How to Start WSO2 ESB with external LDAP

WSO2 ESB is a fast, light-weight, and versatile Enterprise Service Bus. Using WSO2 ESB you can perform a variety of enterprise integration patterns, including filtering, transforming, and routing SOAP, binary, plain XML, and text messages that pass through your business systems by HTTP, HTTPS, JMS, mail, etc.

By default, ESB uses embedded jdbc user store as user management data source.
Default configuration as follows:
<UserStoreManager class="org.wso2.carbon.user.core.jdbc.JDBCUserStoreManager">
<Property name="ReadOnly">false</Property>
<Property name="MaxUserNameListLength">100</Property>
<Property name="IsEmailUserName">false</Property>
<Property name="DomainCalculation">default</Property>
<Property name="PasswordDigest">SHA-256</Property>
<Property name="StoreSaltedPassword">true</Property>
<Property name="UserNameUniqueAcrossTenants">false</Property>
<Property name="PasswordJavaRegEx">^[\S]{5,30}$</Property>
<Property name="PasswordJavaScriptRegEx">^[\\S]{5,30}$</Property>
<Property name="UsernameJavaRegEx">^[^~!#$;%^*+={}\\|\\\\&lt;&gt;,\'\"]{3,30}$</Property>
<Property name="UsernameJavaScriptRegEx">^[\\S]{3,30}$</Property>
<Property name="RolenameJavaRegEx">^[^~!#$;%^*+={}\\|\\\\&lt;&gt;,\'\"]{3,30}$</Property>
<Property name="RolenameJavaScriptRegEx">^[\\S]{3,30}$</Property>
<Property name="UserRolesCacheEnabled">true</Property>
<Property name="maxFailedLoginAttempt">0</Property>

Now, I'll explain how to use external LDAP for ESB user-management user store.

WSO2 IS has its embedded LDAP and here I am going to use it as ESB's external LDAP.

Prerequisites: You need WSO2 ESB and WSO2 IS.
Any version you can choose as per the requirement and extract them
Step 1: Start IS with default port.

Step 2: Change ESB offset (since WSO2 IS uses the default port as per Step 1)
  1. Navigate to ESB_HOME/repository/conf/carbon.xml
    ex: <Offset>1</Offset>
Step 3: Chage user-mgt.xml (ESB_HOME/repository/user-mgt.xml
  1. <Property name="MultiTenantRealmConfigBuilder">org.wso2.carbon.user.core.config.multitenancy.CommonLDAPRealmConfigBuilder</Property>
  2. Comment default internal JDBC user store configurations ( showed in the beginning of this article)
  3. Uncomment external LDAP section
<!-- If product is using an external LDAP as the user store in read/write mode, use following user manager
In case if user core cache domain is needed to identify uniquely set property <Property name="UserCoreCacheIdentifier">domain</Property> -->
<UserStoreManager class="org.wso2.carbon.user.core.ldap.ReadWriteLDAPUserStoreManager">
<Property name="ConnectionURL">ldap://localhost:10389</Property>
<Property name="ConnectionName">uid=admin,ou=system</Property>
<Property name="ConnectionPassword">secret</Property>
<Property name="passwordHashMethod">PLAIN_TEXT</Property>
<Property name="UserNameListFilter">(objectClass=person)</Property>
<Property name="UserEntryObjectClass">inetOrgPerson</Property>
<Property name="UserSearchBase">ou=system</Property>
<Property name="UserNameSearchFilter">(&amp;(objectClass=person)(uid=?))</Property>
<Property name="UserNameAttribute">uid</Property>
<Property name="UsernameJavaRegEx">[a-zA-Z0-9._-|//]{3,30}$</Property>
<Property name="UsernameJavaScriptRegEx">^[\\S]{3,30}$</Property>
<Property name="RolenameJavaScriptRegEx">^[\\S]{3,30}$</Property>
<Property name="RolenameJavaRegEx">[a-zA-Z0-9._-|//]{3,30}$</Property>
<Property name="PasswordJavaScriptRegEx">^[\\S]{5,30}$</Property>
<Property name="ReadLDAPGroups">true</Property>
<Property name="WriteLDAPGroups">true</Property>
<Property name="EmptyRolesAllowed">false</Property>
<Property name="GroupSearchBase">ou=system</Property>
<Property name="GroupNameListFilter">(objectClass=groupOfNames)</Property>
<Property name="GroupEntryObjectClass">groupOfNames</Property>
<Property name="GroupNameSearchFilter">(&amp;(objectClass=groupOfNames)(cn=?))</Property>
<Property name="GroupNameAttribute">cn</Property>
<Property name="MembershipAttribute">member</Property>
<Property name="UserRolesCacheEnabled">true</Property>
<Property name="ReplaceEscapeCharactersAtUserLogin">true</Property>
<Property name="maxFailedLoginAttempt">0</Property>
<Property name="DomainName"></Property>

  1. You need to change some properties according to IS user-mgt.xml (Refer the IS user-mgt/xml and its default LDAP settings)
  • No need to change the LDAP Port if IS started on default port
    (Othereise: 10389+<offset value>)
    ie: <Property name="ConnectionURL">ldap://localhost:10389</Property>
  • <Property name="ConnectionPassword">admin</Property>
  • <Property name="passwordHashMethod">SHA</Property>
  • <Property name="UserEntryObjectClass">identityPerson</Property>
  • <Property name="UserSearchBase">ou=Users,dc=wso2,dc=org</Property>
  • <Property name="GroupSearchBase">ou=Groups,dc=wso2,dc=org</Property>

Step 4: Start ESB

How to Convert JMeter Responses' Content-Type Header to any Format

There are situations where you will get different formatted responses in JMeter.

