;&gt;&gt; Andrew
&gt;&gt;&gt;
&gt;&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt;  
&gt;&gt;&gt; wrote:
&gt;&gt;&gt;
&gt;&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Hello,
&gt;&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and it  
&gt;&gt;&gt;&gt; runs
&gt;&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Only the visualization of real user name is still missing. I get  
&gt;&gt;&gt;&gt; only
&gt;&gt;&gt;&gt; the login name (short name) instead of the full name in the change
&gt;&gt;&gt;&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt;&gt; Harald
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; - --
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;



</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Jim Willeke &lt;jim@willeke.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cb662a94e0910240157u5f53b573v524a2a55ee65db80@mail.gmail.com%3e"/>
<id>urn:uuid:%3cb662a94e0910240157u5f53b573v524a2a55ee65db80@mail-gmail-com%3e</id>
<updated>2009-10-24T08:57:13Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Why allow people to eliminate the user.xml?

Why not allow the use of LDAP for the user profile?

Allow mapping the LDAP attributes to the profile values?

Enterprises have no desire to maintain another separate user store of
information. Many already have a central LDAP store.

-jim
Jim Willeke


On Fri, Oct 23, 2009 at 2:09 PM, Thomas Engelschmidt &lt;te@zama.org&gt; wrote:

&gt; I would suggest a change, if a ldap user is logging the first time.  the
&gt; Wiki should create the user in the user.xml - it gives a lot of problem when
&gt; adding a ldap user to a wiki group, since it possible that the user isn't
&gt; created.
&gt;
&gt;
&gt; On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:
&gt;
&gt;  If a user creates a user profile after logging into the container, he or
&gt;&gt; she will have an opportunity to specify a "full name." If a full name is
&gt;&gt; supplied, it will be used in page histories etc from that point forward.
&gt;&gt;
&gt;&gt; Andrew
&gt;&gt;
&gt;&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt; wrote:
&gt;&gt;
&gt;&gt;  -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt;&gt; Hash: SHA256
&gt;&gt;&gt;
&gt;&gt;&gt; Hello,
&gt;&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and it runs
&gt;&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt;&gt;&gt;
&gt;&gt;&gt; Only the visualization of real user name is still missing. I get only
&gt;&gt;&gt; the login name (short name) instead of the full name in the change
&gt;&gt;&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt;&gt;&gt;
&gt;&gt;&gt; Nice greetings,
&gt;&gt;&gt; Harald
&gt;&gt;&gt;
&gt;&gt;&gt; - --
&gt;&gt;&gt;
&gt;&gt;&gt; Harald Krammer
&gt;&gt;&gt; Brucknerstrasse 33
&gt;&gt;&gt; A - 4020  Linz
&gt;&gt;&gt; AUSTRIA
&gt;&gt;&gt;
&gt;&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;&gt;
&gt;&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt;&gt; =Kd7Y
&gt;&gt;&gt; -----END PGP SIGNATURE-----
&gt;&gt;&gt;
&gt;&gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Thomas Engelschmidt &lt;te@zama.org&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cE58CC51D-E6A1-48BA-835D-5E8115FC2759@zama.org%3e"/>
<id>urn:uuid:%3cE58CC51D-E6A1-48BA-835D-5E8115FC2759@zama-org%3e</id>
<updated>2009-10-23T18:09:25Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
I would suggest a change, if a ldap user is logging the first time.   
the Wiki should create the user in the user.xml - it gives a lot of  
problem when adding a ldap user to a wiki group, since it possible  
that the user isn't created.


On Oct 23, 2009, at 00:38 , Andrew Jaquith wrote:

&gt; If a user creates a user profile after logging into the container,  
&gt; he or she will have an opportunity to specify a "full name." If a  
&gt; full name is supplied, it will be used in page histories etc from  
&gt; that point forward.
&gt;
&gt; Andrew
&gt;
&gt; On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt;  
&gt; wrote:
&gt;
&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt;&gt; Hash: SHA256
&gt;&gt;
&gt;&gt; Hello,
&gt;&gt; I run JSPWiki with Web Container Authentication via LDAP and it runs
&gt;&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt;&gt;
&gt;&gt; Only the visualization of real user name is still missing. I get only
&gt;&gt; the login name (short name) instead of the full name in the change
&gt;&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt;&gt;
&gt;&gt; Nice greetings,
&gt;&gt; Harald
&gt;&gt;
&gt;&gt; - --
&gt;&gt;
&gt;&gt; Harald Krammer
&gt;&gt; Brucknerstrasse 33
&gt;&gt; A - 4020  Linz
&gt;&gt; AUSTRIA
&gt;&gt;
&gt;&gt; Mobil +43.(0) 664. 130 59 58
&gt;&gt; Mail: Harald.Krammer (at) hkr.at
&gt;&gt; -----BEGIN PGP SIGNATURE-----
&gt;&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;&gt;
&gt;&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt;&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt;&gt; =Kd7Y
&gt;&gt; -----END PGP SIGNATURE-----



</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Visual LDAP user name</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c63630BF8-5654-4382-8C54-BDD019E903FA@gmail.com%3e"/>
<id>urn:uuid:%3c63630BF8-5654-4382-8C54-BDD019E903FA@gmail-com%3e</id>
<updated>2009-10-22T22:38:02Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
If a user creates a user profile after logging into the container, he  
or she will have an opportunity to specify a "full name." If a full  
name is supplied, it will be used in page histories etc from that  
point forward.

