Multiple group memberships

Ian Bobbitt ibobbitt at globalnoc.iu.edu
Thu Feb 16 09:27:08 EST 2017


On 2/15/17 8:35 PM, Cantor, Scott wrote:
> On 2/14/17, 4:55 PM, "users on behalf of Ian Bobbitt" <users-bounces at shibboleth.net on behalf of ibobbitt at globalnoc.iu.edu> wrote:
> 
>> This is what I have in my attribute-resolver.xml:
> 
> That seems fine to me, modulo that I have no idea what LDAP search you really have to perform, and that I would never expose a DN in a SAML assertion.
> 
> If that search returns one value back, that's pretty much going to get you one value out, so I'm sure that's the issue. Whether via Simple, Script, anything else, one value in, one out.
> 
> -- Scott
> 

Scott,

Thanks for taking a look.

If I run the same filter I'm using in an `ldapsearch`, I get back around 175 entries for myself, so I think that logic
is good. Logging the entryDN at the start of the script only shows one, so I think there's something not quite right
about how I'm fetching the data from LDAP. Is there some flag I'm missing to have it fetch multiple entries, or some
logging I can enable to help track down what I'm doing wrong?

I agree that exposing the DNs directly isn't great. My eventual goal is to expose the groups' CNs with a scope attached
to them.

-- 
Ian

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3639 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170216/241fc0d3/attachment-0001.p7s>


More information about the users mailing list