IDPv3 Attribute Resolver help

Cantor, Scott cantor.2 at osu.edu
Wed Nov 9 08:55:12 EST 2016


On 11/9/16, 6:21 AM, "users on behalf of Tim Williams" <users-bounces at shibboleth.net on behalf of tmw at autotrain.org> wrote:
> Surely that would generate an error telling me that I didn't have
>    permission to do what I was trying to do rather than give an empty
>    response saying "resultCode=SUCCESS"? Or is AD/Shibboleth not that clever?

No, it wouldn't, that isn't how LDAP works. This has nothing to do with Shibboleth or AD being "clever". If you have bind permission and search permission, you can search. What you get back depends on what you have access to.
  
>    I'm reliably informed by the AD admin that the bindDN user has
>   privileges for everything.

Then your search filter is probably wrong, maybe because of Mike's point, maybe not.

> "How to set up AD for use with Shibboleth" guide
>   would be really handy right now if anybody knows of one.

There are thousands of books on LDAP and on AD. When you understand LDAP and understand *your* LDAP, then you have what you need.

-- Scott
 



More information about the users mailing list