v3 Docs Q: Appropriate use of idp.authn.LDAP.returnAttributes?
Chris Phillips
Chris.Phillips at canarie.ca
Mon Jun 29 14:37:51 EDT 2015
Hi,
Like many others, we are running only a few footsteps behind the Shibboleth dev team and working through recommendations for our community for v3 deployments.
One item I'm digging into is around idp.authn.LDAP.returnAttributes. I feel like it could be more clearly stated how it complements/lives with the attribute-resolver.
Some have implied (incorrectly, and then corrected) that it can replace attribute-resolver configuration(see convo in: https://issues.shibboleth.net/jira/browse/IDP-652 )
My question is:
What are the recommendations/guidance for how the community should use idp.authn.LDAP.returnAttributes?
Related questions I have are:
When specifically should I use it?
Can I leave it blank until then?
FWIW, I explored these 2 additional places to try and understand it's use:
Usual documentation spot: https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration
In the ldap.properties file for v3:
## Return attributes during authentication
## NOTE: this is not used during attribute resolution; configure that directly in the
## attribute-resolver.xml configuration via a DataConnector's <dc:ReturnAttributes> element
Idp.authn.LDAP.returnAttributes=""
Which still left me unclear what I should do with it and when I should use it.
Look forward to some feedback and answers getting woven back into the wiki site :)
Thanks!
C.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150629/d9b0afd6/attachment.html>
More information about the users
mailing list