IDPv4 LDAP account state

Jan Oppolzer jan.oppolzer at cesnet.cz
Fri Feb 12 09:21:33 UTC 2021


On Thu, Feb 11, 2021 at 10:51:45PM +0000, Andrew Jason Morgan wrote:
> After upgrading to IDPv4.0.1, I'm looking to modernize my LDAP
> configuration following the guidance in the Release Notes that the
> ldap-authn-config.xml file can be replaced outright.  I had previously
> enabled the ldaptive password policy beans to get account state back
> from the LDAP server.  The IDP4 docs leave me a little confused.
> 
> Can I simply set idp.authn.LDAP.usePasswordPolicy=true or do I need to
> modify the beans in ldap-authn-config.xml (looking at
> https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration
> under Advanced Features > Account State)?

Set idp.authn.LDAP.usePasswordPolicy=true, modify beans, add
'expiring-password' flow and that should be if, if I recall correctly.

-Jan

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5556 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20210212/09946456/attachment.bin>


More information about the users mailing list