authenticator behavior with AD security context errors
David Bantz
dabantz at alaska.edu
Mon Mar 10 15:41:03 EDT 2014
How does the IdP’s authentication handler, configured to query AD, react to ‘security context errors’ from AD that indicate the submitted password did match that in the target record but the account is marked as “not permitted to login” or “expired” (and other possible conditions)? [The use case is a service available by business rules to prior students and employees even if they are not eligible for other domain services. This service currently relies on a mix of ad hoc and CAS for authN, but I am trying to be ready for eventual Shibb integration as per stated direction.]
David Bantz
U Alaska
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140310/1a633593/attachment.bin
More information about the users
mailing list