Shibboleth with Active Directory rejects all user names

Tim Williams tmw at autotrain.org
Mon Oct 31 09:02:52 EDT 2016


On 31/10/16 12:30, Dave Perry wrote:
> In conf/ldap.properties, here is what we have (production and test IdPs use same details):
> idp.authn.LDAP.bindDN                           = yourBindUser at yourdomain.local
> idp.authn.LDAP.bindDNCredential                 = yourBindPassword
> This assumes your attribute-resolver.xml file is using the variables stored in ldap.properties (I think that's the default).
> 
> We are using insecure LDAP, and have both production and test IdPs in the internal network so they can see AD without firewalls in the way (published via ForeFront TMG, alongside many other services of ours).
> 

Thanks, that's useful information. It was far from clear in the
documentation that the bind "credential" actually meant a user name and
password. The term "credential" implied the use of some kind of shared
secret key for this. I've put this in and changed the config to use the
credentials and I'm now getting the following error:

org.springframework.binding.expression.EvaluationException: An
ELException occurred getting the value for expression
'ValidateUsernamePassword' on context [class
org.springframework.webflow.engine.impl.RequestControlContextImpl]

Any suggestions?

Kind Regards, Tim Williams

-- 
Tim Williams BSc MSc MBCS
AutoTrain
58 Jacoby Place
Priory Road
Edgbaston
Birmingham
B5 7UW
United Kingdom

Web : http://www.autotrain.org, http://www.utrain.info
Tel : +44 (0)844 487 4117

AutoTrain is a trading name of EuroMotor-AutoTrain LLP
Registered in the United Kingdom, number: OC317070.


More information about the users mailing list