dp.attribute.resolver.LDAP.returnAttributes idp v3.3.0
Lipscomb, Gary
glipscomb at csu.edu.au
Tue Nov 15 20:58:21 EST 2016
If you don't explicitly mention memberOf in a ldapsearch it is not returned (at least in openLDAP). If you do include it then you have to explicitly included or * for the other attributes to be returned as well
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Wednesday, 16 November 2016 12:51
> To: Shib Users <users at shibboleth.net>
> Subject: Re: dp.attribute.resolver.LDAP.returnAttributes idp v3.3.0
>
> On 11/15/16, 8:40 PM, "users on behalf of Lipscomb, Gary" <users-
> bounces at shibboleth.net on behalf of glipscomb at csu.edu.au> wrote:
>
> > I removed the property from our build process, both in ldap.properties
> > and attribute-resolver.xml thinking it was not required and that the
> > upgraded v3.3.0 would return all attributes from LDAP as default. All I was
> picking up was just the memberOf attribute. This broke things. My
> misunderstanding of the release notes.
>
> memberOf isn't an operational attribute AFAIK, so I don't know why that
> wouldn't come back, but there's been no change to the behavior. I never
> intended anybody to change their existing settings, I guess even mentioning
> it was just a bad idea.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net
More information about the users
mailing list