AD/LDAP Password as a SAML Attribute
Marc Boorshtein
mboorshtein at gmail.com
Wed Mar 18 14:46:32 EDT 2015
I don't think its possible to get your password out of AD. Oracle had
similar issues with its use of LDAP to authenticate to databases since it
needs the decrypted password and they ended up having to create a second
attribute that stores the password in an additional attribute so the
database could access it.
On Wed, Mar 18, 2015 at 2:40 PM, Patrick Le <ple at jhmi.edu> wrote:
> I know this doesn’t conform to SAML Specs/security, but does anyone know
> if there is a way to enumerate a user’s AD password into a SAML attribute
> response? We’re trying to integrate SSO into VmWare View. Aside from
> Horizon Workspace, there’s no built in SAML authentication support within
> View. We have the environment behind F5 and are trying to figure out a way
> to manipulate a SAML login into providing VmWare with the user information
> it needs. Ideally we would want the password to come in through the SAML
> assertion so it’s properly signed/encrypted/etc as opposed to a separate
> post from our login page to another webpage not protected by Shibboleth.
>
>
>
> Thanks
>
>
>
> Patrick
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150318/a04e6319/attachment.html
More information about the users
mailing list