Friday, January 4, 2013

How to use CLI tool to subscribe to the available cartridges in Stratos2 Demo

Before follow this post you must setup the Stratos2 Demo in your machine. Please refer the following post
http://malalanayake.wordpress.com/2013/01/04/stratos2-demo-setup-alpha-with-open-stack/

"subscribe" function is one of major features included in the CLI tool. This is use for subscribe to available cartridges in the system.

1. Login to the VM by using username "wso2" password "g"

[sourcecode language="bash"]
ssh wso2@172.14.0.1
password : g
[/sourcecode]

Then go to the folder "/demo_setup/software" and extract "CLI.tar.gz"
cm

2. Type "sudo bash" to move as a "root" and export following parameters
[sourcecode language="bash"]
export STRATOS_ADC_HOST=172.14.0.1
export STRATOS_ADC_PORT=9445
[/sourcecode]
cm2

3. Go to extracted CLI folder and run the stratos.sh with username and password
[sourcecode language="bash"]
./stratos.sh dinuka@stratos.com dinuka123
Then you will move to "stratos>"
[/sourcecode]
cm3

In Stratos2 demo environment we have cartridge call "php", now I'm going to subscribe to that cartridge from  my tenant dinuka@stratos.com

4. Now go to above stratos> and follow the command to subscribe to php

[sourcecode language="bash"]stratos> gtsubscribe php sampleapp[/sourcecode]
cm4

Once we done this we can see the created and running php instance in the OpenStack from http://172.14.0.1/syspanel/instances/

op

At this moment separated php instance is available for my tenant dinuka@stratos.com as a sampleapp

5. Lets look how to deploy the sample php file call test.php in to the allocated php server.

once we subscribe to the php cartridge it will create a specific GIT repository.
In above subscription you can see the git repo link as http://git.stratos.com/stratos.com/sampleapp
So what we have to do is we need to take the "git clone" from this location

Before that we have to put the following entries to the /etc/hosts file this should be done in your machine not in the VM
go to your console and follow this command sudo vim /etc/hosts
and put the following entries into the hosts file

172.14.0.1 git.stratos.com
172.14.0.1 sampleapp.php.stratos.com

Now we can make the git clone form http://git.stratos.com/stratos.com/sampleapp
> git clone http://git.stratos.com/stratos.com/sampleapp
username as dinuka@stratos.com dinuka123
cm

Now go to clone repo folder and you can see there are three folders as follows
simplesamlphp sql www
cm

Now you can place the test.php file in to www directory and do the following commands to commit
[sourcecode language="bash"]
> git add *
> git commit -a -m "sampleapp commit"
> git push
[/sourcecode]
username dinuka@stratos.com password dinuka123
cm

Go to http://sampleapp.php.stratos.com:8280/ and you can see the committed test.php file and you can access it from the http://sampleapp.php.stratos.com:8280/test.php/

php

php

Stratos2 Demo Setup Alpha - with Open Stack

This blog post is going to explain how to setup the Stratos2 Demo Setup in VirtualBox

first you have to download our image from here (This will take some time because of the size 17.3GB)
Now double click on it to install.
Once you done with the installation you have to go to configure the "virtual host only interface" with following details
1. go to file->preferences in VirtualBox
2. Select Network tab and add new "Host only network"
vb1

IPV4 address: 172.14.0.254
IPV4 network mask :255.255.0.0
vb2

3. Now start this image and login to the Instance
[sourcecode language="bash"]
username: wso2
password: g
[/sourcecode]

vm

vm1

v3

4. Go to /demo_setup/conf/ and view setup.conf

v4

If you have any changes in configuration according to your environment you can do it in setup.conf

5. Move to demo_setup folder and type "sudo bash" to move to root and run the setup-demo.sh
Press enter when the following questions are coming

================================================================================
[sourcecode language="bash"]
Enter new UNIX password:
Retype new UNIX password:
No password supplied
Enter new UNIX password:
Retype new UNIX password:
No password supplied
Enter new UNIX password:
Retype new UNIX password:
No password supplied
passwd: Authentication token manipulation error
passwd: password unchanged
Try again? [y/N] N

Changing the user information for git
Enter the new value, or press ENTER for the default
Full Name []:
Room Number []:
Work Phone []:
Home Phone []:
Other []:
Is the information correct? [Y/n] Y
do ssh-keygen without password for git user. press enter to continue...

