Password expiring warning with AD

joller lee joller.lee at gmail.com
Tue Feb 16 04:41:10 EST 2016


I have one more related requirement: adding password-changing UI to the
expiring-password sub-flow.

Without customization on the flow, one has to click the password-changing
link on the expiring warning page to go to the password-changing page,
perhaps on another server.
In the password-changing page the original username/password has to be
entered again (unless an SP is installed for this page) and then the new
password be entered.
If the original URL for the "proceed" state cannot be preserved for use
here, the user has to access the original service provider to login again.
For some reason, session is not enabled for my deploy, which means the
worst case takes 3 times of typing password.

Assuming the password changing is easy enough to be implemented in the IdP
service, the ideal case is to allow the user to enter the new password
directly in the expiring-password view and proceed to, being authenticated,
access the original service after successfully changing password.
This may need some sort of flow customization, but the interceptor is
defined in the system folder.

Any suggestion?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160216/247a9644/attachment-0001.html>


More information about the users mailing list