LDAP password authn flow interception
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Fri Jul 31 10:32:15 EDT 2015
Thanks much. I am sure there are lots of great bits there that will help shave some time off my development task.
Josh
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Marvin Addison
Sent: Thursday, July 30, 2015 1:10 PM
To: Shib Users
Subject: Re: LDAP password authn flow interception
I look forward to seeing what you have.
Following is a zip archive of the source tree:
https://docs.google.com/a/vt.edu/uc?id=0Bz3YRk8WRdWrY05LY3Q4bEN4dU0&export=download
There are a number of flows in this project. The one you should study is flows/intercept/vt-account-mgmt. We don't use security questions per se, but rather out-of-band methods to reset or change a password which we call "recovery options." Users must define these initially and maintain them yearly. Note that we drive the flow using the ResolveAttributes action, which is decoupled from the authentication subsystem, but ultimately contains LDAP directory data per our attribute-resolver.xml config.
I'm happy to field further general questions about the source on the list. Contact me privately if it's down in the weeds.
M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150731/7b5ed035/attachment.html>
More information about the users
mailing list