<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-11195359</id><updated>2026-07-18T23:35:35.580+12:00</updated><category term="ADFS"/><category term="Misc"/><category term="C#"/><category term="Visual Studio"/><category term="WIF"/><category term="Java"/><category term=".NET"/><category term="SAML"/><category term="Stackoverflow"/><category term="AAD"/><category term="ASP.NET"/><category term="Windows Server 2016"/><category term="OAuth2"/><category term="Windows"/><category term="AD"/><category term="Windows XP"/><category term="Azure"/><category term="Blackberry"/><category term="IdentityServer"/><category term="Azure B2C"/><category term="Eclipse"/><category term="LINQ"/><category term="Postman"/><category term="SOAP"/><category term="Unix"/><category term="WCF"/><category term="Compact Framework"/><category term="Netbeans"/><category term="ASP"/><category term="IIS 7"/><category term="OpenID Connect"/><category term="Auth0"/><category term="Certificates"/><category term="OWIN"/><category term="Powershell"/><category term="Web services"/><category term="Weblogic"/><category term="ADAL"/><category term="DOS"/><category term="IIS"/><category term="Musings"/><category term="Claims"/><category term="Cobol"/><category term="IE"/><category term="LDAP"/><category term="Security"/><category term="Tomcat"/><category term="Blogger"/><category term="Excel"/><category term="JAX-WS"/><category term="MVC"/><category term="Metro"/><category term="SOAPUI"/><category term="SQL"/><category term="Selenium"/><category term="WebAPI"/><category term="openSTA"/><category term=".NET Core"/><category term="ACS"/><category term="Google"/><category term="IDE"/><category term="Internet Explorer"/><category term="JMeter"/><category term="Selenium IDE"/><category term="Selenium RC"/><category term="Swagger"/><category term="XML"/><category term="EJB"/><category term="Git"/><category term="Glassfish"/><category term="HTTP"/><category term="Intellisense"/><category term="JBoss"/><category term="Kerberos"/><category term="Log4J"/><category term="Node.js"/><category term="OpenNETCF"/><category term="SQL CE"/><category term="Speaking"/><category term="Team Test"/><category term="Vista"/><category term="Web Application Proxy"/><category term="Windows Server 2008"/><category term="Windows Server 2012 R2"/><category term="XSS"/><category term="msdeploy"/><category term="Access Panel"/><category term="C"/><category term="CXF"/><category term="Fiddler"/><category term="Firefox"/><category term="Identity"/><category term="JWT"/><category term="Log4Net"/><category term="MFA"/><category term="MSIL"/><category term="Mercurial"/><category term="NLOG"/><category term="Passport"/><category term="Powerpoint"/><category term="Rant"/><category term="Regex"/><category term="Rhino Mocks"/><category term="SQL Server"/><category term="Serverfault"/><category term="SharePoint 2010"/><category term="Subversion"/><category term="TechNet"/><category term="TechNet Wiki"/><category term="VB"/><category term="Version Control"/><category term="jQuery"/><title type='text'>Random thoughts and collisions</title><subtitle type='html'>Ideas and thoughts about Microsoft Identity, C# development, cabbages and kings and random flotsam on the incoming tide</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>675</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-11195359.post-4675330512188957570</id><published>2020-09-22T20:27:00.002+12:00</published><updated>2020-09-22T20:27:42.708+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Misc"/><title type='text'>Misc: New blog</title><content type='html'>&lt;p&gt;&amp;nbsp;I&#39;ve been doing this for a while and the reason for &quot;hiding&quot; behind &quot;nzpcmad&quot; longer exists.&lt;/p&gt;&lt;p&gt;So jump over here for my &lt;a href=&quot;https://medium.com/the-new-control-plane&quot;&gt;new blog&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;Thanks for all the comments and input over the years!&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;I will still monitor the blog for comments etc.&lt;/p&gt;&lt;p&gt;Enjoy!&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/4675330512188957570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/4675330512188957570' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4675330512188957570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4675330512188957570'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2020/09/misc-new-blog.html' title='Misc: New blog'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-2654461468438322406</id><published>2020-03-31T13:58:00.002+13:00</published><updated>2020-03-31T13:58:32.094+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Misc"/><title type='text'>Misc : One million hits</title><content type='html'>I don&#39;t blog much here anymore but just hit a milestone:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYM3nd2nX7IbqQcRT1XHnNKO5N_GJTW6MCopV3i8497IyNNP-QBXpecx3yAsDfA48kpnRhD3C7757OWPPCXXs9v9po0l7P-VOto5dz6jskaxxa8ZxaUC-yUuaJdB_MyP004rB/s1600/Blogger.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;144&quot; data-original-width=&quot;1284&quot; height=&quot;68&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYM3nd2nX7IbqQcRT1XHnNKO5N_GJTW6MCopV3i8497IyNNP-QBXpecx3yAsDfA48kpnRhD3C7757OWPPCXXs9v9po0l7P-VOto5dz6jskaxxa8ZxaUC-yUuaJdB_MyP004rB/s640/Blogger.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Over a million hits!!!&lt;br /&gt;
&lt;br /&gt;
Somewhat humbled to think I&#39;ve helped a large percentage of those. &lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/2654461468438322406/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/2654461468438322406' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2654461468438322406'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2654461468438322406'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2020/03/misc-one-million-hits.html' title='Misc : One million hits'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSYM3nd2nX7IbqQcRT1XHnNKO5N_GJTW6MCopV3i8497IyNNP-QBXpecx3yAsDfA48kpnRhD3C7757OWPPCXXs9v9po0l7P-VOto5dz6jskaxxa8ZxaUC-yUuaJdB_MyP004rB/s72-c/Blogger.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-4388668523285703712</id><published>2019-03-08T09:39:00.002+13:00</published><updated>2019-03-08T09:39:24.870+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AD"/><title type='text'>AD : Domain Controller password policy</title><content type='html'>Every now and then you get an error:&lt;br /&gt;
&lt;br /&gt;
&quot;&lt;span for=&quot;newPasswordInput&quot; id=&quot;errorText&quot;&gt;Unable to update the 
password. The value provided for the new password does not meet the 
length, complexity, or history requirements of the domain.&lt;/span&gt;&quot;&lt;br /&gt;
&lt;br /&gt;
So you need to find out the allowed length in the password policy.&lt;br /&gt;
&lt;br /&gt;
An easy way to do this is to run:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;secpol.msc&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvUGBOOpvqn22HetolGZy9XOzpaWKhe32WR9zrXjQB3D3raZ1CGvdhxUB8xQFB-R5EAjr99W5jvU4ksqlybCbvNE52hacvjTMg_xMKkcGGELHb7eK-o6v7wyc6lCctMCAio2u3/s1600/secpol.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;150&quot; data-original-width=&quot;766&quot; height=&quot;75&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvUGBOOpvqn22HetolGZy9XOzpaWKhe32WR9zrXjQB3D3raZ1CGvdhxUB8xQFB-R5EAjr99W5jvU4ksqlybCbvNE52hacvjTMg_xMKkcGGELHb7eK-o6v7wyc6lCctMCAio2u3/s400/secpol.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Other reasons for this message are that you have already changed your password in the last 24 hours or that you have reused a password that you used in the last 24 passwords.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/4388668523285703712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/4388668523285703712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4388668523285703712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4388668523285703712'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2019/03/ad-domain-controller-password-policy.html' title='AD : Domain Controller password policy'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvUGBOOpvqn22HetolGZy9XOzpaWKhe32WR9zrXjQB3D3raZ1CGvdhxUB8xQFB-R5EAjr99W5jvU4ksqlybCbvNE52hacvjTMg_xMKkcGGELHb7eK-o6v7wyc6lCctMCAio2u3/s72-c/secpol.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-3003785466948627287</id><published>2019-02-27T15:27:00.000+13:00</published><updated>2019-02-27T15:27:04.561+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="IdentityServer"/><title type='text'>IdentityServer: IResourceOwnerPasswordValidator</title><content type='html'>I was looking at idsrv4 and how to integrate it with a custom user store. In this case it was SQL Server.&lt;br /&gt;
