Accept a special password ?
Christopher Bongaarts
cab at umn.edu
Thu Apr 8 21:08:17 UTC 2021
On 4/8/2021 3:51 PM, Mohamed Lrhazi wrote:
> I received a special request from our team.... Could we accept some
> password X as valid, as we test some user accounts?
>
> We use AD for authentication... Is there a way to tell shibboleth to
> assume authentication success if the provided password is X, and not
> attempt to check with AD/LDAP ? but still do attributes lookups as
> normal, from AD/LDAP ?
Impersonation would allow to authenticate with one username/password,
but have the attribute lookups go against a different user.
But if you really wanted the Always Valid Password, you could probably
rig something up with External Auth. Just be sure that access to that
particular IdP is restricted to just the testers...
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list