[JIRA] Commented: (IDP-113) Create an authentication workflow action that validates a username/password against an LDAP directory
dfisher@vt.edu (JIRA)
noreply at shibboleth.net
Tue Sep 13 18:34:25 BST 2011
[ https://issues.shibboleth.net/jira/browse/IDP-113?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13564#comment-13564 ]
dfisher at vt.edu commented on IDP-113:
------------------------------------
{quote}support enumerating multiple LDAP directories and failing over connections if some are down{quote}
Is the existing functionality sufficient? It's not well documented, so I should remedy that first.
{quote}connections used to search for the user DN should have the option of being pooled{quote}
Both DN resolution and binds will be poolable in the next release.
{quote}ability to catch locked/disabled accounts and expired passwords{quote}
I'll probably need some more specific requirements here. I'm only aware of (2) implementations; AD and OpenLDAP's ppolicy. Do you want solutions for both of those or something else?
> Create an authentication workflow action that validates a username/password against an LDAP directory
> -----------------------------------------------------------------------------------------------------
>
> Key: IDP-113
> URL: https://issues.shibboleth.net/jira/browse/IDP-113
> Project: Identity Provider
> Issue Type: Task
> Components: Authentication
> Reporter: Chad La Joie
> Assignee: Chad La Joie
> Priority: Blocker
> Fix For: 3.0.0
>
> Original Estimate: 1 day
> Remaining Estimate: 1 day
>
> Create an action that validates the username/password, given via the UsernamePasswordSubcontext on the authn request context, against an LDAP directory. If the credentials properly validate then set a UsernamePrincipal as the authenticated principal of the authn request context.
> Additional notes:
> * support enumerating multiple LDAP directories and failing over connections if some are down
> * connections used to search for the user DN should have the option of being pooled
> * ability to catch locked/disabled accounts and expired passwords
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list