Getting role attributes from loginHandler (LDAP)
Daniel Fisher
dfisher at vt.edu
Thu Jun 20 13:18:40 EDT 2013
On Thu, Jun 20, 2013 at 12:06 PM, Byte Flinger <byteflinger at gmail.com>wrote:
> Hi Christopher
>
> Thanks for the answer. As mentioned, I did indeed manage to get the wanted
> information using an LDAP DataConnector however given that the role seems
> to be already returned by the login module, fast or not, it's still a waste
> to have to make yet another connection for information that's already been
> retrieved.
> Trying to get the info out of the principal is exactly what I have been
> trying to do (among other ways) however so far I have had no luck.
>
> If this is not possible, what is the use of the role parameters in the
> Ldaploginmodule anyway since it works to login without it (The module
> simply won't "commit" any roles, whatever that means).
>
It's a general purpose JAAS module, the Shib IDP simply doesn't leverage
those capabilities. (for reasons Scott enumerated...)
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130620/13e17e4a/attachment.html
More information about the users
mailing list