Box.com and Shibboleth
Cantor, Scott
cantor.2 at osu.edu
Thu Mar 3 14:26:57 EST 2016
> lot more. If that line was blank, from what I've read, I would not have
> run into this problem for the last 3 weeks trying to get SSO working
> with Box. Instead, it would have passed any attribute it was supposed to
> look up. Correct?
I doubt it's that simple in terms of how this is configured, it might even just break.
> So from a out of the box experience that may have been more
> preferential. But from a security stand point there may be really good
> reasons that it should contain a fields list. Those fields are pulled
> when the user authenticates
No, they're not.
> so the bindDN would not be needed right?
Yes, it is.
> So if I have the bindDN configured but the returnAttributes is blank in
> ldap.properties everything works.
I don't think so.
> If I have no bindDN configured but I'm
> using anonSearchAuthenticator and the field is blank what happens then?
Authentication and attribute lookup are not related.
-- Scott
More information about the users
mailing list