Passwords are handled differently in the MCB than in the default IdP code

Cantor, Scott cantor.2 at osu.edu
Thu Jul 16 15:29:30 EDT 2015


On 7/16/15, 3:24 PM, "users on behalf of Mark McCoy" <users-bounces at shibboleth.net on behalf of Mark.McCoy at utsa.edu> wrote:

>No worries.  I wish we could upgrade to IdP3 this summer but it has to wait until at least the Spring semester. We can update our password portal to make sure that there are no whitespace characters at the end of the passphrases.

Yes, I just thought it deserved comment / consensus, it's kind of a big deal. OTOH I guess there's the standard argument about saving users from themselves and it will save as many users as it helps.

If people really thought it was the right thing to do, I'll overrule myself and make it an option, but it didn't seem like a good idea when I wrote that code. Of course, one can always do it in Javascript too.

-- Scott



More information about the users mailing list