IdP 3.2.1 Ldap problem

Daniel Fisher dfisher at vt.edu
Wed Feb 3 14:12:07 EST 2016


On Wed, Feb 3, 2016 at 12:44 PM, Negib A. Sherif <aa8288 at wayne.edu> wrote:

> Indeed I was missing idp.attribute.resolver.LDAP.returnAttributes. Now, I
> do see  IdP login page and get the following error when trying to login.
> the error is about baseDN. Ldap is in remote site and don't have access to
> it. baseDN never worked even in my 2.x IdP.  In my IdP 2.x, I have local
> OpenLdap
> and remote Ldap. baseDN for my local OpenLdap works fine. I don't want to
> disable baseDN because I needed for my local OpenLdap. Can some one help?
> Can wild card * be assigned for the value of baseDN in IdP 3.2.1?
>

Can you elaborate on how you expect DN resolution to occur on the remote
LDAP? Typically, if you're not searching on a branch it's because you can
derive the DN entirely from the username. Is that the use case you have?

--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160203/996baa5b/attachment.html>


More information about the users mailing list