attributes through authentication

Yakov Revyakin yrevyakin at gmail.com
Fri May 10 07:09:05 EDT 2019


Hi guys,
My authentication backend doesn't support communications with a service
account to retrieve users attributes - only that user who was
authenticating is allowed to retrieve the own account attributes.
Authentication includes not only static password but dynamic too - totp.
So, if I even known both I wasn't able to authenticate the user to retrieve
his attributes because of totp expiration.
Has IdP any tools to solve this situation without any extra inventions?

PS: I think I will be refresh local cache after successful authentication
and use it on the next step.

Thanks,
Jake
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190510/63b47a0c/attachment.html>


More information about the users mailing list