LDAP uncaught exception
Losen, Stephen C. (scl)
scl at eservices.virginia.edu
Tue Sep 6 07:49:12 EDT 2016
Hi folks,
We have some folks (alums) who can still authenticate with our SSO solution, but who do not have records in LDAP anymore. We are running shib IDP v3.2.1 and are using RemoteUser to integrate with our SSO. When a person with no LDAP record logs in to SSO, the subsequent IDP LDAP lookup fails and we get an "Uncaught exception" from the IDP. Is this expected behavior? Or does it indicate a misconfiguration on my part? It's easy to reproduce with aacli.sh if you are using LDAP. Just enter a principalName that doesn't exist in LDAP.
That brings up another issue. We may need to allow alums to log into a few SPs. I can define a PrincipalName attribute that does not depend on LDAP. However, I did a little experimenting and I can't find a way to configure a SP so that the IDP avoids LDAP. I tried configuring the IDP to release nothing but principalName to a test SP, but the IDP still did the LDAP lookup, resulting in the uncaught exception.
Does anyone have any suggestions for avoiding LDAP? Otherwise I guess we need to create LDAP records for all the alums.
Stephen C. Losen
ITS - Systems and Storage
University of Virginia
scl at virginia.edu 434-924-0640
More information about the users
mailing list