Mapping kerberos principal to ldap connector

Morris, Andi amorris at cardiffmet.ac.uk
Tue Nov 25 10:14:40 EST 2014


Great! Thanks very much both.

Cheers,
Andi

From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of John Hascall
Sent: 25 November 2014 13:59
To: Shib Users
Subject: Re: Mapping kerberos principal to ldap connector

No, I think he means there needs to be one less.
This:

(sAMAccountName=${krb_principalname.get(0)}
(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
instead of this:

(|(sAMAccountName=${krb_principalname.get(0)})
(!(userAccountControl:1.2.840.113556.1.4.803:=2))))

John

On Tue, Nov 25, 2014 at 7:32 AM, Morris, Andi <amorris at cardiffmet.ac.uk<mailto:amorris at cardiffmet.ac.uk>> wrote:
Interesting. It seems to be working as it is. Where would you put the extra | ?




--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141125/2cd13d07/attachment.html 


More information about the users mailing list