Andrew

On Oct 22, 2009, at 16:34, Harald Krammer &lt;Harald.Krammer@hkr.at&gt; wrote:

&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt; Hash: SHA256
&gt;
&gt; Hello,
&gt; I run JSPWiki with Web Container Authentication via LDAP and it runs
&gt; fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).
&gt;
&gt; Only the visualization of real user name is still missing. I get only
&gt; the login name (short name) instead of the full name in the change
&gt; history and so on.  Is it a default behaviour or misconfiguration?
&gt;
&gt; Nice greetings,
&gt; Harald
&gt;
&gt; - --
&gt;
&gt; Harald Krammer
&gt; Brucknerstrasse 33
&gt; A - 4020  Linz
&gt; AUSTRIA
&gt;
&gt; Mobil +43.(0) 664. 130 59 58
&gt; Mail: Harald.Krammer (at) hkr.at
&gt; -----BEGIN PGP SIGNATURE-----
&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;
&gt; iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
&gt; w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
&gt; =Kd7Y
&gt; -----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Visual LDAP user name</title>
<author><name>Harald Krammer &lt;Harald.Krammer@hkr.at&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c4AE0C1F0.1040703@hkr.at%3e"/>
<id>urn:uuid:%3c4AE0C1F0-1040703@hkr-at%3e</id>
<updated>2009-10-22T20:34:56Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello,
I run JSPWiki with Web Container Authentication via LDAP and it runs
fine (JSPWIki 2.8.2, OpenLDAP 2.4.11, Apache 6.0.20, OpenJDK 6).

Only the visualization of real user name is still missing. I get only
the login name (short name) instead of the full name in the change
history and so on.  Is it a default behaviour or misconfiguration?

Nice greetings,
Harald

- --

Harald Krammer
Brucknerstrasse 33
A - 4020  Linz
AUSTRIA

Mobil +43.(0) 664. 130 59 58
Mail: Harald.Krammer (at) hkr.at
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEAREIAAYFAkrgwegACgkQ9QlAsubHO9vd7QCfT5rEQYRsPUAVvbs/HrqMiWfZ
w6cAnjEp4FKX+3T3szBwW1n+DbCMd0z0
=Kd7Y
-----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Links with [ or ] symbols</title>
<author><name>Harald Krammer &lt;Harald.Krammer@hkr.at&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c4ADDFA35.3000607@hkr.at%3e"/>
<id>urn:uuid:%3c4ADDFA35-3000607@hkr-at%3e</id>
<updated>2009-10-20T17:58:13Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello Janne,
no, I didn't know that. This illegal characters are included on a
external URL.

Thanks it works.
Greetings,
Harald


Janne Jalkanen schrieb:
&gt; 
&gt; You gotta realize that "[" and "]" are illegal characters in URLs.  So
&gt; you need to replace them with their percent-encoding versions (which
&gt; your browser might do automatically), just like what you would do with
&gt; regular HTML.
&gt; 
&gt; %5B = [
&gt; %5D = ]
&gt; 
&gt; /Janne
&gt; 
&gt; On Oct 19, 2009, at 22:19 , Harald Krammer wrote:
&gt; 
&gt; Hello,
&gt; what's is the right method to add links with '['or ']' symbols into
&gt; JSPWiki?
&gt; 
&gt; e.g. http://foo.bar/?balbal[problemcmd]blabla[moreproblems]
&gt; 
&gt; Solution like [my link;
&gt; http://foo.bar/?balbal[problemcmd]blabla[moreproblems]] doesn't work.
&gt; 
&gt; Any helps are welcome
&gt; Harald

- --

Harald Krammer
Brucknerstrasse 33
A - 4020  Linz
AUSTRIA

Mobil +43.(0) 664. 130 59 58
Mail: Harald.Krammer (at) hkr.at
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEAREIAAYFAkrd+isACgkQ9QlAsubHO9u3LgCfQ2PgKzwll3yxcqHBuuMSjTHJ
rqYAnjHBIV6BUgwt5k7868mSQgtJGZku
=sEW0
-----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Links with [ or ] symbols</title>
<author><name>Janne Jalkanen &lt;Janne.Jalkanen@ecyrd.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cB96FD40A-9F66-45CC-92B1-A282B548A479@ecyrd.com%3e"/>
<id>urn:uuid:%3cB96FD40A-9F66-45CC-92B1-A282B548A479@ecyrd-com%3e</id>
<updated>2009-10-19T20:12:23Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>

You gotta realize that "[" and "]" are illegal characters in URLs.  So  
you need to replace them with their percent-encoding versions (which  
your browser might do automatically), just like what you would do with  
regular HTML.

%5B = [
%5D = ]

/Janne

On Oct 19, 2009, at 22:19 , Harald Krammer wrote:

&gt; -----BEGIN PGP SIGNED MESSAGE-----
&gt; Hash: SHA256
&gt;
&gt; Hello,
&gt; what's is the right method to add links with '['or ']' symbols into  
&gt; JSPWiki?
&gt;
&gt; e.g. http://foo.bar/?balbal[problemcmd]blabla[moreproblems]
&gt;
&gt; Solution like [my link;
&gt; http://foo.bar/?balbal[problemcmd]blabla[moreproblems]] doesn't work.
&gt;
&gt; Any helps are welcome
&gt; Harald
&gt; - --
&gt;
&gt; Harald Krammer
&gt; Brucknerstrasse 33
&gt; A - 4020  Linz
&gt; AUSTRIA
&gt;
&gt; Mobil +43.(0) 664. 130 59 58
&gt; Mail: Harald.Krammer (at) hkr.at
&gt; -----BEGIN PGP SIGNATURE-----
&gt; Version: GnuPG v1.4.9 (GNU/Linux)
&gt;
&gt; iEYEAREIAAYFAkrcu7QACgkQ9QlAsubHO9u1jwCcDoQ+x0wty/MoTQE9f+W3chJM
&gt; BXsAn08HdYsENP+kgTFA1AjJNgouVl5c
&gt; =5Juu
&gt; -----END PGP SIGNATURE-----



</pre>
</div>
</content>
</entry>
<entry>
<title>Links with [ or ] symbols</title>
<author><name>Harald Krammer &lt;Harald.Krammer@hkr.at&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c4ADCBBBB.90402@hkr.at%3e"/>
<id>urn:uuid:%3c4ADCBBBB-90402@hkr-at%3e</id>
<updated>2009-10-19T19:19:23Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello,
what's is the right method to add links with '['or ']' symbols into JSPWiki?

e.g. http://foo.bar/?balbal[problemcmd]blabla[moreproblems]

Solution like [my link;
http://foo.bar/?balbal[problemcmd]blabla[moreproblems]] doesn't work.