&lt;br /&gt;idsrv4 uses .NET Core 2.2 but a lot of the samples I found were for earlier versions of .Net Core.&lt;br /&gt;&lt;br /&gt;Some of the samples used IUserService but I couldn&#39;t find that.&lt;br /&gt;&lt;br /&gt;So Mr Google to the rescue.&lt;br /&gt;&lt;br /&gt;e.g.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://stackoverflow.com/questions/35304038/identityserver4-register-userservice-and-get-users-from-database-in-asp-net-core&quot;&gt;https://stackoverflow.com/questions/35304038/identityserver4-register-userservice-and-get-users-from-database-in-asp-net-core&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&quot;In IdentityServer4. IUserService is not available anymore, now you have to use IResourceOwnerPasswordValidator to do the authentication and to use IProfileService to get the claims.&quot;&lt;br /&gt;&lt;br /&gt;The problem I have with this is that Resource Owner Password is not just a random method name. It&#39;s the name of an OAuth flow! Most people don&#39;t realise this.&lt;br /&gt;
&lt;br /&gt;
My client used implicit flow. Using IResourceOwnerPasswordValidator makes no sense.&lt;br /&gt;
&lt;br /&gt;
So&amp;nbsp; you can just use a controller to authenticate the user like the AccountController.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/3003785466948627287/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/3003785466948627287' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/3003785466948627287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/3003785466948627287'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2019/02/identityserver-iresourceownerpasswordva.html' title='IdentityServer: IResourceOwnerPasswordValidator'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-637968213698221426</id><published>2019-01-29T13:52:00.001+13:00</published><updated>2019-01-29T13:53:12.477+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Azure"/><title type='text'>Azure : Web API - The requested resource does not support http method &#39;GET&#39;</title><content type='html'>I was running a web API on Azure and doing a POST.&lt;br /&gt;
&lt;br /&gt;
The full error is:&lt;br /&gt;
&lt;br /&gt;
{&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &quot;Message&quot;: &quot;The requested resource does not support http method &#39;GET&#39;.&quot;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
That&#39;s weird because the method is decorated with&amp;nbsp; [HttpPost] and I was doing a POST.&lt;br /&gt;
&lt;br /&gt;
Then I noticed that I was calling Azure with a http connection.&lt;br /&gt;
&lt;br /&gt;
Changing to https fixed the issue.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/637968213698221426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/637968213698221426' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/637968213698221426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/637968213698221426'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2019/01/azure-web-api-requested-resource-does.html' title='Azure : Web API - The requested resource does not support http method &#39;GET&#39;'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-5075622204074915692</id><published>2018-12-06T09:34:00.002+13:00</published><updated>2018-12-06T09:34:21.836+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ADFS"/><title type='text'>ADFS : MSIS7042 - The same client browser session has made &#39;6&#39; requests</title><content type='html'>The full error message is:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Exception details: 
  Microsoft.IdentityServer.Web.InvalidRequestException: MSIS7042: The 
same client browser session has made &#39;6&#39; requests in the last &#39;7&#39; 
seconds. Contact your administrator for details.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
There are many causes for this; one being the &quot;missing /&quot; on the identifier.&lt;br /&gt;
&lt;br /&gt;
I found one recently where I was running an ASP.NET MVC application inside VS that was authenticated via ADFS. This used the OWIN WS-Fed middleware.&lt;br /&gt;
&lt;br /&gt;
I couldn&#39;t authenticate because of this error.&lt;br /&gt;
&lt;br /&gt;
ADFS will only accept https connections so the RP was configured with a:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;https://localhost/...&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
endpoint&lt;br /&gt;
&lt;br /&gt;
But on VS, inside &quot;Properties / Web&quot;, I noticed that the URL was:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;i&gt;http://localhost/...&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Setting this to https fixed the problem.&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
Go figure.&lt;br /&gt;
&lt;br /&gt;
I found a similar solution &lt;a href=&quot;https://stackoverflow.com/a/38203126/9922&quot;&gt;here&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/5075622204074915692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/5075622204074915692' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/5075622204074915692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/5075622204074915692'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/12/adfs-msis7042-same-client-browser.html' title='ADFS : MSIS7042 - The same client browser session has made &#39;6&#39; requests'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-8142676936901687890</id><published>2018-11-23T08:04:00.005+13:00</published><updated>2018-11-23T11:10:53.401+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Azure"/><title type='text'>Azure AD : Getting the UPN</title><content type='html'>I&#39;ve been playing around with the custom SAML connection  in Azure AD and the &quot;claims transformations&quot;&amp;nbsp; that you can do e.g. tolower.&lt;br /&gt;
&lt;br /&gt;
My interest was Guest accounts.&lt;br /&gt;
&lt;br /&gt;
The user screens don&#39;t show the UPN so I needed to do this with PowerShell.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;connect-azuread -tenant tenantname&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;i&gt;Get-AzureADUser -Filter &quot;userType eq &#39;Guest&#39;&quot; -All $true | select Displa&lt;br /&gt;yName,UserPrincipalName,Mail,Department,UserType,CreationType,RefreshTokensValid&lt;br /&gt;FromDateTime,AccountEnabled&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
This displays:&lt;br /&gt;
&lt;br /&gt;
DisplayName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Joe&lt;br /&gt;
UserPrincipalName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : joe@company.com#EXT#@tenantname&lt;br /&gt;
Mail&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : joe@company.com&lt;br /&gt;
Department&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;br /&gt;
UserType&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Guest&lt;br /&gt;
CreationType&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Invitation&lt;br /&gt;
RefreshTokensValidFromDateTime : 21/11/2018 11:13:58 p.m.&lt;br /&gt;
AccountEnabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : True&lt;br /&gt;
&lt;br /&gt;
Or if you wanted the top 10:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Get-AzureADUser -Filter &quot;userType eq &#39;Guest&#39;&quot;&lt;b&gt; -Top 10&lt;/b&gt; | select DisplayNa&lt;br /&gt;me,UserPrincipalName,Mail,Department,UserType,CreationType,RefreshTokensValidFro&lt;br /&gt;mDateTime,AccountEnabled&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Or complex filter:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Get-AzureADUser -Filter &quot;mail eq &#39;joe@company.com&#39; &lt;b&gt;and&lt;/b&gt; userType eq &#39;&lt;br /&gt;Guest&#39;&quot;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
If you want to see the full list of Azure AD attributes with the complete schema, use:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Get-AzureADUser&amp;nbsp; -All $true | fl &amp;gt; allad.txt &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/8142676936901687890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/8142676936901687890' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/8142676936901687890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/8142676936901687890'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/11/azure-ad-getting-upn.html' title='Azure AD : Getting the UPN'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-2230339419304830657</id><published>2018-10-24T08:38:00.002+13:00</published><updated>2018-10-24T08:39:20.127+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Azure B2C"/><title type='text'>Azure B2C : Calling a web API from Azure AD B2C using data types</title><content type='html'>There is a good overview &lt;a href=&quot;https://docs.microsoft.com/en-us/azure/active-directory-b2c/active-directory-b2c-custom-rest-api-netfw&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
In terms of the data types that you can pass, these can be: &lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;boolean&lt;/li&gt;