Generating public/private rsa key pair.
Enter file in which to save the key (/home/git/.ssh/id_rsa):
Created directory '/home/git/.ssh'.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/git/.ssh/id_rsa.
Your public key has been saved in /home/git/.ssh/id_rsa.pub.
The key fingerprint is:
83:55:ac:2b:ae:6d:4a:58:98:b9:11:46:2a:7d:cf:f5 git@s2demo
The key's randomart image is:
+--[ RSA 2048]----+
| . .. |
| + .. |
|o + . o. |
|.. * o +.. |
| = . + S.E |
| = . .. |
| o .. . |
| . .o |
| o+. |
+-----------------+
Reading package lists... Done
Building dependency tree
Reading state information... Done
git is already the newest version.
gitolite is already the newest version.
gitweb is already the newest version.
apache2 is already the newest version.
bind9 is already the newest version.
apache2-suexec is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 56 not upgraded.
Adding entries to gitolite... Please do :wq after gitolite.rc file open. Press enter to continue...

The default settings in the rc file (/home/git/.gitolite.rc) are fine for most
people but if you wish to make any changes, you can do so now.

hit enter...
[/sourcecode]
================================================================================

Once you reached here, it will open the file with details then you have to save the file by doing the ":wq" command
vm5

Again you can see the following commands in console - just press enter to proceed
================================================================================
[sourcecode language="bash"]
creating gitolite-admin...
Initialized empty Git repository in /home/git/repositories/gitolite-admin.git/
creating testing...
Initialized empty Git repository in /home/git/repositories/testing.git/
[master (root-commit) 390bc9e] start
2 files changed, 6 insertions(+)
create mode 100644 conf/gitolite.conf
create mode 100644 keydir/git.pub
Cloning into 'gitolite-admin'...
Warning: Permanently added 'localhost' (ECDSA) to the list of known hosts.
remote: Counting objects: 6, done.
remote: Compressing objects: 100% (4/4), done.
Receiving objects: 100% (6/6), 709 bytes, done.
remote: Total 6 (delta 0), reused 0 (delta 0)
do ssh-keygen without password for wso2 user. press enter to continue...
Generating public/private rsa key pair.
Enter file in which to save the key (/home/wso2/.ssh/id_rsa):
/home/wso2/.ssh/id_rsa already exists.
Overwrite (y/n)? y

Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/wso2/.ssh/id_rsa.
Your public key has been saved in /home/wso2/.ssh/id_rsa.pub.
The key fingerprint is:
03:80:76:55:c0:ea:9f:04:3c:e9:38:d8:bd:9e:09:11 wso2@s2demo
The key's randomart image is:
+--[ RSA 2048]----+
| ..ooo. |
| o ... |
| .Eo o. |
| .* . |
| o.= o S |
|. +.+ . . |
| .. + . |
| ..oo |
| .+ |
+-----------------+
[master a6087aa] Check in by git
3 files changed, 10 insertions(+), 4 deletions(-)
create mode 100644 conf/repos/testing.conf
create mode 100644 keydir/wso2.pub
Already up-to-date.
Counting objects: 12, done.
Compressing objects: 100% (7/7), done.
Writing objects: 100% (8/8), 927 bytes, done.
Total 8 (delta 0), reused 0 (delta 0)
remote: creating testingt...
remote: Initialized empty Git repository in /home/git/repositories/testingt.git/
To git@localhost:gitolite-admin
390bc9e..a6087aa master -> master
Cloning into 'gitolite-admin'...
remote: Counting objects: 14, done.
remote: Compressing objects: 100% (11/11), done.
Receiving objects: 100% (14/14), 1.57 KiB, done.
remote: Total 14 (delta 0), reused 0 (delta 0)
ln: failed to create symbolic link `/etc/apache2/mods-enabled/appfactory.load': File exists
-D AP_DOC_ROOT="/var/www"
-D AP_GID_MIN=100
-D AP_HTTPD_USER="www-data"
-D AP_LOG_EXEC="/var/log/apache2/suexec.log"
-D AP_SAFE_PATH="/usr/local/bin:/usr/bin:/bin"
-D AP_UID_MIN=100
-D AP_USERDIR_SUFFIX="public_html"
ln: failed to create symbolic link `/etc/apache2/mods-enabled/suexec.load': File exists
ln: failed to create symbolic link `/etc/apache2/sites-enabled/git': File exists
apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1 for ServerName
httpd (no pid file) not running
apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1 for ServerName
/opt/ADC ~/demo_setup
~/demo_setup
/opt/cloud_controller ~/demo_setup
In repository/conf/carbon.xml
rm: cannot remove `./repository/conf/service-topology.conf': No such file or directory
rm: cannot remove `./repository/conf/service-topology.conf.back': No such file or directory
~/demo_setup
/opt/wso2mb-2.0.1 ~/demo_setup
~/demo_setup
/opt/elb ~/demo_setup
~/demo_setup
/opt/agent ~/demo_setup
~/demo_setup
/opt/wso2is-4.0.0 ~/demo_setup
~/demo_setup

