Attributes not being release from AD
Michael Richter
mrichter at coastal.edu
Mon Feb 15 10:17:00 EST 2016
Commas!!! That was it. I removed the commas from the returnAttributes statement and it returned the requested attributes. Thanks so much for all the help running this down. I appreciated it!
Mike
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Douglas E Engert
Sent: Saturday, February 13, 2016 9:36 AM
To: users at shibboleth.net
Subject: Re: Attributes not being release from AD
On 2/12/2016 4:53 PM, Daniel Fisher wrote:
> On Fri, Feb 12, 2016 at 4:59 PM, Michael Richter <mrichter at coastal.edu <mailto:mrichter at coastal.edu>> wrote:
>
> Daniel,____
>
> I've attached a txt file with thefull auth requests and responses and the attrib resolver request and responses. It looks like I'm searching the correct DN with the correct search filter
> (sAMAccountname=mrichgter) but it's not finding it. Thanks!
>
>
> It's worth noting that the entry resolver used by authentication and
> the attribute resolver perform different searches on different baseDns for this configuration. I don't think that is the problem, just note that one search is performed on CN=mrichter,OU=CCU, DC=coastal, DC=edu, the other is performed on OU=CCU, DC=coastal, DC=edu.
>
> Just as a sanity check, I wanted to confirm
> a) what version of the IDP are you testing?
> b) you turned off pooling for this test?
>
> Change this property:
> idp.attribute.resolver.LDAP.returnAttributes =
> sn,displayName,mail,sAMAccountName
> to this
> idp.attribute.resolver.LDAP.returnAttributes = sn displayName mail
> sAMAccountName
This sure looks like the problem. In the Ldaptive examples, they do something like
new AuthenticationRequest("dfisher", new Credential("password"), new String[] {"mail", "sn"})); where they list of attributes to return are quoted and separated by commas.
But in the data connector and ldapsearch commands I have always seen space used to separate the attributes, The data connector code may be taking sn,displayName,mail,sAMAccountName as a single attribute.
The debug output for the authenticate has returnAttributes=[cn, sn, displayName, mail, sAMAccountName], where the attributes are listed and separated by ", " for readability.
But debug output for the data connector has returnAttributes=[cn,sn,displayName,mail,sAMAccountName],
i.e. a single attributes which includes commas.
Since both of the debug lines are produced by org.ldaptive.SearchOperation:168 that would imply that the data connector is requesting only a single attribute that has imbedded commas.
>
> --Daniel Fisher
>
>
>
--
Douglas E. Engert <DEEngert at gmail.com>
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list