LDAP uncaught exception

Losen, Stephen C. (scl) scl at eservices.virginia.edu
Tue Sep 6 07:49:12 EDT 2016


Hi folks,

We have some folks (alums) who can still authenticate with our SSO solution, but who do not have records in LDAP anymore.  We are running shib IDP v3.2.1 and are using RemoteUser to integrate with our SSO.  When a person with no LDAP record logs in to SSO, the subsequent IDP LDAP lookup fails and we get an "Uncaught exception" from the IDP.  Is this expected behavior? Or does it indicate a misconfiguration on my part?  It's easy to reproduce with aacli.sh if you are using LDAP.  Just enter a principalName that doesn't exist in LDAP.

That brings up another issue.  We may need to allow alums to log into a few SPs.  I can define a PrincipalName attribute that does not depend on LDAP.  However, I did a little experimenting and I can't find a way to configure a SP so that the IDP avoids LDAP.  I tried configuring the IDP to release nothing but principalName to a test SP, but the IDP still did the LDAP lookup, resulting in the uncaught exception.

Does anyone have any suggestions for avoiding LDAP?  Otherwise I guess we need to create LDAP records for all the alums. 

Stephen C. Losen
ITS - Systems and Storage
University of Virginia
scl at virginia.edu    434-924-0640



More information about the users mailing list