Any helps are welcome
Harald
- --

Harald Krammer
Brucknerstrasse 33
A - 4020  Linz
AUSTRIA

Mobil +43.(0) 664. 130 59 58
Mail: Harald.Krammer (at) hkr.at
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEAREIAAYFAkrcu7QACgkQ9QlAsubHO9u1jwCcDoQ+x0wty/MoTQE9f+W3chJM
BXsAn08HdYsENP+kgTFA1AjJNgouVl5c
=5Juu
-----END PGP SIGNATURE-----


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Web Container Authentication Via LDAP</title>
<author><name>Jim Willeke &lt;jim@willeke.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cb662a94e0910150152t2c948b4apaa1188b7b4ea9f73@mail.gmail.com%3e"/>
<id>urn:uuid:%3cb662a94e0910150152t2c948b4apaa1188b7b4ea9f73@mail-gmail-com%3e</id>
<updated>2009-10-15T08:52:08Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Do you have the connector using the correct parameters for the keystore?
The entries should/could be something like:

    &lt;!-- Define a SSL HTTP/1.1 Connector on port 8443 --&gt;
        &lt;Connector port="8443"
                   maxThreads="150" minSpareThreads="25"
maxSpareThreads="75"
                   enableLookups="false"
                   disableUploadTimeout="true"
                   debug="99"
                   acceptCount="100"
                   scheme="https"
                   secure="true"
                   keystoreFile="&lt;keystore_filename&gt;"
                   keystorePass="changeit"
                   truststoreFile="&lt;trustcacerts-filename&gt;"
                   truststorePass="changeit"
                   clientAuth="false"
                   sslProtocol="TLS" /&gt;

-jim
Jim Willeke


On Wed, Oct 14, 2009 at 5:19 PM, Andrew Jaquith
&lt;andrew.r.jaquith@gmail.com&gt;wrote:

&gt; I don't know what to tell you, exactly. You can try troubleshooting
&gt; Tomcat's SSL connection by adding this to your CATALINA_OPTS
&gt; environment variable:
&gt;
&gt; -Djavax.net.debug=all
&gt;
&gt; You'll see a LOT of diagnostic information as a result. You can also
&gt; fine-tune SSL debugging so you just see trust-store issues, for
&gt; example. See the docs here:
&gt;
&gt; http://java.sun.com/j2se/1.5.0/docs/guide/security/jsse/ReadDebug.html
&gt;
&gt; If that doesn't work, then you likely have deeper LDAP connectivity
&gt; problems than just SSL certificates. You should figure out what those
&gt; are before proceeding further with the Java certificate store
&gt; troubleshooting.
&gt;
&gt; What you should do in that case is use a different LDAP client (for
&gt; example, the Unix 'ldapsearch' command line tool) to verify that you
&gt; can connect to LDAP outside of Tomcat. Once you know the exact base
&gt; DN, search string, SSL setting, etc to use, you'll know how to
&gt; configure it in Tomcat.
&gt;
&gt; I can't give you much more guidance than that. Please don't ask for
&gt; detailed HOWTOs on either of these points -- Google is your friend,
&gt; and will be friendlier to you than I am willing to be at this point.
&gt; Frankly, this is not really a JSPWiki issue -- it's a Tomcat issue.
&gt; You might also want to try the tomcat-user mailing list.
&gt;
&gt; Andrew
&gt;
&gt; On Mon, Oct 12, 2009 at 4:54 AM, anilkumarkatta
&gt; &lt;anilkumarkatta@gmail.com&gt; wrote:
&gt; &gt;
&gt; &gt; yes, i did.
&gt; &gt;
&gt; &gt; I have multiple installation on my machine with different versions of the
&gt; &gt; JVM. I installed the new certicates using InstallCert.java program as
&gt; &gt; suggested and crosschecked those intalled cert in the cercert file using
&gt; &gt; keytool list command.
&gt; &gt;
&gt; &gt; still the same issue. does the application war require any .jks files or
&gt; &gt; .cer file. ?
&gt; &gt;
&gt; &gt; Please advice
&gt; &gt;
&gt; &gt;
&gt; &gt; Jim Willeke wrote:
&gt; &gt;&gt;
&gt; &gt;&gt; Did you look in the jre?
&gt; &gt;&gt;
&gt; &gt;&gt; If you are using a JDK then the file would be:
&gt; &gt;&gt; \jdk1.6.0_14\jre\lib\security\cacerts
&gt; &gt;&gt;
&gt; &gt;&gt;
&gt; &gt;&gt; -jim
&gt; &gt;&gt; Jim Willeke
&gt; &gt;&gt;
&gt; &gt;&gt;
&gt; &gt;&gt; On Fri, Oct 9, 2009 at 5:51 AM, anilkumarkatta
&gt; &gt;&gt; &lt;anilkumarkatta@gmail.com&gt;wrote:
&gt; &gt;&gt;
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; Hi All
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; Thanks for you replies.
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; I have tried installing the ssl for the url. but same issue.
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; I took some time to check how the existing url's ssl is done in
&gt; &gt;&gt;&gt; keystore..
&gt; &gt;&gt;&gt; but find nothing in java_home/lib/security.
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; how this can be no ssl certifcates in keystore?
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; if they keystore is exists in app level where does it saved in
&gt; &gt;&gt;&gt; application
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; Thanks again for the replies.
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; -Anil
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; Andrew Jaquith-4 wrote:
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; You are pretty new to this whole Java thing aren't you?
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; It appears that 1) your LDAP server requires SSL (a good thing!) and
&gt; &gt;&gt;&gt; &gt; that 2) your LDAP's SSL certificate is self-signed and therefore not
&gt; &gt;&gt;&gt; &gt; trusted.
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; Java keeps an internal list of SSL certs it trusts. Your self-signed
&gt; &gt;&gt;&gt; &gt; CA is not one of them. You need to add the SSL certificate CA (that
&gt; &gt;&gt;&gt; &gt; is, the self-signed root) to your local JSSE trusted certificate
&gt; &gt;&gt;&gt; &gt; store. This is at $JAVA_HOME/lib/security/cacerts.
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; The Java command line tool "keytool" can do this. You can also use
my
&gt; &gt;&gt;&gt; &gt; SSLHelper class, part of my freshcookies-security.jar that ships with
&gt; &gt;&gt;&gt; &gt; JSPWiki. Indeed, I wrote it for just this situation. See the docs at
&gt; &gt;&gt;&gt; &gt; freshcookies.org
&gt; &gt;&gt;&gt; &gt;   for details.
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; With either aproach, you will need appprpriate admin rights to modify
&gt; &gt;&gt;&gt; &gt; the truststore.
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; Andrew
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt; On Oct 6, 2009, at 8:29, anilkumarkatta &lt;anilkumarkatta@gmail.com&gt;
&gt; &gt;&gt;&gt; &gt; wrote:
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt; ....contd.
&gt; &gt;&gt;&gt; &gt;&gt; Caused by: javax.net.ssl.SSLHandshakeException:
&gt; &gt;&gt;&gt; &gt;&gt; sun.security.validator.ValidatorException: PKIX path building
&gt; failed:
&gt; &gt;&gt;&gt; &gt;&gt; sun.security.provider.certpath.SunCertPathBuilderException: unable
&gt; &gt;&gt;&gt; &gt;&gt; to find
&gt; &gt;&gt;&gt; &gt;&gt; valid certification path to requested target
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt; anilkumarkatta wrote:
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; Hi All
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; I have tried to authenticate via LDAP server with all the
&gt; &gt;&gt;&gt; &gt;&gt;&gt; configuration
&gt; &gt;&gt;&gt; &gt;&gt;&gt; procedure explained in the URL
&gt; &gt;&gt;&gt; &gt;&gt;&gt; http://www.jspwiki.org/wiki/WebContainerAuthenticationViaLDAP
&gt; &gt;&gt;&gt; &gt;&gt;&gt; with a user provided LDAP settings, I got firewall team to
get the
&gt; &gt;&gt;&gt; &gt;&gt;&gt; secure
&gt; &gt;&gt;&gt; &gt;&gt;&gt; port open from where application is talking to the LDAP.
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; i am getting this exception while start of the application
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:04,581 [Thread-2] INFO
&gt; &gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Done sleeping,
&gt; &gt;&gt;&gt; &gt;&gt;&gt; membership established, start level:4
&gt; &gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:04,581 [Thread-2] INFO
&gt; &gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Sleeping
for
&gt; &gt;&gt;&gt; &gt;&gt;&gt; 1000
&gt; &gt;&gt;&gt; &gt;&gt;&gt; milliseconds to establish cluster membership, start level:8
&gt; &gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:05,581 [Thread-2] INFO
&gt; &gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Done sleeping,
&gt; &gt;&gt;&gt; &gt;&gt;&gt; membership established, start level:8
&gt; &gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:06,144 [Thread-2] WARN
&gt; &gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.core.ContainerBase.[Catalina] - Exception
&gt; &gt;&gt;&gt; &gt;&gt;&gt; performing
&gt; &gt;&gt;&gt; &gt;&gt;&gt; authentication
&gt; &gt;&gt;&gt; &gt;&gt;&gt; javax.naming.CommunicationException: simple bind failed:
&gt; &gt;&gt;&gt; &gt;&gt;&gt; ARTE001.MYDOMAIN.AK.com:636 [Root exception is
&gt; &gt;&gt;&gt; &gt;&gt;&gt; javax.net.ssl.SSLHandshakeException:
&gt; &gt;&gt;&gt; &gt;&gt;&gt; sun.security.validator.ValidatorException: PKIX path building
&gt; failed:
&gt; &gt;&gt;&gt; &gt;&gt;&gt; sun.security.provider.certpath.SunCertPathBuilderException:
unable
&gt; &gt;&gt;&gt; &gt;&gt;&gt; to find
&gt; &gt;&gt;&gt; &gt;&gt;&gt; valid certification path to requested target]
&gt; &gt;&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapClient.authenticate(Unknown Source)
&gt; &gt;&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapCtx.connect(Unknown Source)
&gt; &gt;&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapCtx.&lt;init&gt;(Unknown Source)
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; where as when I place other deatails of the LDAP its working
fine.
&gt; &gt;&gt;&gt; &gt;&gt;&gt; does this required any cerification files like .jks files..
if so
&gt; &gt;&gt;&gt; &gt;&gt;&gt; where
&gt; &gt;&gt;&gt; &gt;&gt;&gt; shall I place them?
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; your replies are most welcome
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;&gt; Regards,
&gt; &gt;&gt;&gt; &gt;&gt;&gt; -Anil Katta
&gt; &gt;&gt;&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt; &gt;&gt; --
&gt; &gt;&gt;&gt; &gt;&gt; View this message in context:
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt;
&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25767801.html
&gt; &gt;&gt;&gt; &gt;&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt; &gt;&gt;&gt; &gt;&gt;
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt; &gt;
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt; --
&gt; &gt;&gt;&gt; View this message in context:
&gt; &gt;&gt;&gt;
&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25818421.html
&gt; &gt;&gt;&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;&gt;
&gt; &gt;&gt;
&gt; &gt;&gt;
&gt; &gt;
&gt; &gt; --
&gt; &gt; View this message in context:
&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25852406.html
&gt; &gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt; &gt;
&gt; &gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Web Container Authentication Via LDAP</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cb90102160910141419x947452fs4a6a79f0facdb384@mail.gmail.com%3e"/>
<id>urn:uuid:%3cb90102160910141419x947452fs4a6a79f0facdb384@mail-gmail-com%3e</id>
<updated>2009-10-14T21:19:34Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
I don't know what to tell you, exactly. You can try troubleshooting
Tomcat's SSL connection by adding this to your CATALINA_OPTS
environment variable:

