Community Note
- Please vote on this issue by adding a 馃憤 reaction to the original issue to help the community and maintainers prioritize this request.
- Please do not leave "+1" comments that do not add relevant information.
- If you are interested in working on this issue or have submitted a pull request, please leave a comment.
Description
Ping CLI documents configuration under service.advancedServices.pingFederate, and the project README lists PingOne Advanced Services as a supported service. However, enabling only the Advanced Services PingFederate configuration does not register a usable service or command path.
The configuration is accepted and retained, but:
- the global authentication status reports that no services are enabled;
pingfederate commands check the ordinary service.pingFederate configuration instead; and
pingcli init offers PingOne and ordinary PingFederate, but no PingOne Advanced Services option.
This prevents the documented P1AS configuration from being used with a hosted PingFederate Admin API.
Ping CLI Version
Reproduced with:
pingcli version 1.5.0 (commit: c544919774fb2a270dd420ef7aba9fb9d90b6f46)
- Ping CLI 1.6.0 official macOS arm64 release binary
Affected Command(s)
pingcli -P p1as auth status
pingcli -P p1as pingfederate auth status
pingcli -P p1as pingfederate version get
pingcli init
Debug Output
With debug logging enabled, Ping CLI builds and initializes the ordinary PingFederate connector, but there is no corresponding initialization of the configured Advanced Services PingFederate connector.
The user-visible result includes:
$ pingcli -P p1as auth status
No services are enabled.
The pingfederate commands report that PingFederate authentication is not configured because ordinary service.pingFederate is deliberately disabled.
A complete sanitized debug log can be supplied if useful. No tenant identifiers, client credentials, or tenant hostnames are included here.
Panic Output
No panic.
Expected Behavior
When service.advancedServices.pingFederate.enabled is true, Ping CLI should recognize the service and provide a supported command path for it.
If the existing pingfederate commands are intended to manage hosted PingFederate, they should use the configured P1AS Admin API host and explicit PingOne token URL. If a separate command is intended, it should be registered and documented.
At minimum, auth status should recognize the enabled Advanced Services service rather than reporting that no services are enabled.
Actual Behavior
The Advanced Services settings are accepted by the configuration model but appear unused by command and connector registration. Only the ordinary PingFederate connector is available.
Enabling ordinary PingFederate is not an equivalent workaround: that connector derives OAuth endpoints from the PingFederate runtime base URL, while P1AS machine authentication uses an explicit PingOne token endpoint.
Steps to Reproduce
- Create a profile with ordinary PingFederate disabled.
- Configure the documented
service.advancedServices.pingFederate settings with OAuth client credentials, an external P1AS PingFederate Admin API host, and an explicit PingOne token URL.
- Set
service.advancedServices.pingFederate.enabled=true.
- Run:
pingcli -P p1as auth status
pingcli -P p1as pingfederate auth status
pingcli -P p1as pingfederate version get
- Observe that the Advanced Services configuration is not recognized.
- Run
pingcli init and observe that no Advanced Services configuration option is offered. The behavior is unchanged when experimental features are enabled.
Important Factoids
- The target is PingFederate hosted in PingOne Advanced Services, not a self-managed PingFederate deployment.
- The P1AS Admin API and OAuth token endpoint are intentionally separate: the Admin API is on the tenant's external PingFederate Admin API hostname, while client-credentials tokens come from the PingOne administrator environment.
References
Community Note
Description
Ping CLI documents configuration under
service.advancedServices.pingFederate, and the project README lists PingOne Advanced Services as a supported service. However, enabling only the Advanced Services PingFederate configuration does not register a usable service or command path.The configuration is accepted and retained, but:
pingfederatecommands check the ordinaryservice.pingFederateconfiguration instead; andpingcli initoffers PingOne and ordinary PingFederate, but no PingOne Advanced Services option.This prevents the documented P1AS configuration from being used with a hosted PingFederate Admin API.
Ping CLI Version
Reproduced with:
pingcli version 1.5.0 (commit: c544919774fb2a270dd420ef7aba9fb9d90b6f46)Affected Command(s)
pingcli -P p1as auth statuspingcli -P p1as pingfederate auth statuspingcli -P p1as pingfederate version getpingcli initDebug Output
With debug logging enabled, Ping CLI builds and initializes the ordinary PingFederate connector, but there is no corresponding initialization of the configured Advanced Services PingFederate connector.
The user-visible result includes:
The
pingfederatecommands report that PingFederate authentication is not configured because ordinaryservice.pingFederateis deliberately disabled.A complete sanitized debug log can be supplied if useful. No tenant identifiers, client credentials, or tenant hostnames are included here.
Panic Output
No panic.
Expected Behavior
When
service.advancedServices.pingFederate.enabledistrue, Ping CLI should recognize the service and provide a supported command path for it.If the existing
pingfederatecommands are intended to manage hosted PingFederate, they should use the configured P1AS Admin API host and explicit PingOne token URL. If a separate command is intended, it should be registered and documented.At minimum,
auth statusshould recognize the enabled Advanced Services service rather than reporting that no services are enabled.Actual Behavior
The Advanced Services settings are accepted by the configuration model but appear unused by command and connector registration. Only the ordinary PingFederate connector is available.
Enabling ordinary PingFederate is not an equivalent workaround: that connector derives OAuth endpoints from the PingFederate runtime base URL, while P1AS machine authentication uses an explicit PingOne token endpoint.
Steps to Reproduce
service.advancedServices.pingFederatesettings with OAuth client credentials, an external P1AS PingFederate Admin API host, and an explicit PingOne token URL.service.advancedServices.pingFederate.enabled=true.pingcli initand observe that no Advanced Services configuration option is offered. The behavior is unchanged when experimental features are enabled.Important Factoids
References