&lt;li&gt;date&lt;/li&gt;
&lt;li&gt;dateTime&lt;/li&gt;
&lt;li&gt;int&lt;/li&gt;
&lt;li&gt;long&lt;/li&gt;
&lt;li&gt;string&lt;/li&gt;
&lt;li&gt;stringCollection&lt;/li&gt;
&lt;li&gt;alternativeSecurityIdCollection&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAhiV8hIhknZBeIKG4Zw2yiQ0Ftf-UKsG2mZsCB6u8pOC8BbVUIWvPMlhoZ8u4fETPBqWjNMsMhQ6p858bVDKAcRG1n-y9htxbq6Hee7y2rE-tuA39AK4IAZbiv0KvCJcyiNcA/s1600/Screen+Shot+10-24-18+at+08.30+AM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;485&quot; data-original-width=&quot;600&quot; height=&quot;321&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAhiV8hIhknZBeIKG4Zw2yiQ0Ftf-UKsG2mZsCB6u8pOC8BbVUIWvPMlhoZ8u4fETPBqWjNMsMhQ6p858bVDKAcRG1n-y9htxbq6Hee7y2rE-tuA39AK4IAZbiv0KvCJcyiNcA/s400/Screen+Shot+10-24-18+at+08.30+AM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The above is the XML to define some of the claim types.&lt;br /&gt;
&lt;br /&gt;
In terms of the JWT returned, the claims look like:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDB5S-cF-a0uF5viWw3Y-yXG-d4yc45FpFckupg7J6d4l5c-q-9bdrD0eQgRSCqysecDV3yb4by6xz2TxTZPlkOmzL30WjRnYjP_n5yoNu1fOxyM8kLgNs26cwlk1wcsqORLyy/s1600/Screen+Shot+10-24-18+at+08.36+AM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;585&quot; data-original-width=&quot;600&quot; height=&quot;390&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDB5S-cF-a0uF5viWw3Y-yXG-d4yc45FpFckupg7J6d4l5c-q-9bdrD0eQgRSCqysecDV3yb4by6xz2TxTZPlkOmzL30WjRnYjP_n5yoNu1fOxyM8kLgNs26cwlk1wcsqORLyy/s400/Screen+Shot+10-24-18+at+08.36+AM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;Enjoy!</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/2230339419304830657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/2230339419304830657' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2230339419304830657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2230339419304830657'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/10/azure-b2c-calling-web-api-from-azure-ad.html' title='Azure B2C : Calling a web API from Azure AD B2C using data types'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAhiV8hIhknZBeIKG4Zw2yiQ0Ftf-UKsG2mZsCB6u8pOC8BbVUIWvPMlhoZ8u4fETPBqWjNMsMhQ6p858bVDKAcRG1n-y9htxbq6Hee7y2rE-tuA39AK4IAZbiv0KvCJcyiNcA/s72-c/Screen+Shot+10-24-18+at+08.30+AM.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-6755111090204671886</id><published>2018-09-11T08:09:00.002+12:00</published><updated>2018-09-11T08:09:55.609+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Misc"/><title type='text'>Misc - a busy day at the office!</title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkORmkG6M5S7JuF-ICDUQxmnp6uLsLiOoOJ7jlN0VgvTEbCjECehsqj8U6N7oSgfuwUOZG3f5wNl_EzB430lUEXcfXKeis-eTaGe63fCimRYoeZouBrHpvjvQHLb0a9RBOpB_7/s1600/Screen+Shot+09-11-18+at+08.07+AM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;637&quot; data-original-width=&quot;800&quot; height=&quot;316&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkORmkG6M5S7JuF-ICDUQxmnp6uLsLiOoOJ7jlN0VgvTEbCjECehsqj8U6N7oSgfuwUOZG3f5wNl_EzB430lUEXcfXKeis-eTaGe63fCimRYoeZouBrHpvjvQHLb0a9RBOpB_7/s400/Screen+Shot+09-11-18+at+08.07+AM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Busy on the forums!&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/6755111090204671886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/6755111090204671886' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6755111090204671886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6755111090204671886'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/09/misc-busy-day-at-office.html' title='Misc - a busy day at the office!'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkORmkG6M5S7JuF-ICDUQxmnp6uLsLiOoOJ7jlN0VgvTEbCjECehsqj8U6N7oSgfuwUOZG3f5wNl_EzB430lUEXcfXKeis-eTaGe63fCimRYoeZouBrHpvjvQHLb0a9RBOpB_7/s72-c/Screen+Shot+09-11-18+at+08.07+AM.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-6905141550769782548</id><published>2018-08-27T08:12:00.001+12:00</published><updated>2018-08-27T08:12:53.611+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Stackoverflow"/><title type='text'>stackoverflow : Top 1%</title><content type='html'>Finally got there:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHOso7ooyvlUVoNmz9JDfsPYC_5AsxtqaVv4xB2lFKeu5_VjaKulrTSDOfb0yq6E8my3WKq83tKWnYfa6sgvR4_ia0GAPIp-LetRVApBXBIXNQTaXxFnX4yiWmEqzu1uMBaRn/s1600/Screen+Shot+08-27-18+at+08.07+AM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;210&quot; data-original-width=&quot;440&quot; height=&quot;190&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHOso7ooyvlUVoNmz9JDfsPYC_5AsxtqaVv4xB2lFKeu5_VjaKulrTSDOfb0yq6E8my3WKq83tKWnYfa6sgvR4_ia0GAPIp-LetRVApBXBIXNQTaXxFnX4yiWmEqzu1uMBaRn/s400/Screen+Shot+08-27-18+at+08.07+AM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
There are over 9 million users on stackoverflow and currently I&#39;m sitting at:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm5Nn5d_oEO9XOQmvJP5qtx8L5-fk3VGX9frKAR1FEGjitLH-5NgfWVazpIvYjegSwK_tsFtfawu8CV7npDvi3QJDfZ7qnVn1F9fn6CQSZhEHAielqvRryE0wOVbARUO-S6g8o/s1600/Screen+Shot+08-27-18+at+08.09+AM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;102&quot; data-original-width=&quot;740&quot; height=&quot;55&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm5Nn5d_oEO9XOQmvJP5qtx8L5-fk3VGX9frKAR1FEGjitLH-5NgfWVazpIvYjegSwK_tsFtfawu8CV7npDvi3QJDfZ7qnVn1F9fn6CQSZhEHAielqvRryE0wOVbARUO-S6g8o/s400/Screen+Shot+08-27-18+at+08.09+AM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Now it gets into the decimals e.g. top 0.5 %&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/6905141550769782548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/6905141550769782548' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6905141550769782548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6905141550769782548'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/08/stackoverflow-top-1.html' title='stackoverflow : Top 1%'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWHOso7ooyvlUVoNmz9JDfsPYC_5AsxtqaVv4xB2lFKeu5_VjaKulrTSDOfb0yq6E8my3WKq83tKWnYfa6sgvR4_ia0GAPIp-LetRVApBXBIXNQTaXxFnX4yiWmEqzu1uMBaRn/s72-c/Screen+Shot+08-27-18+at+08.07+AM.PNG" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-3207083057941125362</id><published>2018-08-24T14:04:00.000+12:00</published><updated>2018-08-27T07:40:50.648+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Misc"/><title type='text'>Misc : My audience</title><content type='html'>Just out of interest, my audience as reported by Blogger.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiONcZ3jnjqbUNCNzk6h2NuBj5KFdY8Qd15YZ6-AfB1qH5b1NXJf-6s2_4BoAOThTaNv9-gFFeG1_tudJdUlYq7W9R5-2uYAMNnwuFaGS9dDsX5OydH3Ea6I0EHzncC08IL1pLd/s1600/Screen+Shot+08-24-18+at+01.29+PM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;523&quot; data-original-width=&quot;800&quot; height=&quot;260&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiONcZ3jnjqbUNCNzk6h2NuBj5KFdY8Qd15YZ6-AfB1qH5b1NXJf-6s2_4BoAOThTaNv9-gFFeG1_tudJdUlYq7W9R5-2uYAMNnwuFaGS9dDsX5OydH3Ea6I0EHzncC08IL1pLd/s400/Screen+Shot+08-24-18+at+01.29+PM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Strange that Google has &quot;Unknown Region&quot;?&lt;br /&gt;
&lt;br /&gt;
Chrome is way ahead on the browsers and Windows is way ahead on the OS.&lt;br /&gt;
&lt;br /&gt;
Would have thought the iPad figure would be higher but maybe iPad users have no interest in Identity :-)&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/3207083057941125362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/3207083057941125362' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/3207083057941125362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/3207083057941125362'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/08/misc-my-audience.html' title='Misc : My audience'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiONcZ3jnjqbUNCNzk6h2NuBj5KFdY8Qd15YZ6-AfB1qH5b1NXJf-6s2_4BoAOThTaNv9-gFFeG1_tudJdUlYq7W9R5-2uYAMNnwuFaGS9dDsX5OydH3Ea6I0EHzncC08IL1pLd/s72-c/Screen+Shot+08-24-18+at+01.29+PM.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-1943464645929483656</id><published>2018-08-24T13:25:00.000+12:00</published><updated>2018-08-24T13:25:40.390+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="C#"/><title type='text'>C# : Invalid URI</title><content type='html'>The full message is:&lt;br /&gt;
&lt;br /&gt;
&quot;Invalid URI : The hostname could not be parsed&quot;.&lt;br /&gt;
&lt;br /&gt;
I get this using the URIBuilder class.&lt;br /&gt;
&lt;br /&gt;
Since it was complaining about the hostname I checked the DNS, I checked that I could ping it, I tried the IP address etc. etc.&lt;br /&gt;
&lt;br /&gt;
Eventually worked out that it was because the password contained special characters.&lt;br /&gt;
&lt;br /&gt;
You are apparently supposed to URL encode them.&lt;br /&gt;
&lt;br /&gt;
