OpenLDAP Password Policy account state handling.

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Dec 14 12:45:45 EST 2016


Thanks Scott,

>> You could just do all this with the MFA flow and avoid all this complexity.

This is, in fact, part of an MFA flow and I have a nextFlowStrategy script in place to try and deal with the account state error; the strategy is not being activated due to lack of success from authn/Password rule.

Our entry factor is authn/Password.  This issue only occurs for the user whose LDAP entry is in password reset mode, via the PPolicy.  All other users continue to complete the MFA flow, successfully.  I am with you, that there is some event happening within authn/Password flow that is returning action back to the login view.  I just can’t seem to locate it in the logs.  I am pretty sure it has to be there, but I am going a little cross-eyed looking at the log entries right now.

Thanks again.

Josh

> On Dec 14, 2016, at 10:18 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> On 12/14/16, 10:48 AM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:
> 
>> Thanks for your help, as the pwdMustChange/pwdReset ppolicy is an important option we would like to implement.
> 
> You could just do all this with the MFA flow and avoid all this complexity. Just my opinion; I definitely can't help with advanced LDAP options.
> 
> If the form is displaying, then of course it failed and there has to be event or exception that triggered the redisplay, and either of those would be logged. I don't think it's possible for this to happen silently unless something has been done to change the flow definition in some way.
> 
> -- Scott
> 
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list