adAuthenticator BAD_NAME but Login Success

Klingenstein, Nate nklingenstein at calstate.edu
Fri Jul 29 17:16:09 EDT 2016


Thanks for taking the time to chime in, Raymond.  I'm glad to know it's not just me.

I've experienced this too.  I'm a newbie but I think I can explain.

I believe after authentication, the ldaptive libraries attempt a 2nd request for attribute resolution.  I believe this 2nd request throws this InvalidNameException because your {user} does not have search capabilities with your AD server.

My attribute resolution machinery isn't connected to my authentication machinery here, but there may be a secondary search for the attributes returned as part of the authentication itself.

It doesn't seem to differ based on the {user} string that authenticates in this case.  I get the same error when I enter the username and password for the administrative user that has enough privileges to do the bind and search.

It would be plausible that authentication and gathering those attributes would have different privileges, though.  I'll chase this down with the AD logs and administrator next.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160729/b8f6bad4/attachment.html>


More information about the users mailing list