LDAP authentication, binding issue

IAM David Bantz dabantz at alaska.edu
Fri Oct 16 21:19:58 EDT 2015


I've always used a full DN for the principal in DataConnectors.


On Fri, Oct 16, 2015 at 4:01 PM, Val P <spamwall at redsigil.com> wrote:

> I'm trying to connect IDP3 to Windows LDAP (Server 2012 R2). I get an
> error when I try to authenticate a user:
>
> DSID-0C09072b, In order to perform an operation, a succesful bind must be
> completed.
>
> I ran a network trace, and I see the following behavior:
>
> <service start>
> ...
> 4   0.028683 aa.aa.aa.aa -> bb.bb.bb.bb LDAP 112 bindRequest(1) "
> sync at my.domain.com" simple
> 5   0.030837 bb.bb.bb.bb -> aa.aa.aa.aa LDAP 88 bindResponse(1) success
> ...
> 7   0.040868 aa.aa.aa.aa -> bb.bb.bb.bb LDAP 102 unbindRequest(2)
> ...
>
> <try to authenticate>
> ...
>  27  80.735579 aa.aa.aa.a -> bb.bb.bb.bb LDAP 165 searchRequest(1)
> "CN=Users,DC=my,DC=domain,DC=com" singleLevel
>  28  80.736019 bb.bb.bb.bb -> aa.aa.aa.a LDAP 240 searchResDone(1)
> operationsError (000004DC: LdapErr: DSID-0C09072B, comment: In order to
> perform this operation a successful bind must be completed on the
> connection., data 0, v2580)
> ...
>
> What I don't understand is why it's not doing a bind. It did a bind during
> the service start, and it was succesful, but it then unbound. During
> authentication, it tries to do a search, but there is no new bind.
>
> Here's snippets from my ldap.properties (aa.aa.aa.aa and bb.bb.bb.bb are
> IP addresses)
>
> id.authn.LDAP.authenticator                     = adAuthenticator
>
> idp.authn.LDAP.ldapURL                          = ldap://bb.bb.bb.bb:3268
> idp.authn.LDAP.useStartTLS                    = false
> idp.authn.LDAP.useSSL                            = false
> ...
> idp.authn.LDAP.baseDN                           =
> CN=Users,DC=my,DC=domain,DC=com
> ...
> idp.authn.LDAP.bindDN                            = sync at my.domain.com
> idp.authn.LDAP.bindDNCredential            = <secret>
> ...
> idp.authn.LDAP.dnFormat                         = %s at my.domain.com
>
>
> and attribute-resolver:
>
>   <resolver:DataConnector id="myLDAP" xsi:type="LDAPDirectory"
> xmlns="urn:mace:shibboleth:2.0:resolver:dc"
>         ldapURL="ldap://bb.bb.bb.bb:3268"
> baseDN="cn=Users,dc=my,dc=domain,dc=com" principal="sync at my.domain.com"
>         principalCredential="<secret>">
>         <FilterTemplate>
>             <![CDATA[
>                 (samAccountName=$requestContext.principalName)
>             ]]>
>         </FilterTemplate>
>   </resolver:DataConnector>
>
>
> Any suggestions I could try?
>
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151016/a242ccf8/attachment.html>


More information about the users mailing list