<div dir="ltr"><div class="" style="font-size:medium"><div class=""><div class=""><div class="" tabindex="-1"><div class="" style="width:1413px"><div class=""><div id=":2iv"><div class=""><div class=""><div id=":23d" class="" style="font-size:12.8px"><div id=":202" class=""><div dir="ltr">Hi Experts,<div><br></div><div>I am continuously getting this exception while logging in.</div><div>I am able to connect offline to LDAP, but not through the IDP..</div><div>Please help me in identifying the issue..</div><div><br></div><div><div>2016-05-30 15:38:30,662 - WARN [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:175] - Profile Action ValidateUsernamePasswordAgainstLDAP: Login by muthu produced exception</div><div>org.ldaptive.LdapException: javax.naming.NamingException: [LDAP: error code 1 - 000004DC: LdapErr: DSID-0C0906DD, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v1772]; remaining name 'DC=idp,DC=yourdomain,DC=com'</div><div> at org.ldaptive.provider.ProviderUtils.throwOperationException(ProviderUtils.java:77)</div><div>Caused by: javax.naming.NamingException: [LDAP: error code 1 - 000004DC: LdapErr: DSID-0C0906DD, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v1772]</div><div> at com.sun.jndi.ldap.LdapCtx.mapErrorCode(LdapCtx.java:3127)</div><div><br></div><div><br></div><div><b>My ldap.properties file is like as follows...</b></div><div><br></div><div><div># LDAP authentication configuration, see authn/ldap-authn-config.xml</div><div># Note, this doesn't apply to the use of JAAS</div><div><br></div><div>## Authenticator strategy, either anonSearchAuthenticator, bindSearchAuthenticator, directAuthenticator, adAuthenticator</div><div>#idp.authn.LDAP.authenticator = anonSearchAuthenticator</div><div><br></div><div>## Connection properties ##</div><div>idp.authn.LDAP.ldapURL=ldap://<a href="http://idp.yourdomain.com:389/" target="_blank">idp.yourdomain.com:389</a></div><div>idp.authn.LDAP.useStartTLS=false</div><div>idp.authn.LDAP.useSSL=false</div><div>idp.authn.LDAP.connectTimeout=3000</div><div><br></div><div>## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust</div><div>#idp.authn.LDAP.sslConfig = certificateTrust</div><div>## If using certificateTrust above, set to the trusted certificate's path</div><div>idp.authn.LDAP.trustCertificates = %{idp.home}/credentials/ldap-server.crt</div><div>## If using keyStoreTrust above, set to the truststore path</div><div>idp.authn.LDAP.trustStore = %{idp.home}/credentials/ldap-server.truststore</div><div><br></div><div>## Return attributes during authentication</div><div>## NOTE: there is a separate property used for attribute resolution</div><div>idp.authn.LDAP.returnAttributes = passwordExpirationTime,loginGraceRemaining</div><div><br></div><div>## DN resolution properties ##</div><div><br></div><div># Search DN resolution, used by anonSearchAuthenticator, bindSearchAuthenticator</div><div># for AD: CN=Users,DC=example,DC=org</div><div>idp.authn.LDAP.baseDN=DC=idp,DC=yourdomain,DC=com</div><div>idp.authn.LDAP.subtreeSearch=true</div><div>idp.authn.LDAP.userFilter=(cn={user})</div><div># bind search configuration</div><div># for AD: idp.authn.LDAP.bindDN=<a href="mailto:adminuser@domain.com" target="_blank">adminuser@domain.com</a></div><div>idp.authn.LDAP.bindDN=<a href="mailto:Administrator@idp.yourdomain.com" target="_blank">Administrator@idp.yourdomain.com</a></div><div>idp.authn.LDAP.bindDNCredential=password</div><div><br></div><div># Format DN resolution, used by directAuthenticator, adAuthenticator</div><div># for AD use idp.authn.LDAP.dnFormat=%<a href="mailto:s@domain.com" target="_blank">s@domain.com</a></div><div>idp.authn.LDAP.dnFormat=CN=%<a href="mailto:s@idp.yourdomain.com" target="_blank">s@idp.yourdomain.com</a>,CN=shib-users,DC=idp,DC=yourdomain,DC=com</div><div><br></div><div># LDAP attribute configuration, see attribute-resolver.xml</div><div># Note, this likely won't apply to the use of legacy V2 resolver configurations</div><div>idp.attribute.resolver.LDAP.ldapURL = %{idp.authn.LDAP.ldapURL}</div><div>idp.attribute.resolver.LDAP.baseDN = %{idp.authn.LDAP.baseDN:undefined}</div><div>idp.attribute.resolver.LDAP.bindDN = %{idp.authn.LDAP.bindDN:undefined}</div><div>idp.attribute.resolver.LDAP.bindDNCredential = %{idp.authn.LDAP.bindDNCredential:undefined}</div><div>idp.attribute.resolver.LDAP.useStartTLS = %{idp.authn.LDAP.useStartTLS:true}</div><div>idp.attribute.resolver.LDAP.trustCertificates = %{idp.authn.LDAP.trustCertificates:undefined}</div><div>idp.attribute.resolver.LDAP.searchFilter = (uid=$resolutionContext.principal)</div><div>idp.attribute.resolver.LDAP.returnAttributes = cn,homephone,mail</div></div><div><br></div>Thanks,</div><div>Muthu</div></div></div></div></div></div></div></div></div></div></div></div></div><div><br></div><br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div style="font-size:12.8px"><span style="font-size:12.8px"></span></div></div></div></div></div></div></div></div></div></div>
<div><br></div></div>
<HR>The information transmitted, including any attachments, is intended only for the person or entity to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited, and all liability arising therefrom is disclaimed. If you received this in error, please contact the sender and delete the material from any computer. PricewaterhouseCoopers LLP is a Delaware limited liability partnership. This communication may come from PricewaterhouseCoopers LLP or one of its subsidiaries.<BR>