dp.attribute.resolver.LDAP.returnAttributes idp v3.3.0

Lipscomb, Gary glipscomb at csu.edu.au
Tue Nov 15 20:58:21 EST 2016


If you don't explicitly mention memberOf in a ldapsearch it is not returned (at least in openLDAP). If you do include it then you have to explicitly included or * for the other attributes to be returned as well

> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Wednesday, 16 November 2016 12:51
> To: Shib Users <users at shibboleth.net>
> Subject: Re: dp.attribute.resolver.LDAP.returnAttributes idp v3.3.0
> 
> On 11/15/16, 8:40 PM, "users on behalf of Lipscomb, Gary" <users-
> bounces at shibboleth.net on behalf of glipscomb at csu.edu.au> wrote:
> 
> > I removed the property from our build process, both in ldap.properties
> > and attribute-resolver.xml  thinking it was not required and that the
> > upgraded v3.3.0 would return all attributes from LDAP as default. All I was
> picking up was just the memberOf attribute. This broke things. My
> misunderstanding of the release notes.
> 
> memberOf isn't an operational attribute AFAIK, so I don't know why that
> wouldn't come back, but there's been no change to the behavior. I never
> intended anybody to change their existing settings, I guess even mentioning
> it was just a bad idea.
> 
> -- Scott
> 
> 
> --
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net


More information about the users mailing list