Just changed the password to use letters and numbers and all was well.&lt;br /&gt;
&lt;br /&gt;
Somewhat misleading error message :-)&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/1943464645929483656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/1943464645929483656' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/1943464645929483656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/1943464645929483656'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/08/c-invalid-uri.html' title='C# : Invalid URI'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-6611100660097938094</id><published>2018-07-13T07:11:00.001+12:00</published><updated>2018-07-13T07:12:37.487+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Stackoverflow"/><title type='text'>stackoverflow : Answered 1,000 questions</title><content type='html'>Achievement unlocked!&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhh7jiz5rj2gwnlt10flcCStA9YAurNSvpPl5dBLFTUmq99igGwdiPYAShBgtQ9OgY82ltjHzXB1-7dTLGJXhi3TEnvATmRJKmx2E619W8jScQpEOGXJju8WgL74XfcOCTxQehk/s1600/Rep.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;242&quot; data-original-width=&quot;972&quot; height=&quot;98&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhh7jiz5rj2gwnlt10flcCStA9YAurNSvpPl5dBLFTUmq99igGwdiPYAShBgtQ9OgY82ltjHzXB1-7dTLGJXhi3TEnvATmRJKmx2E619W8jScQpEOGXJju8WgL74XfcOCTxQehk/s400/Rep.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
Most of these are in the Identity space and of course the problem is that in order to answer a question, someone has to ask it first.&lt;br /&gt;
&lt;br /&gt;
It is somewhat of a niche category. I&#39;ve been on stackoverflow for 9 years and 10 months (at time of writing) so it&#39;s taken a while to get here.&lt;br /&gt;
&lt;br /&gt;
Looking at the tags e.g. ADFS:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibh5ynMJvxwfRcTJVvWCOqciX-IlJjoEerTK5gITL-91bxxzBG1GwQWoNPkbPIM0Hmx-rXCbwGVMWdudeeUDyljiz8Ewax3wKC2_LcpbSZUUHFNg5KoXYOLP2TFPyc52VefI6G/s1600/ADFS.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;723&quot; data-original-width=&quot;607&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibh5ynMJvxwfRcTJVvWCOqciX-IlJjoEerTK5gITL-91bxxzBG1GwQWoNPkbPIM0Hmx-rXCbwGVMWdudeeUDyljiz8Ewax3wKC2_LcpbSZUUHFNg5KoXYOLP2TFPyc52VefI6G/s640/ADFS.PNG&quot; width=&quot;536&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
What&#39;s also interesting about this is the other contributors.&lt;br /&gt;
&lt;br /&gt;
Just calling out some of them:&lt;br /&gt;
&lt;br /&gt;
Eugenio Pace and Matias Woloski are the founders of Auth0 and vibronet has recently joined them.&lt;br /&gt;
&lt;br /&gt;
leastprivilege is one of the people behind identityserver.&lt;br /&gt;
&lt;br /&gt;
Across the other tags:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilF8QDJL_ha9QAKav1M0C34Cb_I_ptfVmEhefncz74UiGmg6Uq9iPm3rUAeXWKK5SdSkBiKjhqEawADErGQVOHLLo8AcZw6l8DqhUeuoVS8JQWd-dX2tj6xWGlQwvtg4CBbYiI/s1600/Percentage.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;219&quot; data-original-width=&quot;620&quot; height=&quot;141&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEilF8QDJL_ha9QAKav1M0C34Cb_I_ptfVmEhefncz74UiGmg6Uq9iPm3rUAeXWKK5SdSkBiKjhqEawADErGQVOHLLo8AcZw6l8DqhUeuoVS8JQWd-dX2tj6xWGlQwvtg4CBbYiI/s400/Percentage.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I guess now I need to identify my next achievement!&lt;br /&gt;
&lt;br /&gt;
And onto the next 1,000!&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/6611100660097938094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/6611100660097938094' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6611100660097938094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6611100660097938094'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/07/stackoverflow-answered-1000-questions.html' title='stackoverflow : Answered 1,000 questions'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhh7jiz5rj2gwnlt10flcCStA9YAurNSvpPl5dBLFTUmq99igGwdiPYAShBgtQ9OgY82ltjHzXB1-7dTLGJXhi3TEnvATmRJKmx2E619W8jScQpEOGXJju8WgL74XfcOCTxQehk/s72-c/Rep.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-2398201513605850544</id><published>2018-07-12T07:06:00.002+12:00</published><updated>2018-07-12T07:06:30.013+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Certificates"/><title type='text'>Certificates : Displaying errors</title><content type='html'>Quite often, you can&#39;t connect to an SSL site because .NET will tell you that the certificate is invalid.&lt;br /&gt;
&lt;br /&gt;
This openssl command shows you the certificate errors:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;openssl s_client -connect company.co.nz:443|openssl x509 -text&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
The output looks like:&lt;br /&gt;
&lt;br /&gt;
depth=2 CN = Company Root CA&lt;br /&gt;
&lt;i&gt;verify error:num=19:self signed certificate in certificate chain&lt;/i&gt;&lt;br /&gt;
Certificate:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; Data:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Version: 3 (0x2)&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Serial Number:&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1f:06:eb:c1:00:34:00:05:56:38&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
etc.&lt;br /&gt;
&lt;br /&gt;
It also checks the intermediate and root CA certificate validation chain.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/2398201513605850544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/2398201513605850544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2398201513605850544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2398201513605850544'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/07/certificates-displaying-errors.html' title='Certificates : Displaying errors'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-4115351999781674109</id><published>2018-07-06T07:32:00.002+12:00</published><updated>2018-07-06T07:32:51.961+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Certificates"/><title type='text'>Certificates : The remote certificate is invalid according to the validation procedure</title><content type='html'>I see this error so many times. It is generally on the client side as part of the .NET framework.&lt;br /&gt;
&lt;br /&gt;
The root cause of this is:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Your server certificate is self-signed&lt;/li&gt;
&lt;li&gt;You are using an incorrect host name to connect&lt;/li&gt;
&lt;li&gt;Your certificate is not trusted&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
The host name must match the subject name on the certificate e.g. company.com and orders.company.com both point to the same URL but the certificate has been issued to company.com. So that is the name you need to use to get to the web site. Or else you can add the other names to the SAN.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
If the certificate is not trusted, you can add it to the &quot;Trusted Root Certification Authorities&quot;. But be mindful of security.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
I find it useful to &lt;a href=&quot;https://blogs.msdn.microsoft.com/jpsanders/2009/09/16/troubleshooting-asp-net-the-remote-certificate-is-invalid-according-to-the-validation-procedure/&quot;&gt;log&lt;/a&gt; why .NET doesn&#39;t like it.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Just in case that article disappears, I&#39;ve saved the config &lt;a href=&quot;https://gist.github.com/nzpcmad/6f2592fb6275c2f3ff4fd628c7db8b43&quot;&gt;here&lt;/a&gt;.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;Key info:&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
The Network Service account must be able to write to this log so give the account access to the directory.&amp;nbsp;&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Change the log location.&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;i&gt;e.g. initializeData=&quot;c:\Logs\Trace.log&quot;&lt;/i&gt;&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Now assume that company.com is not in the DNS and you have an IP address e.g. 124.40.60.80.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Now the URL is 124.40.60.80 but the certificate subject name is company.com. Bingo. You get the error.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
The solution is to create a host file entry.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