As an example you will get binary response which is not readable. i.e: "Content-Type: application/octet-stream"
 Yet, you want to convert them to human readable format such as "Content-Type: application/xml"

To Convert the content-Type format, "Accept" header in HTTP Header Manager can be used.
Accept: application/xml or Aceept: text/xml, application/xhtml+xml

Send JMeter requests such as POST, PUT, GET, DELETE and view the message format with TCPMON.
(TCPMon is a utility that allows the messages to be viewed and resent. It is very much useful as a debug tool.

tcpmon response from backend:

HTTP/1.1 200 OK
Set-Cookie: JSESSIONID=83A7EAF464474482FAB4ACE810E14592; Path=/jaxrs_basic_44/; HttpOnly
Date: Thu, 16 May 2013 04:51:13 GMTfr
Content-Type: application/octet-stream
Content-Length: 115
Server: WSO2 Carbon Server

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
      <name>method : test1</name>

Binary format Response at user level: 

HTTP/1.1 200 OK
Content-Type: application/xml; charset=UTF-8
Server: WSO2 Carbon Server
Set-Cookie: JSESSIONID=83A7EAF464474482FAB4ACE810E14592; Path=/jaxrs_basic_44/; HttpOnly
Date: Thu, 16 May 2013 04:51:13 GMT
Transfer-Encoding: chunked
Connection: keep-alive

<axis2ns11:binary xmlns:axis2ns11="">PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiIHN0YW5kYWxvbmU9InllcyI/PjxDdXN0b21lcj48aWQ+MTIzPC9pZD48bmFtZT5tZXRob2QgOiB0ZXN0MTwvbmFtZT48L0N1c3RvbWVyPg==</axis2ns11:binary>0

After Using the "Accept" header in JMeter HTTP Header Manager (Refer the screenshot to add the Accept header):

Response at user level:
HTTP/1.1 200 OK
Content-Type: application/xml; charset=UTF-8
Server: WSO2 Carbon Server
Set-Cookie: JSESSIONID=78A769D448B58BC8D0F2D7858AB20E63; Path=/jaxrs_basic_44/; HttpOnly
Date: Thu, 16 May 2013 06:16:36 GMT
Transfer-Encoding: chunked
Connection: keep-alive

   <name>method : test1</name></Customer>0

Step by step guide to configure multiple ActiveMQ instances in one Server

1. Download ActiveMQ binary file
(ex: apache-activemq-5.4.2-bin.tar.gz from
2. untar the .tar.gz file
tar -zxvf apache-activemq-5.4.2-bin.tar.gz

Create and Start instance 1:
1.  Navigate to ActiveMQ folder:
cd /home/test/apache-activemq-5.4.2
2. Create an ActiveMQ instance as instance1:
bin/activemq create instance1
(This will create a folder as instance1: "/home/test/apache-activemq-5.4.2/instance1")
3.  bin/activemq setup ~/.activemqrc-instance-instance1
4.  ln -s activemq bin/activemq-instance-instance1
5.  Give executable permission to instance:
chmod 755 instance1/bin/instance1
6.  cd instance1/bin (i.e: /home/test/apache-activemq-5.4.2/instance1/bin)
7.  Start intsnace1
./instance1 console

Create and Start instance 2:
8.   cd /home/test/apache-activemq-5.4.2
9.   bin/activemq create instance2
10. bin/activemq setup ~/.activemqrc-instance-instance2
11. ln -s activemq bin/activemq-instance-instance2
12. chmod 755 instance2/bin/instance2
13. Edit activemq.xml file and jetty.xml in /<instance>/conf folder
  • cd instance2 (i.e: /home/test/apache-activemq-5.4.2/instance2)
  • vi conf/activemq.xml
  • Edit “transportConnectors” port:
    (ex:<transportConnector name="openwire" uri="tcp://"/>)
Default setting as follows:
<transportConnectors> <transportConnector name="openwire" uri="tcp://"/> </transportConnectors>
  • save and exit

  • vi conf/jetty.xml
  • Edit “Connector” port
    (ex: <property name="port" value="8162" />
Default setting as follows:
<property name="connectors"> <list>
<bean id="Connector" class="org.eclipse.jetty.server.nio.SelectChannelConnector">
<property name="port" value="8161" />
  • save and exit
14. cd instance2/bin (i.e: /home/test/apache-activemq-5.4.2/instance2/bin)
15. Start intsnace2
./instance2 console

Note: Any number of instances can be configured and started accordingly.