v3 Docs Q: Appropriate use of idp.authn.LDAP.returnAttributes?

Chris Phillips Chris.Phillips at canarie.ca
Mon Jun 29 14:37:51 EDT 2015


Hi,

Like many others, we are running only a few footsteps behind the Shibboleth dev team and working through recommendations for our community for v3 deployments.

One item I'm digging into is around idp.authn.LDAP.returnAttributes. I feel like it could be more clearly stated how it complements/lives with the attribute-resolver.
Some have implied (incorrectly, and then corrected) that it can replace attribute-resolver configuration(see convo in: https://issues.shibboleth.net/jira/browse/IDP-652 )

My question is:


What are the recommendations/guidance for how the community should use idp.authn.LDAP.returnAttributes?


Related questions I have are:

When specifically should I use it?

Can I leave it blank until then?



FWIW, I explored these 2 additional places to try and understand it's use:

Usual documentation spot: https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration


In the ldap.properties file for v3:

## Return attributes during authentication

## NOTE: this is not used during attribute resolution; configure that directly in the

## attribute-resolver.xml configuration via a DataConnector's <dc:ReturnAttributes> element

Idp.authn.LDAP.returnAttributes=""

Which still left me unclear what I should do with it and when I should use it.


Look forward to some feedback and answers getting woven back into the wiki site :)


Thanks!


C.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150629/d9b0afd6/attachment.html>


More information about the users mailing list