FreeIPA - Password Expiration
Prashant Bapat
prashant at apigee.com
Fri Jun 3 08:33:38 EDT 2016
Hi Daniel,
After some effort, I was able to get the ldaptive snapshot you provided
working. Relevant sections of authn/ldap-authn-config.xml are as below.
<!-- Bind Search Configuration -->
<bean name="bindSearchAuthenticator"
class="org.ldaptive.auth.Authenticator"
p:authenticationResponseHandlers-ref="authenticationResponseHandler"
p:resolveEntryOnFailure="%{idp.authn.LDAP.resolveEntryOnFailure:false}">
Towards the end of this file.
<!-- add the FreeIPA response handler -->
<bean id="authenticationResponseHandler"
class="org.ldaptive.auth.ext.FreeIPAAuthenticationResponseHandler" />
Now I'm getting the 20 second delay message when I login even for the
passwords that are not due to expire.
Your password will be expiring soon!
To create a new password now, go to *#
<https://portal.apigee.io/idp/profile/SAML2/Redirect/SSO?execution=e1s2#>*.
Your login will proceed in 20 seconds or you may click *here
<https://portal.apigee.io/idp/profile/SAML2/Redirect/SSO?execution=e1s2&_eventId_proceed=1>*
to continue.
Any settings that I have missed ?
Thanks.
--Prashant
On 3 June 2016 at 09:05, Prashant Bapat <prashant at apigee.com> wrote:
> Hi Scott,
>
> Yes. I understand. What I meant by the next version is the intercept flow
> that you had earlier posted about.
>
> Thanks.
> --Prashant
>
> On 2 June 2016 at 19:03, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> > Tried it but got into runtime exceptions. I guess I will have to wait
>> for the
>> > next version.
>>
>> What Daniel's talking about doesn't rely on the next version.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160603/b736e51d/attachment.html>
More information about the users
mailing list