anomalies with LDAP failure messaging
IAM David Bantz
dabantz at alaska.edu
Fri Jun 2 21:54:14 EDT 2017
IdP 3.3.1 using the extended detailed messaging in combination with
jaas.config for password authn:
1. The identical message for "account_locked" seems to be triggered by two
rather different events:
(a) an IdP initiated temporary lockout triggered by repeated failed
authN, per
https://wiki.shibboleth.net/confluence/display/IDP30/PasswordAuthnConfiguration#PasswordAuthnConfiguration-AccountLockout3.3,
affecting only authN via the IdP, and
(b) encountering a locked directory account, presumably requiring some
action by the directory admins to unlock.
It seems these should be distinguished.
2. With multiple directories for authN in JAAS.config denoted "sufficient,"
a user that fails to be found (no directory entry) in a directory, then is
found in a subsequent directory, but fails authN because of an invalid
password, receives the "not found" error message on the login page. This is
of course mis-leading to the user who has been found in a second or third
directory source, but failed instead because they submitted an incorrect
password.
Have I insufficiently or mis-configured these features?
David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170602/019c7812/attachment.html>
More information about the users
mailing list