OpenLDAP Password Policy account state handling.

Daniel Fisher dfisher at vt.edu
Mon Dec 12 16:05:40 EST 2016


On Mon, Dec 12, 2016 at 3:34 PM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu>
wrote:

> Sure.  The following is DEBUG output from ldaptive packages.  I believe we
> are seeing a successful bind followed by a failed search operation.  The
> search operation appears to be restricted from the list of current allowed
> operations.  I believe this is due to the fact that the directory is
> enforcing a password-must-change policy that is active.  I am concluding
> that because search operations are not being restricted for accounts with
> normal account state.
>

That's what I expected. If you need that attribute for your flow, you'll
have to wire up a connection factory to read it.
See
https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-AttributeRetrieval

--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161212/c8a6c1b3/attachment.html>


More information about the users mailing list