Box.com and Shibboleth

Cantor, Scott cantor.2 at osu.edu
Thu Mar 3 14:26:57 EST 2016


> lot more. If that line was blank, from what I've read, I would not have
> run into this problem for the last 3 weeks trying to get SSO working
> with Box. Instead, it would have passed any attribute it was supposed to
> look up. Correct?

I doubt it's that simple in terms of how this is configured, it might even just break.

> So from a out of the box experience that may have been more
> preferential. But from a security stand point there may be really good
> reasons that it should contain a fields list. Those fields are pulled
> when the user authenticates

No, they're not.

> so the bindDN would not be needed right?

Yes, it is.

> So if I have the bindDN configured but the returnAttributes is blank in
> ldap.properties everything works.

I don't think so.

> If I have no bindDN configured but I'm
> using anonSearchAuthenticator and the field is blank what happens then?

Authentication and attribute lookup are not related.

-- Scott



More information about the users mailing list