Shib IDP's LDAPS attribute resolution and SSLv3

Wessel, Keith kwessel at illinois.edu
Wed Oct 15 16:50:57 EDT 2014


Thanks, Scott and Paul. That page talks extensively about adding GSSAPI authentication to JAAS, but would I just pass the same options to the library inside my LDAP data connector definition?

Keith


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, October 15, 2014 3:44 PM
To: Shib Users
Subject: Re: Shib IDP's LDAPS attribute resolution and SSLv3

On 10/15/14, 4:41 PM, "Wessel, Keith" <kwessel at illinois.edu> wrote:
>
>If anyone knows a way to change the sasl mechanism used by the LDAP
>library to gssapi, our AD admins would prefer I do what I said earlier:
>Kerberos authentication over the cleartext channel. Personally, this
>feels like more that could break moving forward than just using startTLS.

https://code.google.com/p/vt-middleware/wiki/vtldapGSSAPI

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list