IdP 3 - Password Expired
James McCartin
jmccartin at loyola.edu
Thu Jun 30 12:14:26 EDT 2016
I also see the following if I turn on trace for net.shibboleth.idp:
2016-06-30 12:08:39,410 - TRACE [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:137] - Profile Action ValidateUsernamePasswordAgainstLDAP: Authentication response [org.ldaptive.auth.AuthenticationResponse at 1451698118::authenticationResultCode=AUTHENTICATION_HANDLER_FAILURE, ldapEntry=[dn=CN=jmccartin,OU=Loyola,DC=adtest,DC=loyola,DC=edu[]], accountState=null, result=false, resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 773, v2580 ], controls=null]
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Daniel Fisher
Sent: Thursday, June 30, 2016 11:16 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: IdP 3 - Password Expired
On Thu, Jun 30, 2016 at 10:53 AM, James McCartin <jmccartin at loyola.edu<mailto:jmccartin at loyola.edu>> wrote:
Is there something I’m missing?
Looks correct at first glance. Did you modify the ClassifiedMessageMap? Put the org.ldaptive package in DEBUG and confirm you are getting the ppolicy response control back from your directory.
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160630/7c9863fa/attachment.html>
More information about the users
mailing list