Password login flow & Kerberos

Cantor, Scott cantor.2 at osu.edu
Wed Jul 20 11:55:13 EDT 2016


> I would say stop there, and, instead, separate authentication from
> attributes. Configure an LDAP DataConnector and appropriate
> AttributeDefinitions in attribute-resolver.xml to get the attributes
> you want (and of course filter them appropriately in
> attribute-filter.xml). In other words, I don't think it's a best
> practice to rely on authentication for attributes.

Definitely not, it's very limiting.

-- Scott



More information about the users mailing list