Import the wso2.pub into openstack (With the same name mentioned in /opt/cloud_controller/repository/deployment/server/cartridges/)
cat /home/wso2/wso2.pub.
Cut and paste the output into the box that you get when execute import keys of the openstack dashboard
When you are ready press any key to continue starting servers
[/sourcecode]
================================================================================
once you come here in the command line you have to take another console and login to the VM as follows
[sourcecode language="bash"]
ssh wso2@172.14.0.1
password : g
[/sourcecode]
op7

then follow this command to view the public key
cat /home/wso2/wso2.pub and copy the public key
vm6

Then open the OpenStack buy using the IP address http://172.14.0.1/
op
[sourcecode language="bash"]
username : admin
password : openstack
[/sourcecode]
op1

Go to Project -> Access and Security then go to section Key Pairs 
op4

Delete the already exist "stratos-demo" key and import it again
op5

once you finish this again you can go to earlier command line and press enter to start servers
op6

when it finished you can see the command line as follows
op8

Now the stratos demo environment ready for use

6. Go to https://172.14.0.1:9445/carbon/admin/login.jsp
[sourcecode language="bash"]
username : admin
password : admin
[/sourcecode]
as

Create new tenant with following details

Domain : stratos.com
FirstName : statos2
LastName : alpha
Admin Username : dinuka
Password : dinuka123
Email : dinukam@wso2.com
as1

Now we are done with the Stratos2 Demo Setup

Wednesday, December 19, 2012

Unit Testing for C#.Net (Nunit)

[slideshare id=15708088&w=476&h=400&sc=no]

You can download sample C# project here

Invoke secured service(Sign and encrypt) from SoapUI 4.0.0

Here we are using the WSO2ESB 4.0.3 and SoapUI 4.0.0

First of all you have to start the ESB and secure the "echo" service as follows

1. Click on the "List" button under "Web Service" menu and Select the "Unsecured" button to Secure the service in front of "echo" service

esb1

2. Now select "yes" from drop down and selected the policy number "5" and click Next

esb2

3. Select the "Trusted key store" and "Private key store" click Finish

esb3

4. You can see the message "Security applied successfully"

esb4

Configuration part in ESB side is finished. What we have to do now is Invoke the secured service through the SoapUI

1. Open the SoapUI and go to "New SoapUI project" and give the service endpoint url with wsdl

ex/ endpoint url - http://localhost:8280/services/echo?wsdl

you can easily take the endpoint url by click on the service

esb5

Place the endpoint url with wsdl and create SoapUI project

so1

2. Click on the created project and select "Show Project View"

so2

3. go to "WS-Security Configurations"

so3

4. Select "Keystores / Certificates"

so4

5. Add new keystore - select the "wso2carbon.jks" that you select to secure the service (you can easily find this here ${ESB_HOME}/repository/resources/security)

so5

so6

so7

6. Set Default Alias as "wso2carbon" and Alias Password as "wso2carbon"

so8

7. Select tab "Incoming WS-Security Configuration"

so9

Add new record name as "incoming-security"

so10

Select Signature keystore as "wso2carbon.jks" and set password as "wso2carbon"

so11

8. Select tab "Outgoing WS-Security Configuration"

so12

Add new record name as "outgoing-security"

so13

so14

Set Alias name as "wso2carbon" and password as "wso2carbon"

so15

9. Add new WS Entry "TimeStamp"

so16

so17

Set value as "300000"

so18

9. Add another WS Entry "Signature"

Keystore : wso2carbon.jks
Alias : wso2carbon
Password : wso2carbon
Key Identifier type : Binary Security Token
Signature Algorithm : http://www.w3.org/2000/09/xmldsig#rsa-sha1
Signature Canonicalization : http://www.w3.org/2001/10/xml-exc-c14n#
Digest Algorithm : sha1
Use Single certificate : true

Parts - Add a new sign part for SOAP body. For that use the following values

ID - [keep it as blank]
Name - Body
Namespace - http://www.w3.org/2003/05/soap-envelope
Encode - Content

so19

9. Add another WS Entry "Encryption"

so20
Keystore : wso2carbon.jks
Alias : wso2carbon
Password : wso2carbon
Key Identifier type : Binary Security Token
Symmetric Encoding Algorithm : <Default>
Key Encryption Algorithm : <Default>
Encryption Canonicalization : <Default>
Create Encrypted Key : true
Parts - Add a new Encryption part

