authenticator behavior with AD security context errors

Cantor, Scott cantor.2 at osu.edu
Mon Mar 10 15:54:43 EDT 2014


On 3/10/14, 3:41 PM, "David Bantz" <dabantz at alaska.edu> wrote:

>How does the IdP¹s authentication handler, configured to query AD, react
>to Œsecurity context errors¹ from AD that indicate the submitted password
>did match that in the target record but the account is marked as ³not
>permitted to login² or ³expired² (and other possible conditions)?

It doesn't. You'd need a custom login handler for that (mine uses message
string matching to report that).

-- Scott




More information about the users mailing list