FreeIPA - Password Expiration

Cantor, Scott cantor.2 at osu.edu
Fri Jul 22 10:41:23 EDT 2016


> Do you mean when there is a shib_idp_session cookie which is valid, and
> user tries to login again ?

I don't know what you're asking. I'm saying attribute resolution is a totally separate step and populates a different context. Attributes during authentication is a special feature of the LDAP option and is what you're using.

> that case right ? This is the reason for my question about the recommended
> way to deny without setting the shib_idp_session cookie. Right now, as part
> of my non-proceed event, I'm explicitly removing the cookie like this ;

Do NOT do that. You have no business doing it, and you cannot depend on anything like that.

-- Scott




More information about the users mailing list