Question on Login Handlers

Kevin P. Foote kpfoote at iup.edu
Thu Aug 22 16:47:02 EDT 2013



On Thu, 22 Aug 2013, David Langenberg wrote:

> Yes, but you could still solve that by making disabled users in LDAP1
> invisible to the Attribute Resolver.  They'd then be able to authN, but no
> attributes for them would be returned.  Hopefully your downstream apps are
> not performing AuthN == AuthZ.

Ahhh, nice touch! But...  "require valid-user" is so very prevalant ;-)

------
thanks
  kevin.foote


More information about the users mailing list