IdP 3.2.1 Ldap problem

Tom Zeller tzeller at dragonacea.biz
Wed Feb 3 10:26:14 EST 2016


> On Feb 3, 2016, at 9:14 AM, Negib A. Sherif <aa8288 at wayne.edu> wrote:
> 
> I am working on IdP 3.2.1 and stuck with Ldap problem. No error is showing on idp-process.log when tomcat8 starts. However,
> I am getting the following error after SP directed me to IdP and before opening login screen on IdP.
>  I have 2.x running fine and want to setup, clean, 3.2.1 in another server. Help is appreciated.
> 
> 2016-02-03 09:55:45,072 - ERROR [net.shibboleth.utilities.java.support.service.AbstractReloadableService:231] - Service 'shibboleth.AttributeResolverService': Reload for shibboleth.AttributeResolverService failed
> net.shibboleth.utilities.java.support.service.ServiceException: org.springframework.beans.factory.BeanDefinitionStoreException: Invalid bean definition with name 'myLDAP' defined in null: Could not resolve placeholder 'idp.attribute.resolver.LDAP.returnAttributes' in string value "%{idp.attribute.resolver.LDAP.returnAttributes}"; nested exception is java.lang.IllegalArgumentException: Could not resolve placeholder 'idp.attribute.resolver.LDAP.returnAttributes' in string value "%{idp.attribute.resolver.LDAP.returnAttributes}"
>         at net.shibboleth.ext.spring.service.ReloadableSpringService.doReload(ReloadableSpringService.java:334)
> Caused by: org.springframework.beans.factory.BeanDefinitionStoreException: Invalid bean definition with name 'myLDAP' defined in null: Could not resolve placeholder 'idp.attribute.resolver.LDAP.returnAttributes' in string value "%{idp.attribute.resolver.LDAP.returnAttributes}"; nested exception is java.lang.IllegalArgumentException: Could not resolve placeholder 'idp.attribute.resolver.LDAP.returnAttributes' in string value "%{idp.attribute.resolver.LDAP.returnAttributes}"
>         at org.springframework.beans.factory.config.PlaceholderConfigurerSupport.doProcessProperties(PlaceholderConfigurerSupport.java:211)
> Caused by: java.lang.IllegalArgumentException: Could not resolve placeholder 'idp.attribute.resolver.LDAP.returnAttributes' in string value "%{idp.attribute.resolver.LDAP.returnAttributes}"
>         at org.springframework.util.PropertyPlaceholderHelper.parseStringValue(PropertyPlaceholderHelper.java:174)
> 
> Here is what i have in ldap.properties and attribute-resolver xml files.
> 
> ldap.properties file:
> 
> idp.authn.LDAP.authenticator        = bindSearchAuthenticator
> idp.attribute.resolver.LDAP.ldapURL = ldap://x.y.z:389
> idp.attribute.resolver.LDAP.bindDN  = bindDN info here
> idp.authn.LDAP.useStartTLS          = false
> idp.authn.LDAP.useSSL               = false
> idp.authn.LDAP.sslConfig            = jvmTrust
> idp.attribute.resolver.LDAP.bindDNCredential  = password
> idp.attribute.resolver.LDAP.searchFilter = (uid=$requestContext.principalName)
> 
> 
> attribute-resolver.xml file:
> 
>     <resolver:AttributeDefinition id="uid" xsi:type="ad:Simple" sourceAttributeID="uid">
>         <resolver:Dependency ref="myLDAP" />
>         <resolver:AttributeEncoder xsi:type="enc:SAML1String" name="urn:mace:dir:attribute-def:uid" encodeType="false" />
>         <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="urn:oid:0.9.2342.19200300.100.1.1" friendlyName="uid" encodeType="false" />
>     </resolver:AttributeDefinition>
> 
> <resolver:DataConnector id="myLDAP" xsi:type="dc:LDAPDirectory"
>         ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"
>         principal="%{idp.attribute.resolver.LDAP.bindDN}"
>         principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}">
>         <dc:FilterTemplate>
>             <![CDATA[
>                 %{idp.attribute.resolver.LDAP.searchFilter}
>             ]]>
>         </dc:FilterTemplate>
>         <dc:ReturnAttributes>%{idp.attribute.resolver.LDAP.returnAttributes}</dc:ReturnAttributes> 
>     </resolver:DataConnector>
> 

Looks like you’re missing idp.attribute.resolver.LDAP.returnAttributes in ldap.properties.



More information about the users mailing list