How can I configure userFIlter login.config
Teresa Fasano
t.fasano at cineca.it
Wed Jun 4 13:13:15 EDT 2014
Il 04/06/2014 18:58, David Gersic ha scritto:
>>>> On 6/4/2014 at 11:48 AM, Teresa Fasano <t.fasano at cineca.it> wrote:
>> Il 04/06/2014 18:39, David Gersic ha scritto:
>>>>>> On 6/4/2014 at 11:30 AM, Teresa Fasano <t.fasano at cineca.it> wrote:
>>>> Hi,
>>>> I need to set the userFilter in the login.config with the attribute uid
>>>> and the name of two objectClass.
>>>>
>>>> The filter in the ldapsearch is:
>>>> ldapsearch -x -H ldap://LDAP-MY-SERVER:389-D 'cn=blah,blah,blah' -w
>>>> 'xxxxxxxx'-b 'my-base-dn' -a never
>>>> "(&(uid=user-test)(|(objectClass=name-of-class1)(objectClass=name-of-class2)))"
>>>>
>>>> How can I configure the filter
>>>> "(&(uid=user-test)(|(objectClass=name-of-class1)(objectClass=name-of-class2)))"?
>>>>
>>>> I tried with
>>>> userFilter="&(uid)(|(objectClass=name-of-class1)(objectClass=name-of-class2)))
>>>> but I obtained:
>>>>
>>>> 18:22:04.616 - INFO
>>>> [com.cineca.shibboleth.idp.provider.MultiLoginServlet:328] - The user
>>>> identita.digitale cannot be authenticated
>>>> javax.security.auth.login.LoginException:
>>>> javax.naming.directory.InvalidSearchFilterException: Missing 'equals';
>>>>
>>>> Do you know how can I configure it?
>>>>
>>>> thanks,
>>>> Teresa
>>> The example configuration includes:
>>>
>>> userFilter="uid={0}";
>>>
>>> Your test configuration seems to be missing the "={0}" part of this, which
>> could be what it's complaining about when it says: "Missing 'equals';"
>>>
>>>
>>>
>>> --
>>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>> OK, I have:
>> edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient
>> host="MY-LDAP-SERVER"
>> port="389"
>> serviceUser="cn=bla,bla,bla"
>> serviceCredential="*****"
>> base="MY-BASE-DN"
>> ssl="false"
>> tls="true"
>> subtreeSearch="true"
>> userField="&(uid={0})(|(objectClass=name-of-class1)(objectClass=name-of-class2))"
>> derefAliases="never";
>>
>> Now, no syntax errors but the login fails because the user is not found
>> using this information.
>> While, with the ldapsearch the output is successful.
>
> I think you need one more level of parens to make a proper search filter.
>
> userField="(&(uid={0})(|(objectClass=name-of-class1)(objectClass=name-of-class2)))"
I added the brackets as you suggest, but the login fails.
>
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
----------------------------------
L'educazione è il pane dell'anima
----------------------------------
Teresa Fasano
CINECA
System and Technologies Department
Middleware and Infrastructure Group
Via Magnanelli, 6/3
Casalecchio di Reno (Bologna) ITALY
web: http://www.cineca.it
e-mail: t.fasano at cineca.it
phone: +39 06 444 86 517
More information about the users
mailing list