LDAP Authentication and LDAP Attributes

Cantor, Scott cantor.2 at osu.edu
Mon Oct 6 10:28:16 EDT 2014


On 10/6/14, 10:19 AM, "Rod Widdowson" <rdw at steadingsoftware.com> wrote:

>I hear what you are saying, but it strikes me as somewhat strange to have
>the properties which 95% of our customer will want to change not available
>in the central place.  Surely you could say the same for specific methods
>of
>persistent ID (where we have specific configuration for both computed and
>stored subtypes in idp.properties - rightly so, I would say).

To be clear, I'm also against the attribute resolver properties being in
there.

The difference to me is between configuring the IdP itself, and the
settings involved with site-specific integration choices.

>If that would work, I'm fine with it.  But do we believe that it will
>work?
>Can we have multiple property placeholder files?  If so I'd vote for doing
>that, even if it becomes cumbersome.

I forgot that we internalized all that, but I can think of one obvious way
that actually we should do anyway, add a property to idp.properties to
point to additional property files.

-- Scott



More information about the dev mailing list