-Djavax.net.debug=all

You'll see a LOT of diagnostic information as a result. You can also
fine-tune SSL debugging so you just see trust-store issues, for
example. See the docs here:

http://java.sun.com/j2se/1.5.0/docs/guide/security/jsse/ReadDebug.html

If that doesn't work, then you likely have deeper LDAP connectivity
problems than just SSL certificates. You should figure out what those
are before proceeding further with the Java certificate store
troubleshooting.

What you should do in that case is use a different LDAP client (for
example, the Unix 'ldapsearch' command line tool) to verify that you
can connect to LDAP outside of Tomcat. Once you know the exact base
DN, search string, SSL setting, etc to use, you'll know how to
configure it in Tomcat.

I can't give you much more guidance than that. Please don't ask for
detailed HOWTOs on either of these points -- Google is your friend,
and will be friendlier to you than I am willing to be at this point.
Frankly, this is not really a JSPWiki issue -- it's a Tomcat issue.
You might also want to try the tomcat-user mailing list.

Andrew

On Mon, Oct 12, 2009 at 4:54 AM, anilkumarkatta
&lt;anilkumarkatta@gmail.com&gt; wrote:
&gt;
&gt; yes, i did.
&gt;
&gt; I have multiple installation on my machine with different versions of the
&gt; JVM. I installed the new certicates using InstallCert.java program as
&gt; suggested and crosschecked those intalled cert in the cercert file using
&gt; keytool list command.
&gt;
&gt; still the same issue. does the application war require any .jks files or
&gt; .cer file. ?
&gt;
&gt; Please advice
&gt;
&gt;
&gt; Jim Willeke wrote:
&gt;&gt;
&gt;&gt; Did you look in the jre?
&gt;&gt;
&gt;&gt; If you are using a JDK then the file would be:
&gt;&gt; \jdk1.6.0_14\jre\lib\security\cacerts
&gt;&gt;
&gt;&gt;
&gt;&gt; -jim
&gt;&gt; Jim Willeke
&gt;&gt;
&gt;&gt;
&gt;&gt; On Fri, Oct 9, 2009 at 5:51 AM, anilkumarkatta
&gt;&gt; &lt;anilkumarkatta@gmail.com&gt;wrote:
&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; Hi All
&gt;&gt;&gt;
&gt;&gt;&gt; Thanks for you replies.
&gt;&gt;&gt;
&gt;&gt;&gt; I have tried installing the ssl for the url. but same issue.
&gt;&gt;&gt;
&gt;&gt;&gt; I took some time to check how the existing url's ssl is done in
&gt;&gt;&gt; keystore..
&gt;&gt;&gt; but find nothing in java_home/lib/security.
&gt;&gt;&gt;
&gt;&gt;&gt; how this can be no ssl certifcates in keystore?
&gt;&gt;&gt;
&gt;&gt;&gt; if they keystore is exists in app level where does it saved in
&gt;&gt;&gt; application
&gt;&gt;&gt;
&gt;&gt;&gt; Thanks again for the replies.
&gt;&gt;&gt;
&gt;&gt;&gt; -Anil
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;&gt; Andrew Jaquith-4 wrote:
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; You are pretty new to this whole Java thing aren't you?
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; It appears that 1) your LDAP server requires SSL (a good thing!) and
&gt;&gt;&gt; &gt; that 2) your LDAP's SSL certificate is self-signed and therefore not
&gt;&gt;&gt; &gt; trusted.
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; Java keeps an internal list of SSL certs it trusts. Your self-signed
&gt;&gt;&gt; &gt; CA is not one of them. You need to add the SSL certificate CA (that
&gt;&gt;&gt; &gt; is, the self-signed root) to your local JSSE trusted certificate
&gt;&gt;&gt; &gt; store. This is at $JAVA_HOME/lib/security/cacerts.
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; The Java command line tool "keytool" can do this. You can also use my
&gt;&gt;&gt; &gt; SSLHelper class, part of my freshcookies-security.jar that ships with
&gt;&gt;&gt; &gt; JSPWiki. Indeed, I wrote it for just this situation. See the docs at
&gt;&gt;&gt; &gt; freshcookies.org
&gt;&gt;&gt; &gt;   for details.
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; With either aproach, you will need appprpriate admin rights to modify
&gt;&gt;&gt; &gt; the truststore.
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; Andrew
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt; On Oct 6, 2009, at 8:29, anilkumarkatta &lt;anilkumarkatta@gmail.com&gt;
&gt;&gt;&gt; &gt; wrote:
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; &gt;&gt; ....contd.
&gt;&gt;&gt; &gt;&gt; Caused by: javax.net.ssl.SSLHandshakeException:
&gt;&gt;&gt; &gt;&gt; sun.security.validator.ValidatorException: PKIX path building failed:
&gt;&gt;&gt; &gt;&gt; sun.security.provider.certpath.SunCertPathBuilderException: unable
&gt;&gt;&gt; &gt;&gt; to find
&gt;&gt;&gt; &gt;&gt; valid certification path to requested target
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; &gt;&gt; anilkumarkatta wrote:
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; Hi All
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; I have tried to authenticate via LDAP server with all the
&gt;&gt;&gt; &gt;&gt;&gt; configuration
&gt;&gt;&gt; &gt;&gt;&gt; procedure explained in the URL
&gt;&gt;&gt; &gt;&gt;&gt; http://www.jspwiki.org/wiki/WebContainerAuthenticationViaLDAP
&gt;&gt;&gt; &gt;&gt;&gt; with a user provided LDAP settings, I got firewall team to get the
&gt;&gt;&gt; &gt;&gt;&gt; secure
&gt;&gt;&gt; &gt;&gt;&gt; port open from where application is talking to the LDAP.
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; i am getting this exception while start of the application
