anomalies with LDAP failure messaging

IAM David Bantz dabantz at alaska.edu
Fri Jun 2 21:54:14 EDT 2017


IdP 3.3.1 using the extended detailed messaging in combination with
jaas.config for password authn:

1. The identical message for "account_locked" seems to be triggered by two
rather different events:
   (a) an IdP initiated temporary lockout triggered by repeated failed
authN, per
https://wiki.shibboleth.net/confluence/display/IDP30/PasswordAuthnConfiguration#PasswordAuthnConfiguration-AccountLockout3.3,
affecting only authN via the IdP, and
   (b) encountering a locked directory account, presumably requiring some
action by the directory admins to unlock.

It seems these should be distinguished.

2. With multiple directories for authN in JAAS.config denoted "sufficient,"
a user that fails to be found (no directory entry) in a directory, then is
found in a subsequent directory, but fails authN because of an invalid
password, receives the "not found" error message on the login page. This is
of course mis-leading to the user who has been found in a second or third
directory source, but failed instead because they submitted an incorrect
password.

Have I insufficiently or mis-configured these features?

David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170602/019c7812/attachment.html>


More information about the users mailing list