OpenLDAP Password Policy account state handling.

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Dec 14 10:48:56 EST 2016


Thanks Daniel,

I have continued to make small steps towards finding the root of the issue, but not there yet…  Per your last reply, I did implement a bindSearchEntryResolver with broad privy for fetching attributes, so the LDAP Error Code-50 is no longer occurring.  I can see, though, that the auth/Password flow is not reaching a ‘proceed’ event after the authentication response happens.  It just returns to the login.vm view with no messages.  I still cannot see anything in the logs to indicate what is causing this.

I do have the loggers …webflow, …idp, and …ldaptive tuned up to TRACE or DEBUG.  So there is a lot there.  I am hoping that I am just overlooking something that is there to find.

Thanks for your help, as the pwdMustChange/pwdReset ppolicy is an important option we would like to implement.

Josh

On Dec 14, 2016, at 8:27 AM, Daniel Fisher <dfisher at vt.edu<mailto:dfisher at vt.edu>> wrote:

On Mon, Dec 12, 2016 at 4:33 PM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu<mailto:Josh.O'Dowd at mso.umt.edu>> wrote:
So back to my original issue, the IdP is not handling the CHANGE_AFTER_RESET account state.


I haven't forgotten about this. As soon as I get some free time I will investigate.

--Daniel Fisher

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>



More information about the users mailing list