v3 Docs Q: Appropriate use of idp.authn.LDAP.returnAttributes?
Daniel Fisher
dfisher at vt.edu
Mon Jun 29 22:58:04 EDT 2015
On Mon, Jun 29, 2015 at 3:13 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> Both of those use cases are things you can do more easily with the
> attribute resolver and without writing code or scripts, but that does mean
> extra LDAP binds, so I guess there's an efficiency argument in rare cases,
> but certainly not routinely.
>
One reason to pull attributes during authentication is that it is the only
time you can read attributes as the authenticating user. For some directory
implementations it is attractive to simply exercise the user ACLs rather
than configuring a service account to read that data.
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150629/4f815652/attachment-0001.html>
More information about the users
mailing list