authentication failure reasons in IdP logs
David Bantz
dabantz at alaska.edu
Thu Jun 19 17:17:09 EDT 2014
I appreciate the references to details Kevin, but as my post indicated, I’m OK with the
‘normal’ failure code 49 from AD as indicating an invalid submitted password. I’d like
to understand the failures that are NOT that, with mysterious (to me) indicators in the IdP logs of
"Inappropriate authentication" and
"Cannot authenticate dn”
Do any Shib users know what event, error, or condition of a user’s AD record
triggers those reported errors?
Thanks,
David Bantz
On Thu, 19 Jun 2014, at 11:44 , Kevin Foote <kpfoote at uoregon.edu> wrote:
>
> On Jun 19, 2014, at 12:26 PM, David Bantz <dabantz at alaska.edu> wrote:
>>
>> "Invalid Credentials," "Exceeded password retry limit," and "password expired" seem clear enough and reflect user failure to provide current valid password,
>> but what about the other errors - "Inappropriate authentication" and "Cannot authenticate dn" - what states or events do they reflect in AD?
>
> David,
>
> AD sends back “sub error” codes to the calling client..
>
> You can field these in various places here is one approach I've used in the past:
>
> Look at the Handling Login Errors section of this page [1] and its derivative page [2]
>
>
> [1] <https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthUserPassLoginPage>
> [2] <https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthUserPassLoginPageMSADerror>
>
>
> --------
> thanks
> kevin.foote
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140619/b2ca4416/attachment-0001.bin
More information about the users
mailing list