OpenLDAP Password Policy account state handling.
Daniel Fisher
dfisher at vt.edu
Mon Dec 12 16:05:40 EST 2016
On Mon, Dec 12, 2016 at 3:34 PM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu>
wrote:
> Sure. The following is DEBUG output from ldaptive packages. I believe we
> are seeing a successful bind followed by a failed search operation. The
> search operation appears to be restricted from the list of current allowed
> operations. I believe this is due to the fact that the directory is
> enforcing a password-must-change policy that is active. I am concluding
> that because search operations are not being restricted for accounts with
> normal account state.
>
That's what I expected. If you need that attribute for your flow, you'll
have to wire up a connection factory to read it.
See
https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-AttributeRetrieval
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161212/c8a6c1b3/attachment.html>
More information about the users
mailing list