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:04,581 [Thread-2] INFO
&gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Done sleeping,
&gt;&gt;&gt; &gt;&gt;&gt; membership established, start level:4
&gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:04,581 [Thread-2] INFO
&gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Sleeping for
&gt;&gt;&gt; &gt;&gt;&gt; 1000
&gt;&gt;&gt; &gt;&gt;&gt; milliseconds to establish cluster membership, start level:8
&gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:05,581 [Thread-2] INFO
&gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Done sleeping,
&gt;&gt;&gt; &gt;&gt;&gt; membership established, start level:8
&gt;&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:06,144 [Thread-2] WARN
&gt;&gt;&gt; &gt;&gt;&gt; org.apache.catalina.core.ContainerBase.[Catalina] - Exception
&gt;&gt;&gt; &gt;&gt;&gt; performing
&gt;&gt;&gt; &gt;&gt;&gt; authentication
&gt;&gt;&gt; &gt;&gt;&gt; javax.naming.CommunicationException: simple bind failed:
&gt;&gt;&gt; &gt;&gt;&gt; ARTE001.MYDOMAIN.AK.com:636 [Root exception is
&gt;&gt;&gt; &gt;&gt;&gt; javax.net.ssl.SSLHandshakeException:
&gt;&gt;&gt; &gt;&gt;&gt; sun.security.validator.ValidatorException: PKIX path building failed:
&gt;&gt;&gt; &gt;&gt;&gt; sun.security.provider.certpath.SunCertPathBuilderException: unable
&gt;&gt;&gt; &gt;&gt;&gt; to find
&gt;&gt;&gt; &gt;&gt;&gt; valid certification path to requested target]
&gt;&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapClient.authenticate(Unknown Source)
&gt;&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapCtx.connect(Unknown Source)
&gt;&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapCtx.&lt;init&gt;(Unknown Source)
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; where as when I place other deatails of the LDAP its working fine.
&gt;&gt;&gt; &gt;&gt;&gt; does this required any cerification files like .jks files.. if so
&gt;&gt;&gt; &gt;&gt;&gt; where
&gt;&gt;&gt; &gt;&gt;&gt; shall I place them?
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; your replies are most welcome
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;&gt; Regards,
&gt;&gt;&gt; &gt;&gt;&gt; -Anil Katta
&gt;&gt;&gt; &gt;&gt;&gt;
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; &gt;&gt; --
&gt;&gt;&gt; &gt;&gt; View this message in context:
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25767801.html
&gt;&gt;&gt; &gt;&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt;&gt;&gt; &gt;&gt;
&gt;&gt;&gt; &gt;
&gt;&gt;&gt; &gt;
&gt;&gt;&gt;
&gt;&gt;&gt; --
&gt;&gt;&gt; View this message in context:
&gt;&gt;&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25818421.html
&gt;&gt;&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt;&gt;&gt;
&gt;&gt;&gt;
&gt;&gt;
&gt;&gt;
&gt;
&gt; --
&gt; View this message in context: http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25852406.html
&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: interesting user logon problem</title>
<author><name>Harry Metske &lt;harry.metske@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c3a6c97f00910121135j7c16c27ah47681dab2d9e6dae@mail.gmail.com%3e"/>
<id>urn:uuid:%3c3a6c97f00910121135j7c16c27ah47681dab2d9e6dae@mail-gmail-com%3e</id>
<updated>2009-10-12T18:35:56Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
This indeed looks very much like you are accessing your JSPWiki with a
"wrong URL", a URL that is different from the baseURL configured in
jspwiki.properties.(like Madu also suggested)

Once  you login, you are redirected to the baseURL and have to log in again.
It has nothing todo with RACF.

regards,
Harry


2009/10/12 Ben Thompson &lt;Ben.Thompson@nt.gov.au&gt;

&gt; I have an interesting issue,  with one user who has to logon twice to be
&gt; authenticated to JSPWiki.  All the other 25 users, including myself do
&gt; not have this problem.  We are running JSPWiki 2.8.2 with RACF for our
&gt; authentication, but it turns out that the user had the same problem
&gt; under JSPWiki 2.8.1 using JSPWiki's authentication.  The users has to
&gt; logon twice to be authenticated to JSPWiki under both Explorer and
&gt; Firefox.  We have removed all cookies from both Explorer and Firefox,
&gt; this has not made a difference.
&gt;
&gt;
&gt;
&gt; The step to logon are:
&gt;
&gt; *       When at the JSPWiki home page, G'day (anonymous guest) appears
&gt; next to login.
&gt;
&gt;
&gt;
&gt; *       click Login and Login page displays.
&gt;
&gt;
&gt;
&gt; *       fill in RACF username &amp; Password.
&gt;
&gt;
&gt;
&gt; *       JSPWiki home page is displayed with  G'day (anonymous guest)
&gt; appearing against the login again, user still does not have access.
&gt;
&gt;
&gt;
&gt; *       Repeat the process by clicking on the login and login page
&gt; displays.
&gt;
&gt;
&gt;
&gt; *       Fill in RACF username &amp; Password , JSPWiki home page is
&gt; displayed with  G'day, XXX(authenticated). And at this stage the user
&gt; can access the info in JSPWiki.
&gt;
&gt;
&gt;
&gt; Any ideas on what's going on here
&gt;
&gt;
&gt;
&gt; Thanks
&gt;
&gt;
&gt;
&gt; Benjamin Thompson
&gt; Systems Programmer
&gt; Data Centre Services
&gt; Northern Territory Government
&gt;
&gt; twitter:benthompsonau
&gt; ph (08) 89997693
&gt;
&gt;
&gt;
&gt;


