IdP 3 - Password Expired

James McCartin jmccartin at loyola.edu
Thu Jun 30 14:05:57 EDT 2016


Any idea on how to do this with Active Directory? The documentation mentions Active Directory, but I guess it doesn’t apply.  I can see the data value in error change based on whether the account is disabled, expired, etc.:

LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 533, v2580

I’m hoping there is a way to change the error message based on this.

From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Daniel Fisher
Sent: Thursday, June 30, 2016 1:14 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: IdP 3 - Password Expired

On Thu, Jun 30, 2016 at 12:14 PM, James McCartin <jmccartin at loyola.edu<mailto:jmccartin at loyola.edu>> wrote:
I also see the following if I turn on trace for net.shibboleth.idp:

2016-06-30 12:08:39,410 - TRACE [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:137] - Profile Action ValidateUsernamePasswordAgainstLDAP: Authentication response [org.ldaptive.auth.AuthenticationResponse at 1451698118::authenticationResultCode=AUTHENTICATION_HANDLER_FAILURE, ldapEntry=[dn=CN=jmccartin,OU=Loyola,DC=adtest,DC=loyola,DC=edu[]], accountState=null, result=false, resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 773, v2580 ], controls=null]

That appears to be a response from Active Directory, but you've modified your configuration to support an OpenLDAP ppolicy implementation.

--Daniel Fisher

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160630/a741321e/attachment-0001.html>


More information about the users mailing list