authentication failure reasons in IdP logs
David Bantz
dabantz at alaska.edu
Fri Jun 20 19:53:32 EDT 2014
Is it possible that in attempting to authenticate against a directory, with
multiple servers specified in the url:
ldapUrl="ldap://fbk-adua02.ua.ad.alaska.edu:3268 ldap://fbk-adua03.ua.ad.alaska.edu:3268”
that the first step - search of the directory with the user-provided identifier - returns a dn from one server,
while the second step - to bind with that dn and the user-provided password - hits the other server, and
that the second server fails to find that dn, leading to the “invalid dn” message?
Of course the two servers are supposed to be in sync, but is it possible that the “invalid dn” I’m seeing
during a few authentications reflects an out-of-sync condition plus hitting two different servers in the “two step bind?”
Grasping at straws I know...
David Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140620/1f0b30cb/attachment.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140620/1f0b30cb/attachment.bin
More information about the users
mailing list