authn eDirectory LDAP and grace logins

Daniel Fisher dfisher at vt.edu
Tue Jun 14 16:58:13 EDT 2016


On Tue, Jun 14, 2016 at 4:38 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> So the attributes there come back even if the bind fails?
>

Not by default, but you can set idp.authn.LDAP.resolveEntryOnFailure=true.
That will attempt to get the attributes on the same connection that the
bind failed on.
If ACLs prevent that from working, a custom entry resolver can be wired up.

--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160614/5f8f6f97/attachment.html>


More information about the users mailing list