ID - [keep it as blank]
Name - Body
Namespace - http://www.w3.org/2003/05/soap-envelope
Encode - Content

so24

10. Save the SoapUI project and select the one of function under soap12Binding and go to request

Select "Aut" and Set the  "Outgoing WSS" and "Incoming WSS"

so23

11. Invoke the service with the required parameters

so25

Thursday, December 13, 2012

How to Invoke the "echo service" secured with Kerberos in WSO2 ESB

This is most useful sample to verify the echo service secured with "kerberos"

First you have to download the WSO2-ESB 4.5.0 and WSO2-IS 4.0.0
In this example IS(Identity Server) act as KDC(key distribution center) so first of all we have to configure the IS

Open the bellow mentioned files and do the required changes

1. $IS_HOME/repository/conf/embedded-ldap.xml

Download Sample embedded-ldap.xml here
under <KDCServer> and  make the property "enable" = true as follows
<Property name="enabled">true</Property>

add this property under <KDCServer>
<Property name="preAuthenticationTimeStampEnabled">false</Property>

2. $IS_HOME/repository/conf/user-mgt.xml

Download Sample user-mgt.xml here
under <ApacheDSUserStoreManager>
<Property name="kdcEnabled">true</Property>

3. $IS_HOME/repository/conf/security/krb5.conf

Download Sample krb5.conf here

[libdefaults]
default_realm = WSO2.ORG
default_tkt_enctypes = des-cbc-md5 des-cbc-crc des3-cbc-sha1
default_tgs_enctypes = des-cbc-md5 des-cbc-crc des3-cbc-sha1
permitted_enctypes = des-cbc-md5 des-cbc-crc des3-cbc-sha1
allow_weak_crypto = true

[realms]
WSO2.ORG = {
kdc = 127.0.0.1:8000
}

[domain_realm]
.wso2.org = WSO2.ORG
wso2.org = WSO2.ORG

[login]
krb4_convert = true
krb4_get_tickets = false

4. $IS_HOME/repository/conf/security/jaas.conf

Download Sample jaas.conf here

Server {
com.sun.security.auth.module.Krb5LoginModule required
useKeyTab=false
storeKey=true
useTicketCache=false
isInitiator=false
principal="esb/localhost@WSO2.ORG";
};

Client {
com.sun.security.auth.module.Krb5LoginModule required
useTicketCache=false;
};

Now IS is configured successfully
Go to $IS_HOME/bin and run the wso2serever.sh

If IS configured properly, when your stating the IS you can see this log in command line
"[2012-12-13 14:40:32,426] INFO {org.apache.directory.server.kerberos.kdc.KdcServer} - Kerberos service started."

Now you have to create the Server principle that we mention in "jass.conf"

Login to IS buy using username - "admin" password -"admin" and go to configure->Service Principle and create   It

is

Register the Server Principle
Service Name : esb/localhost
Description : Test
Password : dinuka
Re Password : dinuka

Next we have to create Client Principle that means "User"

Username : dinuka
Password : dinuka
User Role : admin
is

Lets move to configure the ESB

First go to $ESB_HOME/repository/conf/security/
and place the same krb5.conf and jaas.conf files in $IS_HOME/repository/conf/security/

Open $IS_HOME/repository/conf/carbon.xml and change the offset 0 to 1 and start the ESB
Download sample carbon.xml here

Go to ESB and secure the "echo" service with kerboros

is1

Service Principle Name : esb/localhost
Service Principle Password : dinuka

is2

We are done with the configuration now we have to invoke the echo service so you can download the Java Client from here

You have to set the project dependencies for above client so point the all jars in $ESB_HOME/repository/components/plugins 

If you change username and password at the configuration time you have to make those changes on the above client also Go to policy.xml in the above client and change the following details according to your setting

<rampart:property name="client.principal.name">dinuka</rampart:property>
<!-- Authenticating user password -->
<rampart:property name="client.principal.password">dinuka</rampart:property>
<!-- To which service client needs to talk to -->
<rampart:property name="service.principal.name">esb/localhost@WSO2.ORG</rampart:property>

Finally change the ECHO_SERVICE_EPR  relevant to the your ESB and run the KerberosClient.java

Results should be

Calling Echo service with parameter - Hello World
Response : <ns:echoStringResponse xmlns:ns="http://echo.services.core.carbon.wso2.org"><return>Hello World</return></ns:echoStringResponse>