<div dir="ltr"><div>On Command:<br>curl -H 'Accept: application/json' -i -u 162e869a-1f22-4aba-a620-d07edb906df9:110af61f265c04e728f3fc9951afda8c <a href="http://192.168.1.11:8080/hawkular/accounts/personas/current">http://192.168.1.11:8080/hawkular/accounts/personas/current</a><br><br>Response is:<br>HTTP/1.1 403 Forbidden<br>Connection: keep-alive<br>X-Powered-By: Undertow/1<br>Server: WildFly/10<br>Content-Length: 74<br>Content-Type: text/html<br>Date: Mon, 25 Jan 2016 08:47:23 GMT<br><br><html><head><title>Error</title></head><body>403 - Forbidden</body></html><br><br></div>but replacing token key and secrete with username and password showing correct results<br><div><div class="gmail_extra"><br><div class="gmail_quote">On Sat, Jan 23, 2016 at 9:13 PM, Heiko W.Rupp <span dir="ltr"><<a href="mailto:hrupp@redhat.com" target="_blank">hrupp@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Anuj, Mazz,<br>
<span class=""><br>
On 23 Jan 2016, at 16:19, John Mazzitelli wrote:<br>
<br>
> Juca - can you take a look and tell me if its a problem in<br>
> accounts/keycloak? Based on my testing I think that's where the<br>
> problem lies, but I'm not 100% sure.<br>
<br>
</span>Does this work (for a previously created token):<br>
<br>
curl -H 'Accept: application/json' -i -u<br>
b3063b1f-640b-4853-81df-47257c01e63e:94edc711ef80c592cb417bfffd9bc496<br>
<a href="http://localhost:8080/hawkular/accounts/personas/current" rel="noreferrer" target="_blank">http://localhost:8080/hawkular/accounts/personas/current</a><br>
<br>
?<br>
<br>
( from<br>
<a href="http://www.hawkular.org/blog/2015/12/16/hawkular-1.0.0.Alpha8-released.html" rel="noreferrer" target="_blank">http://www.hawkular.org/blog/2015/12/16/hawkular-1.0.0.Alpha8-released.html</a><br>
)<br>
<div class="HOEnZb"><div class="h5"><br>
<br>
><br>
> Just create yourself a token and configure the agent to use it rather<br>
> than username/password and you should be able replicate the problem.<br>
><br>
> ----- Forwarded Message -----<br>
> From: "Anuj Garg" <<a href="mailto:anuj1708@gmail.com">anuj1708@gmail.com</a>><br>
> To: "John Mazzitelli" <<a href="mailto:mazz@redhat.com">mazz@redhat.com</a>>, "Discussions around Hawkular<br>
> development" <<a href="mailto:hawkular-dev@lists.jboss.org">hawkular-dev@lists.jboss.org</a>><br>
> Sent: Friday, January 22, 2016 10:03:12 PM<br>
> Subject: Re: [Hawkular-dev] agent cannot use security token<br>
><br>
> It happened to me too yesterday but i was thinking might be I am not<br>
> properly using the tokens coz I am new to it.<br>
> But was following the same procedure.<br>
> On 23 Jan 2016 3:26 am, "John Mazzitelli" <<a href="mailto:mazz@redhat.com">mazz@redhat.com</a>> wrote:<br>
><br>
>> I just tried installing the agent to use securityKey/securitySecret<br>
>> rather<br>
>> than username/password and it failed to authenticate with the server.<br>
>> If I<br>
>> use username/password, it works fine.<br>
>><br>
>> It isn't anything with the agent that seems to be the problem because<br>
>> during my testing, I attached to the agent with my debugger and right<br>
>> before I sent the auth message to<br>
>><br>
>> <a href="http://127.0.0.1:8080/hawkular/accounts/personas/current" rel="noreferrer" target="_blank">http://127.0.0.1:8080/hawkular/accounts/personas/current</a><br>
>><br>
>> I change the value of the key/secret to "jdoe" and "password" and it<br>
>> works. So there is something on the server-side that doesn't like the<br>
>> agent<br>
>> passing in the token credentials.<br>
>><br>
>> Can I ask if anyone else sees the same thing? It's easy to test:<br>
>><br>
>> 1) in the UI, create yourself a new token<br>
>> 2) in standalone.xml's <storage-adapter> element, change the<br>
>> "username"<br>
>> attribute name to be called "securityKey" and set its value to your<br>
>> new<br>
>> token's key and change the "password" attribute name to be called<br>
>> "securitySecret" and set its value to your new token's secret.<br>
>> 3) start the agent back up again<br>
>><br>
>> It should work, but doesn't for me. I tried it with two different<br>
>> token<br>
>> key/secret pairs, failed both times.<br>
>> _______________________________________________<br>
>> hawkular-dev mailing list<br>
>> <a href="mailto:hawkular-dev@lists.jboss.org">hawkular-dev@lists.jboss.org</a><br>
>> <a href="https://lists.jboss.org/mailman/listinfo/hawkular-dev" rel="noreferrer" target="_blank">https://lists.jboss.org/mailman/listinfo/hawkular-dev</a><br>
>><br>
> _______________________________________________<br>
> hawkular-dev mailing list<br>
> <a href="mailto:hawkular-dev@lists.jboss.org">hawkular-dev@lists.jboss.org</a><br>
> <a href="https://lists.jboss.org/mailman/listinfo/hawkular-dev" rel="noreferrer" target="_blank">https://lists.jboss.org/mailman/listinfo/hawkular-dev</a><br>
<br>
<br>
</div></div><span class="HOEnZb"><font color="#888888">--<br>
Reg. Adresse: Red Hat GmbH, Technopark II, Haus C,<br>
Werner-von-Siemens-Ring 14, D-85630 Grasbrunn<br>
Handelsregister: Amtsgericht München HRB 153243<br>
Geschäftsführer: Charles Cachera, Michael Cunningham, Paul Hickey,<br>
Charlie Peters<br>
</font></span><div class="HOEnZb"><div class="h5">_______________________________________________<br>
hawkular-dev mailing list<br>
<a href="mailto:hawkular-dev@lists.jboss.org">hawkular-dev@lists.jboss.org</a><br>
<a href="https://lists.jboss.org/mailman/listinfo/hawkular-dev" rel="noreferrer" target="_blank">https://lists.jboss.org/mailman/listinfo/hawkular-dev</a><br>
</div></div></blockquote></div><br></div></div></div>