Shib IDP's LDAPS attribute resolution and SSLv3

Cantor, Scott cantor.2 at osu.edu
Wed Oct 15 16:55:23 EDT 2014


On 10/15/14, 4:50 PM, "Wessel, Keith" <kwessel at illinois.edu> wrote:

> Thanks, Scott and Paul. That page talks extensively about adding GSSAPI
>authentication to JAAS, but would
> I just pass the same options to the library inside my LDAP data
>connector definition?

I have absolutely no idea. Using SASL with LDAP is very complex. I doubt
you could do it right now, you'd need to be able to configure lots of
underlying behavior in the LDAP client.

Using Kerberos to authenticate to AD is totally unrelated. That has
nothing to do with securing LDAP binds, which is what you're asking about.

-- Scott



More information about the users mailing list