FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login
    1. Home
    2. mark.robustelli
    3. Posts
    • Profile
    • Following 0
    • Followers 0
    • Topics 15
    • Posts 340
    • Best 22
    • Controversial 0
    • Groups 3

    Posts made by mark.robustelli

    • RE: Encountering certificate issue causing customers to be locked out

      @john-spellman, Can you let us a bit more about how you created the key? Which option did you choose to import? Which certificate type did you use? You could try different types.

      Anything you can tell us about which Identity Provider you created and what the architecture looks like will help. Is FusionAuth the IdP/SP or both?

      Also, If you can share the settings of you SAML tab for the application (without sharing secrets), that may give us some insight to the issue as well, if you are using FusionAuth as an IdP.

      I don't have a ton of experience with importing certificates, so if anyone out there knows better, please feel free to chime in.

      I have set up a key for a SAML provider before and using an RSA/RS256 type key. I generated that key with FusionAuth, but I don't see any reason you couldn't import the key you need.

      You may want to check out this blog to test a simple SAML configuration if your situation reflects the setup.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Users are unable to log in to FusionAuth

      @john-spellman I'm glad you have access to the instance. If you need help in a non public forum and you have a paid plan which includes technical support, please open a ticket via your account portal.

      If you don't have a paid plan and still want the private support, please check out theEssentials Plan. You will get private email support with that.

      Other than that, I would recommend posting the issues here and removing any sensitive info.

      Also, based on your request, be very careful of anyone reaching out to help privately. I like to believe the world is a good place, but there are bad actors out there looking to take advantage of people in your situation.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: NetworkError when attempting to fetch resource

      @kiouplidis, can you please give us a little more detail on how you are set up and exactly what you are trying to do. I see you are getting a NetworkError when trying to reach (auth.*.com). Is that an instance of FusionAuth hosted by FusionAuth or is that an instance of FusionAuth that you have deployed? How are you trying to access the resource? Through a web browser or are you trying to execute an API call? The more information you can provide, the easier it will be to help.

      If you have a paid plan which includes technical support, please open a ticket via your account portal.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Users are unable to log in to FusionAuth

      @john-spellman can you tell us a little more about your set up and situation? Was it working before? What changed? Can the one user still log into prod? The more detail you give the easier it will be for someone to help. Please do not post any passwords or secrets.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Get user email in claims with saml

      @laurent-bartet awesome! So it sounds like you had things set up right, you just were not logged out, so when you went back the reconcile event never took place cause you were already logged in. Is that right?

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Get user email in claims with saml

      @laurent-bartet hmm.., since the lambda seems to be set up correctly but appears to not be hitting, let's take a step back and look at the configuration. Can you tell me a little more about that? What identity providers you are using and how they are configured? I read you are using SAML, but it appears in the log that you are using OAuth2. If you are using OAuth2, you might be able to use a JWT populate lambda in that case, but would like to know more about your setup.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Get user email in claims with saml

      @laurent-bartet Since it is a SAML reconcile lambda, do you have it assigned to the Identity Provider?

      Settings -> Identity Providers -> {Your SAML v2 Identity Provider} -> Edit -> Reconcile Lambda

      Screenshot 2025-04-23 at 8.08.28 AM.png

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Localhost:9011 cant reach this page

      @arnel-terblanche Can you tell us a little more about your setup? Is this a first time install? Was it working before? Is this a docker image you are trying to run? Please provide more details.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Get user email in claims with saml

      @laurent-bartet

      What kind of Lambda did you create? Did you assign the Lamba to the application?

      If it was SAML V2 Poulate then make sure it is assigned to your application.

      Applications -> {Your Application} -> SAML tab -> Authentication response -> Populate Lambda -> {Choose the lambda you created}

      Also make sure you have Debug enabled set on the Lambda.

      Let me know if this helps.

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: Get user email in claims with saml

      @bartetlau Have you had a chance to check out FusionAuth Lambdas? Specifically, SAML v2 Populate Lambda? Does that get you what you need?

      posted in General Discussion
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 Awesome that you are making progress and thanks for keeping the post updated. I'll keep an eye on the thread, and if other issues come up, let us know.

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 also did you grant these scopes in the google config?
      Screenshot 2025-04-10 at 10.54.38 AM.png

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 Thanks for taking the time to work with this. It is generally a pretty straight forward process taking no more than 5 minutes. I am out of the office this week, but will try to get some time to replicate what you are going through. I want to make sure I am working on the right thing, so just want to confirm that we have the same end goal. You want the 'Login with Google' button to work for an Application you created within FusionAuth, right?

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 looks like you are getting closer. If I go back to your screenshot of the provider configuration page, it looks like the scope input box is empty. Three common scopes to include are email, profile, and openid.. Please add the correct scope(s) and let me know if that works for you.

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup reverse proxy for an SSO session bootstrap

      @joseantonio When you add the response_type=code. That should be literal 'response_type=code' not response_type={code} where {code} is some secret. Other than that, you can add additional parameters to the query string if needed. As long as you are not passing secrets in the query string you should be ok.

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 OK, it looks like the redirect_uri does not match what is configured in the application. Can you make sure you are supplying the correct uri?

      This can be found under: Applications -> Edit -> OAuth tab

      Screenshot 2025-04-07 at 8.05.59 AM.png

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: how can i learn FusionAuth?

      @cybermark0707 That is a bit of a loaded question. If you have something more specific in mind, please let me know but the following should be a good start.

      Overall:
      Getting Started

      If you are a developer and want to get hands on with an example, check out:
      Quickstarts

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup reverse proxy for an SSO session bootstrap

      @joseantonio using the response_type=code should be fine, let me know how it goes.

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 OK, let's try this. Go into the FusionAuth AdminUI.

      Go to Applications
      Find your application
      select View
      find the OAuth2 & OpenID Connect Integration details section
      copy the OAuth IdP login URL

      use that for the value of the url. Let me know if that works.

      posted in Q&A
      mark.robustelliM
      mark.robustelli
    • RE: How to setup OAuth properly

      @altear147 can you try to use application Id of the application in FusionAuth for the client_id instead of the google client id and see if that works?

      posted in Q&A
      mark.robustelliM
      mark.robustelli