authenticator behavior with AD security context errors

David Bantz dabantz at alaska.edu
Mon Mar 10 15:41:03 EDT 2014


How does the IdP’s authentication handler, configured to query AD, react to ‘security context errors’ from AD that indicate the submitted password did match that in the target record but the account is marked as “not permitted to login” or “expired” (and other possible conditions)?  [The use case is a service available by business rules to prior students and employees even if they are not eligible for other domain services.  This service currently relies on a mix of ad hoc and CAS for authN, but I am trying to be ready for eventual Shibb integration as per stated direction.]

David Bantz
U Alaska

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140310/1a633593/attachment.bin 


More information about the users mailing list