124.40.60.80 company.com&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Now you can browse to company.com and the name will match.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Enjoy!&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/4115351999781674109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/4115351999781674109' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4115351999781674109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4115351999781674109'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/07/certificates-remote-certificate-is.html' title='Certificates : The remote certificate is invalid according to the validation procedure'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-7398485256890959627</id><published>2018-07-06T06:41:00.003+12:00</published><updated>2018-07-06T06:42:15.683+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Visual Studio"/><title type='text'>Visual Studio : You need to find somefile.cs to view the source</title><content type='html'>Debugging through some socket code and suddenly the debugger came up with the above when I tried to step into the .NET code.&lt;br /&gt;
&lt;br /&gt;
It was asking for NetworkStream.cs , Socket.cs etc.&lt;br /&gt;
&lt;br /&gt;
Trying to browse to the file wasn&#39;t helping.&lt;br /&gt;
&lt;br /&gt;
So Mr. Google to the rescue.&lt;br /&gt;
&lt;br /&gt;
The solution is:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Visual Studio / Tools / Options / Debugging / General / Enable source server support&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Problem solved.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/7398485256890959627/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/7398485256890959627' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/7398485256890959627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/7398485256890959627'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/07/visual-studio-you-need-to-find.html' title='Visual Studio : You need to find somefile.cs to view the source'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-2653589173816985016</id><published>2018-07-03T06:40:00.004+12:00</published><updated>2018-07-03T06:40:45.664+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="C#"/><title type='text'>C# : The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly</title><content type='html'>Busy doing some work with a SQL component.&lt;br /&gt;
&lt;br /&gt;
To check all was well, I set VS to break-point on all CLR exceptions and suddenly it came up with the above error.&lt;br /&gt;
&lt;br /&gt;
WTF?&lt;br /&gt;
&lt;br /&gt;
Lots of discussions with Mr. Google and the usual ton of garbage but then I found &lt;a href=&quot;https://jack-vanlightly.com/blog/2016/11/15/new-sqlconnection-the-requested-performance-counter-is-not-a-custom-counter&quot;&gt;this&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Run &quot;cmd&quot; as admin.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;cd C:\Windows\Inf\.NET Data Provider for SqlServer&lt;/i&gt;&lt;div&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div&gt;
&lt;i&gt;lodctr _dataperfcounters_shared12_neutral.ini&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;That did the trick.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
BTW, lodctr &quot;allows you to register or save performance counter name and registry settings in a file and designate trusted services&quot;.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Enjoy!&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/2653589173816985016/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/2653589173816985016' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2653589173816985016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/2653589173816985016'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/07/c-requested-performance-counter-is-not.html' title='C# : The requested Performance Counter is not a custom counter, it has to be initialized as ReadOnly'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-6735984072269352503</id><published>2018-07-02T07:03:00.002+12:00</published><updated>2018-07-02T07:09:15.244+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Log4Net"/><title type='text'>log4net: Why are all logs written to when I invoke just one?</title><content type='html'>I was trying to get log4net working and I wanted 3 logs:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Console&lt;/li&gt;
&lt;li&gt;Text file&lt;/li&gt;
&lt;li&gt;Event log&lt;/li&gt;
&lt;/ul&gt;
So the config. looked like:&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
root&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; !--level value=&quot;ALL&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; appender-ref ref=&quot;ConsoleLog&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; appender-ref ref=&quot;Log&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; appender-ref ref=&quot;EventLog&quot; /--&lt;br /&gt;
&amp;nbsp;/root&lt;/blockquote&gt;
and then e.g.:&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
appender name=&quot;ConsoleLog&quot; type=&quot;log4net.Appender.ColoredConsoleAppender&quot;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; mapping&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; level value=&quot;ERROR&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; foreColor value=&quot;White&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; backColor value=&quot;Red, HighIntensity&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; /mapping&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; layout type=&quot;log4net.Layout.PatternLayout&quot;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; conversionPattern value=&quot;%date [%thread] %level %logger - %message%newline&quot;/&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; /layout&lt;br /&gt;
/appender&amp;nbsp;&lt;/blockquote&gt;
and called via e.g. :&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;private static readonly ILog LogConsole = log4net.LogManager.GetLogger(&quot;ConsoleLog&quot;);&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
But when I tried e.g.&lt;br /&gt;
&lt;br /&gt;
LogConsole.Info&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
all three logs were invoked and all three entries were written!&lt;br /&gt;
&lt;br /&gt;
Turns out you need to remove the root level and use e.g.:&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
logger name=&quot;ConsoleLog&quot;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; level value=&quot;ALL&quot; /&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; appender-ref ref=&quot;ConsoleLog&quot; /&lt;br /&gt;
/logger&lt;/blockquote&gt;
where the&amp;nbsp; &quot;appender-ref&quot; points to the correct log.&lt;br /&gt;
&lt;br /&gt;
Then all works as expected.&lt;br /&gt;
&lt;br /&gt;
Note: angle brackets removed for display purposes!&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/6735984072269352503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/6735984072269352503' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6735984072269352503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6735984072269352503'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/07/i-was-trying-to-get-log4net-working-and.html' title='log4net: Why are all logs written to when I invoke just one?'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-3266886897114229844</id><published>2018-06-20T15:43:00.002+12:00</published><updated>2018-06-20T15:44:15.255+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Auth0"/><title type='text'>Auth0 playground</title><content type='html'>Auth0 have a neat &lt;a href=&quot;https://auth0.github.io/playground/&quot;&gt;playground&lt;/a&gt; where you can play around with the Lock settings.&lt;br /&gt;
&lt;br /&gt;
Lock is the Auth0 login component.&lt;br /&gt;
&lt;br /&gt;
I was trying to get some extra fields added when the user wants to self-register and we want to capture some extra information.&lt;br /&gt;
&lt;br /&gt;
There are examples but they don&#39;t have context i.e. they show you what attribute to set but you don&#39;t get to see the full picture.&lt;br /&gt;
&lt;br /&gt;
As usual, the gist is &lt;a href=&quot;https://gist.github.com/nzpcmad/58384013b67153098e0071f227f007bd&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKmF6okAD00TFruZ-0fz_aAHJ_gRK8uxrPJ7jKloLz8wmCaFKArLecln8kdCXMZk0eI3XB6OQTu163pWnEUlMAQoBGeutNwCfXknKsaVZQvkHp70W5omPffq9MT1s0ILSu79J7/s1600/Screen+Shot+06-20-18+at+03.34+PM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;647&quot; data-original-width=&quot;400&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKmF6okAD00TFruZ-0fz_aAHJ_gRK8uxrPJ7jKloLz8wmCaFKArLecln8kdCXMZk0eI3XB6OQTu163pWnEUlMAQoBGeutNwCfXknKsaVZQvkHp70W5omPffq9MT1s0ILSu79J7/s400/Screen+Shot+06-20-18+at+03.34+PM.PNG&quot; width=&quot;246&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