</pre>
</div>
</content>
</entry>
<entry>
<title>Re: Web Container Authentication Via LDAP</title>
<author><name>anilkumarkatta &lt;anilkumarkatta@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3c25852406.post@talk.nabble.com%3e"/>
<id>urn:uuid:%3c25852406-post@talk-nabble-com%3e</id>
<updated>2009-10-12T08:54:36Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>

yes, i did.

I have multiple installation on my machine with different versions of the
JVM. I installed the new certicates using InstallCert.java program as
suggested and crosschecked those intalled cert in the cercert file using
keytool list command.

still the same issue. does the application war require any .jks files or
.cer file. ?

Please advice


Jim Willeke wrote:
&gt; 
&gt; Did you look in the jre?
&gt; 
&gt; If you are using a JDK then the file would be:
&gt; \jdk1.6.0_14\jre\lib\security\cacerts
&gt; 
&gt; 
&gt; -jim
&gt; Jim Willeke
&gt; 
&gt; 
&gt; On Fri, Oct 9, 2009 at 5:51 AM, anilkumarkatta
&gt; &lt;anilkumarkatta@gmail.com&gt;wrote:
&gt; 
&gt;&gt;
&gt;&gt;
&gt;&gt; Hi All
&gt;&gt;
&gt;&gt; Thanks for you replies.
&gt;&gt;
&gt;&gt; I have tried installing the ssl for the url. but same issue.
&gt;&gt;
&gt;&gt; I took some time to check how the existing url's ssl is done in
&gt;&gt; keystore..
&gt;&gt; but find nothing in java_home/lib/security.
&gt;&gt;
&gt;&gt; how this can be no ssl certifcates in keystore?
&gt;&gt;
&gt;&gt; if they keystore is exists in app level where does it saved in
&gt;&gt; application
&gt;&gt;
&gt;&gt; Thanks again for the replies.
&gt;&gt;
&gt;&gt; -Anil
&gt;&gt;
&gt;&gt;
&gt;&gt; Andrew Jaquith-4 wrote:
&gt;&gt; &gt;
&gt;&gt; &gt; You are pretty new to this whole Java thing aren't you?
&gt;&gt; &gt;
&gt;&gt; &gt; It appears that 1) your LDAP server requires SSL (a good thing!) and
&gt;&gt; &gt; that 2) your LDAP's SSL certificate is self-signed and therefore not
&gt;&gt; &gt; trusted.
&gt;&gt; &gt;
&gt;&gt; &gt; Java keeps an internal list of SSL certs it trusts. Your self-signed
&gt;&gt; &gt; CA is not one of them. You need to add the SSL certificate CA (that
&gt;&gt; &gt; is, the self-signed root) to your local JSSE trusted certificate
&gt;&gt; &gt; store. This is at $JAVA_HOME/lib/security/cacerts.
&gt;&gt; &gt;
&gt;&gt; &gt; The Java command line tool "keytool" can do this. You can also use my
&gt;&gt; &gt; SSLHelper class, part of my freshcookies-security.jar that ships with
&gt;&gt; &gt; JSPWiki. Indeed, I wrote it for just this situation. See the docs at
&gt;&gt; &gt; freshcookies.org
&gt;&gt; &gt;   for details.
&gt;&gt; &gt;
&gt;&gt; &gt; With either aproach, you will need appprpriate admin rights to modify
&gt;&gt; &gt; the truststore.
&gt;&gt; &gt;
&gt;&gt; &gt; Andrew
&gt;&gt; &gt;
&gt;&gt; &gt; On Oct 6, 2009, at 8:29, anilkumarkatta &lt;anilkumarkatta@gmail.com&gt;
&gt;&gt; &gt; wrote:
&gt;&gt; &gt;
&gt;&gt; &gt;&gt;
&gt;&gt; &gt;&gt;
&gt;&gt; &gt;&gt; ....contd.
&gt;&gt; &gt;&gt; Caused by: javax.net.ssl.SSLHandshakeException:
&gt;&gt; &gt;&gt; sun.security.validator.ValidatorException: PKIX path building failed:
&gt;&gt; &gt;&gt; sun.security.provider.certpath.SunCertPathBuilderException: unable
&gt;&gt; &gt;&gt; to find
&gt;&gt; &gt;&gt; valid certification path to requested target
&gt;&gt; &gt;&gt;
&gt;&gt; &gt;&gt;
&gt;&gt; &gt;&gt; anilkumarkatta wrote:
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; Hi All
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; I have tried to authenticate via LDAP server with all the
&gt;&gt; &gt;&gt;&gt; configuration
&gt;&gt; &gt;&gt;&gt; procedure explained in the URL
&gt;&gt; &gt;&gt;&gt; http://www.jspwiki.org/wiki/WebContainerAuthenticationViaLDAP
&gt;&gt; &gt;&gt;&gt; with a user provided LDAP settings, I got firewall team to get the
&gt;&gt; &gt;&gt;&gt; secure
&gt;&gt; &gt;&gt;&gt; port open from where application is talking to the LDAP.
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; i am getting this exception while start of the application
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:04,581 [Thread-2] INFO
&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Done sleeping,
&gt;&gt; &gt;&gt;&gt; membership established, start level:4
&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:04,581 [Thread-2] INFO
&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Sleeping for
&gt;&gt; &gt;&gt;&gt; 1000
&gt;&gt; &gt;&gt;&gt; milliseconds to establish cluster membership, start level:8
&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:05,581 [Thread-2] INFO
&gt;&gt; &gt;&gt;&gt; org.apache.catalina.tribes.membership.McastService - Done sleeping,
&gt;&gt; &gt;&gt;&gt; membership established, start level:8
&gt;&gt; &gt;&gt;&gt; 2009-10-06 22:14:06,144 [Thread-2] WARN
&gt;&gt; &gt;&gt;&gt; org.apache.catalina.core.ContainerBase.[Catalina] - Exception
&gt;&gt; &gt;&gt;&gt; performing
&gt;&gt; &gt;&gt;&gt; authentication
&gt;&gt; &gt;&gt;&gt; javax.naming.CommunicationException: simple bind failed:
&gt;&gt; &gt;&gt;&gt; ARTE001.MYDOMAIN.AK.com:636 [Root exception is
&gt;&gt; &gt;&gt;&gt; javax.net.ssl.SSLHandshakeException:
&gt;&gt; &gt;&gt;&gt; sun.security.validator.ValidatorException: PKIX path building failed:
&gt;&gt; &gt;&gt;&gt; sun.security.provider.certpath.SunCertPathBuilderException: unable
&gt;&gt; &gt;&gt;&gt; to find
&gt;&gt; &gt;&gt;&gt; valid certification path to requested target]
&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapClient.authenticate(Unknown Source)
&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapCtx.connect(Unknown Source)
&gt;&gt; &gt;&gt;&gt;    at com.sun.jndi.ldap.LdapCtx.&lt;init&gt;(Unknown Source)
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; where as when I place other deatails of the LDAP its working fine.
&gt;&gt; &gt;&gt;&gt; does this required any cerification files like .jks files.. if so
&gt;&gt; &gt;&gt;&gt; where
&gt;&gt; &gt;&gt;&gt; shall I place them?
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; your replies are most welcome
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;&gt; Regards,
&gt;&gt; &gt;&gt;&gt; -Anil Katta
&gt;&gt; &gt;&gt;&gt;
&gt;&gt; &gt;&gt;
&gt;&gt; &gt;&gt; --
&gt;&gt; &gt;&gt; View this message in context:
&gt;&gt; &gt;&gt;
&gt;&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25767801.html
&gt;&gt; &gt;&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt;&gt; &gt;&gt;
&gt;&gt; &gt;
&gt;&gt; &gt;
&gt;&gt;
&gt;&gt; --
&gt;&gt; View this message in context:
&gt;&gt; http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25818421.html
&gt;&gt; Sent from the JspWiki - User mailing list archive at Nabble.com.
&gt;&gt;
&gt;&gt;
&gt; 
&gt; 

