FreeIPA - Password Expiration

Prashant Bapat prashant at apigee.com
Fri Jun 3 08:33:38 EDT 2016


Hi Daniel,

After some effort, I was able to get the ldaptive snapshot you provided
working. Relevant sections of authn/ldap-authn-config.xml are as below.

<!-- Bind Search Configuration -->
    <bean name="bindSearchAuthenticator"
class="org.ldaptive.auth.Authenticator"
p:authenticationResponseHandlers-ref="authenticationResponseHandler"
p:resolveEntryOnFailure="%{idp.authn.LDAP.resolveEntryOnFailure:false}">

Towards the end of this file.
<!-- add the FreeIPA response handler -->
<bean id="authenticationResponseHandler"
class="org.ldaptive.auth.ext.FreeIPAAuthenticationResponseHandler" />

Now I'm getting the 20 second delay message when I login even for the
passwords that are not due to expire.

Your password will be expiring soon!

To create a new password now, go to *#
<https://portal.apigee.io/idp/profile/SAML2/Redirect/SSO?execution=e1s2#>*.

Your login will proceed in 20 seconds or you may click *here
<https://portal.apigee.io/idp/profile/SAML2/Redirect/SSO?execution=e1s2&_eventId_proceed=1>*
to continue.


Any settings that I have missed ?

Thanks.
--Prashant

On 3 June 2016 at 09:05, Prashant Bapat <prashant at apigee.com> wrote:

> Hi Scott,
>
> Yes. I understand. What I meant by the next version is the intercept flow
> that you had earlier posted about.
>
> Thanks.
> --Prashant
>
> On 2 June 2016 at 19:03, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> > Tried it but got into runtime exceptions. I guess I will have to wait
>> for the
>> > next version.
>>
>> What Daniel's talking about doesn't rely on the next version.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160603/b736e51d/attachment.html>


More information about the users mailing list