This is the basic screen - notice I&#39;ve added some of the Asian social providers like Baidu. This isn&#39;t part of the js - it&#39;s part of the application configuration.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpbijTglFstpPC9LHVoOWimCN5mjh7QkUVf0R5SKQo5Obfhx7_oMX8J_tq1ym0lDmF9ron4PftGwiCbli4xwt5vi4xGFIILjhdsy30Lg7lV6vpZebjwvI9H8aJyw1I7u5XIa3o/s1600/Screen+Shot+06-20-18+at+03.37+PM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;872&quot; data-original-width=&quot;400&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpbijTglFstpPC9LHVoOWimCN5mjh7QkUVf0R5SKQo5Obfhx7_oMX8J_tq1ym0lDmF9ron4PftGwiCbli4xwt5vi4xGFIILjhdsy30Lg7lV6vpZebjwvI9H8aJyw1I7u5XIa3o/s400/Screen+Shot+06-20-18+at+03.37+PM.PNG&quot; width=&quot;182&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Here is the signup screen. Clicking &quot;United States&quot; shows the drop-down. Also notice the checkbox at the bottom.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir4R26Hf__1h-X056Ng4I9sSDyHVbIV9XlrvO3PC_NKJHPWgMYqpgX8t22VAvIddfFOd97_CmW-GZNbS2e3FQ7toMG0YoAB8Tq0_soVQUAeGvqSqUjX7Useh7J0TF_daCpPGFF/s1600/Screen+Shot+06-20-18+at+03.37+PM+001.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;237&quot; data-original-width=&quot;350&quot; height=&quot;270&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir4R26Hf__1h-X056Ng4I9sSDyHVbIV9XlrvO3PC_NKJHPWgMYqpgX8t22VAvIddfFOd97_CmW-GZNbS2e3FQ7toMG0YoAB8Tq0_soVQUAeGvqSqUjX7Useh7J0TF_daCpPGFF/s400/Screen+Shot+06-20-18+at+03.37+PM+001.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Shortening the text shows the error message that is part of the validation.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh70Suo9gnFHrRVu9ClkUSg-p0cwsKSbAexecsOyTF5GbfxScTJqKt-MX47eQJOqVbuwLcSQUcVflzmv83CEZPRJBjOIiLkFzZ7vdRMVNlHG08OGD7lMuWqZlSoWnZCmT5-81XG/s1600/Screen+Shot+06-20-18+at+03.38+PM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;746&quot; data-original-width=&quot;400&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh70Suo9gnFHrRVu9ClkUSg-p0cwsKSbAexecsOyTF5GbfxScTJqKt-MX47eQJOqVbuwLcSQUcVflzmv83CEZPRJBjOIiLkFzZ7vdRMVNlHG08OGD7lMuWqZlSoWnZCmT5-81XG/s400/Screen+Shot+06-20-18+at+03.38+PM.PNG&quot; width=&quot;213&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/3266886897114229844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/3266886897114229844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/3266886897114229844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/3266886897114229844'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/06/auth0-playground.html' title='Auth0 playground'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKmF6okAD00TFruZ-0fz_aAHJ_gRK8uxrPJ7jKloLz8wmCaFKArLecln8kdCXMZk0eI3XB6OQTu163pWnEUlMAQoBGeutNwCfXknKsaVZQvkHp70W5omPffq9MT1s0ILSu79J7/s72-c/Screen+Shot+06-20-18+at+03.34+PM.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-6036821818777278812</id><published>2018-05-16T15:03:00.000+12:00</published><updated>2018-05-16T15:30:11.248+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ADFS"/><title type='text'>ADFS : Cookies, tokens and timeouts</title><content type='html'>This is for Server 2016 (ADFS 4.0).&lt;br /&gt;
&lt;br /&gt;
I&#39;ve been helping a customer get to the bottom of token timeouts, sessions timeouts etc.&lt;br /&gt;
&lt;br /&gt;
The two best links I&#39;ve found are:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/ad-fs-single-sign-on-settings&quot;&gt;AD FS Single Sign-On Settings&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://blog.msresource.net/2016/07/07/active-directory-federation-services-adfs-single-sign-on-sso-and-token-lifetime-settings/&quot;&gt;Active Directory Federation Services (#ADFS) Single Sign On (SSO) and token lifetime settings&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
and a few lines in:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-faq&quot;&gt;AD FS Frequently Asked Questions (FAQ)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
that are:&lt;br /&gt;
&lt;br /&gt;
&quot;&lt;b&gt;How long are ADFS tokens valid? &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Often this question means ‘how long do users get single sign on (SSO) without having to enter new credentials, and how can I as an admin control that?’ This behavior, and the configuration settings that control it, are described in the article &lt;a href=&quot;https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-fs/operations/ad-fs-2016-single-sign-on-settings&quot;&gt;here&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
The default lifetimes of the various cookies and tokens are listed below (as well as the parameters that govern the lifetimes): &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Registered Devices&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
PRT and SSO cookies: 90 days maximum, governed by PSSOLifeTimeMins. (Provided device is used at least every 14 days, which is controlled by DeviceUsageWindow)&lt;br /&gt;
&lt;br /&gt;
Refresh token: calculated based on the above to provide consistent behavior &lt;br /&gt;
&lt;br /&gt;
access_token: 1 hour by default, based on the relying party &lt;br /&gt;
&lt;br /&gt;
id_token: same as access token&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Un-registered Devices&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
SSO cookies: 8 hours by default, governed by SSOLifetimeMins. When Keep Me Signed in (KMSI) is enabled, default is 24 hours and configurable via KMSILifetimeMins. &lt;br /&gt;
&lt;br /&gt;
Refresh token: 8 hours by default. 24 hours with KMSI enabled &lt;br /&gt;
&lt;br /&gt;
access_token: 1 hour by default, based on the relying party &lt;br /&gt;
&lt;br /&gt;
id_token: same as access token&quot;&lt;br /&gt;
&lt;br /&gt;
And here we see the first problem - there is a major distinction between registered and unregistered (aka non registered) devices and most of the documentation is for the former.&lt;br /&gt;
&lt;br /&gt;
A registered device is a device that has been provisioned via EMS / Intune. You could add domain-joined here. This allows a user to BYOD and still have access to a company&#39;s intranet.&lt;br /&gt;
&lt;br /&gt;
So if you have a customer with a B2C type of scenario where their users have a wide range of devices and never need to access the company intranet, you start to see some problems.&lt;br /&gt;
&lt;br /&gt;
The first issue is that of persistent cookies.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Set-AdfsProperties –EnablePersistentSso &lt;/i&gt;&lt;boolean&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;
These are not enabled for unregistered devices. You can turn them on with the KMSI (Keep Me Signed In) option.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Set-AdfsProperties -EnableKmsi $true&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
What you now see in a PC browser is:&lt;/boolean&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code class=&quot;lang-powershell&quot;&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7tT4Sys0H2SbhAoBfvIG_uHQytibkzG1-FDb6IjFF0EKEPjNyPqEh65o1pznwfiqqWBtXrv9isMuKEVBeuT-dIVDjWHQtByG-P8cr1jmZH1Bqp3q1l27pkRfKub9FojfJ_osk/s1600/Screen+Shot+05-16-18+at+10.54+AM.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;264&quot; data-original-width=&quot;400&quot; height=&quot;263&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7tT4Sys0H2SbhAoBfvIG_uHQytibkzG1-FDb6IjFF0EKEPjNyPqEh65o1pznwfiqqWBtXrv9isMuKEVBeuT-dIVDjWHQtByG-P8cr1jmZH1Bqp3q1l27pkRfKub9FojfJ_osk/s400/Screen+Shot+05-16-18+at+10.54+AM.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;pre&gt;&lt;code class=&quot;lang-powershell&quot;&gt;
&lt;/code&gt;&lt;/pre&gt;
&amp;nbsp;and indeed the cookies are now persistent if you tick the box.&lt;br /&gt;
&lt;br /&gt;
The defaults have changed from 8 hours to 24 as above.&lt;br /&gt;
&lt;br /&gt;
However, on some mobile devices, the onload.js has a:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;style=&quot;display:none&quot;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
which means that it does not display and you are back to square one.&lt;br /&gt;
&lt;br /&gt;
This may be because there is a:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&quot;&amp;amp;prompt=login&quot;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
in the query string,&lt;br /&gt;
&lt;br /&gt;
So assuming &lt;b&gt;KMSI is on&lt;/b&gt;, you have:&lt;br /&gt;
&lt;br /&gt;
access token = id-token = 1 hour&lt;br /&gt;
&lt;br /&gt;
SSO cookie = refresh token = 24 hours&lt;br /&gt;
&lt;br /&gt;
To change the default:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Set-AdfsProperties – KmsiLifetimeMins int32&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
and if &lt;b&gt;KMSI is off&lt;/b&gt;:&lt;br /&gt;
&lt;br /&gt;
access token = id-token = 1 hour&lt;br /&gt;
&lt;br /&gt;
SSO cookie = refresh token = 8 hours&lt;br /&gt;
&lt;br /&gt;
To change the default:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Set-AdfsProperties –SsoLifetime int32&lt;int32&gt; &lt;/int32&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Also note that there is a KMSI &quot;user component&quot; (which adds the box) and a KMSI &quot;ADFS feature&quot; (that changes the timeout values).&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
