Custom aggregate LDAPAuthnConfiguration help
Grant Byers
Grant.Byers at aarnet.edu.au
Wed Jun 30 00:22:40 UTC 2021
Yes, it turns out one of the LDAP servers was presenting a 1024 bit key, but i'd been running all my validation tests against another LDAP server in the pool.
Nothing quite like consistency... Had been tearing my hair out thinking i'd done something stupid wiring it up.
And yes, I had also taken the example for aggregate DNs from the wiki and adapted to our use case with same results. I'll use that config now I know it was a
dodgy AD server.
Thanks,
Grant
On Tue, 2021-06-29 at 12:15 +0000, Cantor, Scott wrote:
> [External Mail]
>
>
> Clearly you're wrong about there being no 1024 bit key, but that aside, you need to dump the old file and simply look at the documentation, there are examples
> of chaining validators together, be it for OU purposes or separate server purposes.
>
> The LDAP wiring is the one example where you need to start over and not try and use the old configuration.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Cgrant.byers%40aarnet.edu.au%7C632ae828d4c045d500bd08d93af79fac%7C4795f4d0a4b847c4af198dd47da5d8d4%7C0%7C0%7C637605657487990353%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=xKeQUHLJgFCBIKafsUgB%2FFv94ExB%2BzeWlSQS5vsMa1Y%3D&reserved=0
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list