IDP LDAP Query only works some of the time?

Cantor, Scott cantor.2 at osu.edu
Mon Apr 1 16:58:19 EDT 2013


On 4/1/13 12:30 PM, "Kanuch, Andrew" <Andy.Kanuch at sdstate.edu> wrote:

>1. Is there any way I can output *all* the values stored in my attribute
>by the recursive LDAP search? (Called Œmemberof¹ and ŒDistinguishedNamed¹
>in the data connector below.) It would help me troubleshoot the issue.

I don't think it logs values, but whatever logging is available is in
vt-ldap, just turn it up.

> I have tried
> Œpassing it on¹ to a test SP in attempt to check the value there,  but I
>believe that is not working because of the multiple values stored in the
>attribute.

I don't understand what that means. The SP gets whatever you send.

>2.      
>Will Trace or Debug logging levels capture what the Attribute Resolver
>Script is doing?  Perhaps I could turn them on and wait for the problem
>to happen again?

No. If you want to log something in your script you have to do it, there's
no way for anything else to.

>3.      
>I do not know very much about Service Providers yet. Can SPs place a time
>restriction how on how long it¹s authentication request is valid for? If
>we end up having to increase the TimeLimit for the query I should make
>sure I know about any hard upper limit.

The SP is irrelevant, the client is talking to your IdP, that's it. If it
times out, it times out.

-- Scott




More information about the users mailing list