You don&#39;t want the refresh token to time out because that would force the user to re-authenticate.&lt;br /&gt;
&lt;br /&gt;
So you can use the &quot;authorize&quot; endpoint to get a brand new set of tokens. Because the SSO cookie has not yet expired, ADFS will simply mint a new set without any login requirement.&lt;br /&gt;
&lt;br /&gt;
The tokens are &quot;brand new&quot; e.g the id-token will be valid for another hour.&lt;br /&gt;
&lt;br /&gt;
By a &quot;new set&quot;, I mean an access token, a refresh token and an id-token.&lt;br /&gt;
&lt;br /&gt;
You get the same behaviour if you call the refresh endpoint.&lt;br /&gt;
&lt;br /&gt;
However, I noticed that although the value of the refresh token is different, it has the same&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&quot;refresh_token_expires_in&quot;: 72186&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
value (adjusted by the time it took to do the refresh itself).&lt;br /&gt;
&lt;br /&gt;
So the new refresh token inherits the old &quot;time to timeout&quot;.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/6036821818777278812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/6036821818777278812' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6036821818777278812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6036821818777278812'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/05/adfs-cookies-tokens-and-timeouts.html' title='ADFS : Cookies, tokens and timeouts'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7tT4Sys0H2SbhAoBfvIG_uHQytibkzG1-FDb6IjFF0EKEPjNyPqEh65o1pznwfiqqWBtXrv9isMuKEVBeuT-dIVDjWHQtByG-P8cr1jmZH1Bqp3q1l27pkRfKub9FojfJ_osk/s72-c/Screen+Shot+05-16-18+at+10.54+AM.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-8096807432452697679</id><published>2018-04-24T09:49:00.001+12:00</published><updated>2018-04-24T09:49:49.344+12:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Stackoverflow"/><title type='text'>Stackoverflow : How to treat newbies</title><content type='html'>Joel Spolsky is writing a series of articles on the evolution of &lt;a href=&quot;https://www.joelonsoftware.com/2018/04/06/the-stack-overflow-age/&quot;&gt;stackoverflow&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Part of this is the treatment of newbies; in particular the arrogant treatment of people who genuinely need an answer but don&#39;t know how to ask the question.&lt;br /&gt;
&lt;br /&gt;
Jon Skeet wrote an &lt;a href=&quot;https://codeblog.jonskeet.uk/2010/08/29/writing-the-perfect-question/&quot;&gt;excellent post&lt;/a&gt; on how to ask a question.&lt;br /&gt;
&lt;br /&gt;
The problem arises when they don&#39;t know enough to do that.&lt;br /&gt;
&lt;br /&gt;
e.g. &quot;My boss tells me that I need to convert my ASP.NET Membership application to SAML 2.0. I&#39;ve googled SAML for a whole day and am hopelessly confused&quot;.&lt;br /&gt;
&lt;br /&gt;
Now, the standard response on stackoverflow is to close this - too broad - not focused - not a programming question.&lt;br /&gt;
&lt;br /&gt;
All of which is true and this question could also go on serverfault.&lt;br /&gt;
&lt;br /&gt;
But that doesn&#39;t help the newbie.&lt;br /&gt;
&lt;br /&gt;
My approach is to say something like:&lt;br /&gt;
&lt;br /&gt;
&quot;OK - you need a SAML stack on the client side. Here&#39;s a list of SAML clients, Find one that fits your requirements (language, cost etc.) and read the documentation and samples&quot;.&lt;br /&gt;
&lt;br /&gt;
Then I ask what IDP they plan to use?&lt;br /&gt;
&lt;br /&gt;
And depending on that, I may have some more suggestions or links to a good post.&lt;br /&gt;
&lt;br /&gt;
The outcome is that the newbie has something concrete to go on.&lt;br /&gt;
&lt;br /&gt;
(I leave the admin. to other people). &lt;br /&gt;
&lt;br /&gt;
In fact, that&#39;s how this blog originally started.&lt;br /&gt;
&lt;br /&gt;
I was answering the same question again and again and so I answered the question in the blog and then posted the link. Major time saving.&lt;br /&gt;
&lt;br /&gt;
The other point is that I can&#39;t do their job for them. All I can do is point them in the right direction.&lt;br /&gt;
&lt;br /&gt;
The comments section in stackoverflow is for further questions.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/8096807432452697679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/8096807432452697679' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/8096807432452697679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/8096807432452697679'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/04/stackoverflow-how-to-treat-newbies.html' title='Stackoverflow : How to treat newbies'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-4591098523647992866</id><published>2018-03-29T10:55:00.003+13:00</published><updated>2018-03-29T10:55:45.788+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Certificates"/><title type='text'>Certificates : Removing a certificate store folder</title><content type='html'>I created the wrong folder using makecert and you can&#39;t remove it using &quot;mmc&quot;.&lt;br /&gt;
&lt;br /&gt;
Then I found this &lt;a href=&quot;http://www.digitallycreated.net/Blog/58/removing-a-windows-system-certificate-store&quot;&gt;post&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;void Main()&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; int CERT_SYSTEM_STORE_LOCATION_SHIFT = 16;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uint CERT_SYSTEM_STORE_CURRENT_USER_ID = 1;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uint CERT_SYSTEM_STORE_LOCAL_MACHINE_ID = 2;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uint CERT_STORE_DELETE_FLAG = 0x10;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uint CERT_SYSTEM_STORE_CURRENT_USER = CERT_SYSTEM_STORE_CURRENT_USER_ID &amp;lt;&amp;lt; CERT_SYSTEM_STORE_LOCATION_SHIFT;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uint CERT_SYSTEM_STORE_LOCAL_MACHINE = CERT_SYSTEM_STORE_LOCAL_MACHINE_ID &amp;lt;&amp;lt; CERT_SYSTEM_STORE_LOCATION_SHIFT;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; CertUnregisterSystemStore(&quot;makecert&quot;, CERT_STORE_DELETE_FLAG | CERT_SYSTEM_STORE_CURRENT_USER);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;[DllImport(&quot;crypt32.dll&quot;, CharSet = CharSet.Unicode)]&lt;br /&gt;public static extern bool CertUnregisterSystemStore(string systemStore, uint flags); &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Also need to add:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;using System.Runtime.InteropServices;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
and run in LINQPad as a &quot;C# program&quot;.&lt;br /&gt;
&lt;br /&gt;
Works for &quot;Current User&quot; but doesn&#39;t seem to work for &quot;Local Computer&quot;.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/4591098523647992866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/4591098523647992866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4591098523647992866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/4591098523647992866'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/03/certificates-removing-certificate-store.html' title='Certificates : Removing a certificate store folder'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-7750133602097241453</id><published>2018-03-20T08:08:00.000+13:00</published><updated>2018-03-20T08:08:42.097+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ADFS"/><category scheme="http://www.blogger.com/atom/ns#" term="Certificates"/><title type='text'>Certificates : Getting the thumbprint via OpenSSL</title><content type='html'>I&#39;ve been looking at AWS Cognito and keep coming across interesting snippets of how to do things.&lt;br /&gt;
&lt;br /&gt;
Let&#39;s say you wanted the ADFS thumbprint for the SSL certificate.&lt;br /&gt;
&lt;br /&gt;
You could do this via mmc or via the ADFS wizard or via the IIS binding.&lt;br /&gt;
&lt;br /&gt;
You could also do:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;openssl s_client -showcerts -connect my-adfs:443&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Note: You just use the top-level ADFS URL - don&#39;t add /adfs/ls etc.&lt;br /&gt;
&lt;br /&gt;