-- 
View this message in context: http://www.nabble.com/Web-Container-Authentication-Via-LDAP-tp25767713p25852406.html
Sent from the JspWiki - User mailing list archive at Nabble.com.



</pre>
</div>
</content>
</entry>
<entry>
<title>Re: interesting user logon problem</title>
<author><name>Andrew Jaquith &lt;andrew.r.jaquith@gmail.com&gt;</name></author>
<link rel="alternate" href="http://mail-archives.apache.org/mod_mbox/incubator-jspwiki-user/200910.mbox/%3cb90102160910112052l1cfc546fw496be62f8bfccfe5@mail.gmail.com%3e"/>
<id>urn:uuid:%3cb90102160910112052l1cfc546fw496be62f8bfccfe5@mail-gmail-com%3e</id>
<updated>2009-10-12T03:52:31Z</updated>
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">
<pre>
Given that JSPWiki doesn't ship out-of-the box with RACF support,
would you mind describing your configuration in more detail? In
particular, how is your authentication configured?

Andrew

On Sun, Oct 11, 2009 at 9:38 PM, Ben Thompson &lt;Ben.Thompson@nt.gov.au&gt; wrote:
&gt; I have an interesting issue,  with one user who has to logon twice to be
&gt; authenticated to JSPWiki.  All the other 25 users, including myself do
&gt; not have this problem.  We are running JSPWiki 2.8.2 with RACF for our
&gt; authentication, but it turns out that the user had the same problem
&gt; under JSPWiki 2.8.1 using JSPWiki's authentication.  The users has to
&gt; logon twice to be authenticated to JSPWiki under both Explorer and
&gt; Firefox.  We have removed all cookies from both Explorer and Firefox,
&gt; this has not made a difference.
&gt;
&gt;
&gt;
&gt; The step to logon are:
&gt;
&gt; *       When at the JSPWiki home page, G'day (anonymous guest) appears
&gt; next to login.
&gt;
&gt;
&gt;
&gt; *       click Login and Login page displays.
&gt;
&gt;
&gt;
&gt; *       fill in RACF username &amp; Password.
&gt;
&gt;
&gt;
&gt; *       JSPWiki home page is displayed with  G'day (anonymous guest)
&gt; appearing against the login again, user still does not have access.
&gt;
&gt;
&gt;
&gt; *       Repeat the process by clicking on the login and login page
&gt; displays.
&gt;
&gt;
&gt;
&gt; *       Fill in RACF username &amp; Password , JSPWiki home page is
&gt; displayed with  G'day, XXX(authenticated). And at this stage the user
&gt; can access the info in JSPWiki.
&gt;
&gt;
&gt;
&gt; Any ideas on what's going on here
&gt;
&gt;
&gt;
&gt; Thanks
&gt;
&gt;
&gt;
&gt; Benjamin Thompson
&gt; Systems Programmer
&gt; Data Centre Services
&gt; Northern Territory Government
&gt;
&gt; twitter:benthompsonau
&gt; ph (08) 89997693
&gt;
&gt;
&gt;
&gt;


</pre>
</div>
</content>
</entry>
</feed>