This displays:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Loading &#39;screen&#39; into random state - done&lt;br /&gt;CONNECTED(000005DC)&lt;br /&gt;depth=0 CN = my-adfs&lt;br /&gt;verify error:num=18:self signed certificate&lt;br /&gt;verify return:1&lt;br /&gt;depth=0 CN = my-adfs&lt;br /&gt;verify return:1&lt;br /&gt;---&lt;br /&gt;Certificate chain&lt;br /&gt;&amp;nbsp;0 s:/CN=my-adfs&lt;br /&gt;&amp;nbsp;&amp;nbsp; i:/CN=my-adfs&lt;br /&gt;-----BEGIN CERTIFICATE-----&lt;br /&gt;MIIExD...vLMng0&lt;br /&gt;-----END CERTIFICATE-----&lt;br /&gt;---&lt;br /&gt;Server certificate&lt;br /&gt;subject=/CN=my-adfs&lt;br /&gt;issuer=/CN=my-adfs&lt;br /&gt;---&lt;br /&gt;No client certificate CA names sent&lt;br /&gt;---&lt;br /&gt;SSL handshake has read 1964 bytes and written 447 bytes&lt;br /&gt;---&lt;br /&gt;New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384&lt;br /&gt;Server public key is 4096 bit&lt;br /&gt;Secure Renegotiation IS supported&lt;br /&gt;Compression: NONE&lt;br /&gt;Expansion: NONE&lt;br /&gt;SSL-Session:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol&amp;nbsp; : TLSv1.2&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cipher&amp;nbsp;&amp;nbsp;&amp;nbsp; : ECDHE-RSA-AES256-GCM-SHA384&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session-ID: 29140000...E4D79A337F1F0BBC9&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session-ID-ctx:&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Master-Key: 91E8...DE30CD&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Key-Arg&amp;nbsp;&amp;nbsp; : None&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PSK identity: None&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PSK identity hint: None&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SRP username: None&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start Time: 1521150875&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timeout&amp;nbsp;&amp;nbsp; : 300 (sec)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Verify return code: 18 (self signed certificate)&lt;br /&gt;---&lt;br /&gt;read:errno=10054&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Copy / paste this section:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;-----BEGIN CERTIFICATE-----&lt;br /&gt;MIIExD...vLMng0&lt;br /&gt;-----END CERTIFICATE-----&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
into a file called e.g. adfs.cer&lt;br /&gt;
&lt;br /&gt;
Then:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;openssl x509 -in c:\xxx\adfs.cer -fingerprint -noout&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;&lt;i&gt;SHA1 Fingerprint=24:F8:...:9A:21:2B:35&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/7750133602097241453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/7750133602097241453' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/7750133602097241453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/7750133602097241453'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/03/certificates-getting-thumbprint-via.html' title='Certificates : Getting the thumbprint via OpenSSL'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-6990410699016797104</id><published>2018-03-13T15:55:00.000+13:00</published><updated>2018-03-13T16:01:25.309+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="SAML"/><title type='text'>SAML : Decoding the SAML response</title><content type='html'>I&#39;ve blogged before about this and I normally use the SAML Tracer running under Firefox.&lt;br /&gt;
&lt;br /&gt;
Someone asked me about AWS Cognito and while I was having a look at this and doing some troubleshooting, I came across a page that also showed you how you can do this with PowerShell.&lt;br /&gt;
&lt;br /&gt;
Basically, in your trace find the &quot;SAML Response&quot;.&lt;br /&gt;
&lt;br /&gt;
Then copy / paste it into:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String(&quot;base64encodedtext&quot;))&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
so something like:&lt;br /&gt;
&lt;br /&gt;
PS C:\&amp;gt; [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64Strin&lt;br /&gt;
g(&quot;PHNhbWxwO2...c2FtbHA6UmVzcG9uc2U+&quot;))&lt;br /&gt;
&lt;br /&gt;
&lt;pre style=&quot;background-color: white; margin: 0em; overflow: auto;&quot;&gt;&lt;code style=&quot;color: black; font-family: &amp;quot;consolas&amp;quot; , &amp;quot;courier new&amp;quot; , &amp;quot;courier&amp;quot; , monospace; font-size: 10pt;&quot;&gt;&amp;lt;samlp:Response ID=&lt;span style=&quot;color: #a31515;&quot;&gt;&quot;_f560b...9cf8c7d&quot;&lt;/span&gt; Version=&lt;span style=&quot;color: #a31515;&quot;&gt;&quot;2.0&quot;&lt;/span&gt; IssueIn
stant=&lt;span style=&quot;color: #a31515;&quot;&gt;&quot;2018-03-13T02:13:05.625Z&quot;&lt;/span&gt; Destination=&lt;span style=&quot;color: #a31515;&quot;&gt;&quot;https://signin.aws.amazon.com/saml
&quot;&lt;/span&gt; Consent=&lt;span style=&quot;color: #a31515;&quot;&gt;&quot;urn:oasis:names:tc:SAML:2.0:consent:unspecified&quot;&lt;/span&gt; xmlns:samlp=&lt;span style=&quot;color: #a31515;&quot;&gt;&quot;urn:oas
is:names:tc:SAML:2.0:protocol&quot;&lt;/span&gt;&amp;gt;...&amp;lt;/Assertion&amp;gt;&amp;lt;/samlp:Response&amp;gt;&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
Neat!&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/6990410699016797104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/6990410699016797104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6990410699016797104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/6990410699016797104'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/03/saml-decoding-saml-response.html' title='SAML : Decoding the SAML response'/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11195359.post-9197825831692197111</id><published>2018-02-14T13:46:00.000+13:00</published><updated>2018-02-14T13:46:58.653+13:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ADFS"/><title type='text'>ADFS : MSIS9642: The request cannot be completed </title><content type='html'>This is for Server 2016 (ADFS 4.0).&lt;br /&gt;
&lt;br /&gt;
The full error is:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;MSIS9642: The request cannot be completed because an id token is required but the server was unable to construct an id token for the current user.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
You only get this error if you are using OpenID Connect with ADAL configured via Application Groups.&lt;br /&gt;
&lt;br /&gt;
Our setup is:&lt;br /&gt;
&lt;br /&gt;
User --&amp;gt; application --&amp;gt; external ADFS A --&amp;gt; internal ADFS B via HRD&lt;br /&gt;
&lt;br /&gt;
We had used this model no problem with OWIN OIDC applications authenticating on both the internal and external ADFS.&lt;br /&gt;
&lt;br /&gt;
However, on the applications that used ADAL, external authentication worked fine but trying the internal one threw the above error.&lt;br /&gt;
&lt;br /&gt;
ADFS A is set up as a CP to ADFS B.&lt;br /&gt;
&lt;br /&gt;
There&#39;s a good write-up &lt;a href=&quot;https://stackoverflow.com/questions/35295260/adfs-openid-connect-email-claim-and-external-adfs&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&quot;The root cause of MSIS9642 is that the new OpenID Connect Application Group features in ADFS 2016 need to issue an access token to your application. This token must include the users identity. In order to issue the token the subsystem must understand which claim in the inbound claims is used to uniquely identify the user. &lt;br /&gt;
&lt;br /&gt;
A new property called AnchorClaimType has been added to the Claim Provider Trust model.&quot;&lt;br /&gt;
&lt;br /&gt;
Note that this property is &lt;b&gt;not available&lt;/b&gt; on a RP trust.&lt;br /&gt;
&lt;br /&gt;
The PowerShell needs to be run on the CP server i.e. ADFS A.&lt;br /&gt;
&lt;br /&gt;
(Get-AdfsClaimsProviderTrust -Name &quot;CP name&quot;).anchorclaimtype&lt;br /&gt;
&lt;br /&gt;
This will be blank the first time. You can use any attribute that makes sense to uniquely identify the user. Typically, this would be sAMAccountName or UPN.&lt;br /&gt;
&lt;br /&gt;
In our case, we had a custom claim so the command was:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Set-AdfsClaimsProviderTrust -TargetName &quot;CP Trust&quot; -AnchorClaimType &quot;http://company/claims&lt;br /&gt;/sAMAccountname&quot;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
and you can check this is correct by running the above Get-AdfsClaimsProviderTrust command again.&lt;br /&gt;
&lt;br /&gt;
Remember that you need to pass-through this claim in the CP claims rules and the RP claims rules.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://nzpcmad.blogspot.com/feeds/9197825831692197111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/11195359/9197825831692197111' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/9197825831692197111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11195359/posts/default/9197825831692197111'/><link rel='alternate' type='text/html' href='http://nzpcmad.blogspot.com/2018/02/adfs-msis9642-request-cannot-be.html' title='ADFS : MSIS9642: The request cannot be completed '/><author><name>nzpcmad</name><uri>http://www.blogger.com/profile/06352759009406963230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7bWyepdP8e-NWEav1x9kUSASJtIk1xt9iiiQNqxODZbEnsUM4OK7JFayb41rI8WNM7RtwXPbjFChZWOUnvied9SI02Cwo3ZXatiklvXQORe_jddoXkHoffG5lam1xIA/s113/kiwi.jpg'/></author><thr:total>1</thr:total></entry></feed>