openLDAP pwdReset pwdMustChange

Lipscomb, Gary glipscomb at csu.edu.au
Tue Aug 23 05:31:21 UTC 2022


Hi List,
Environment

  *   IdP 4.2.1
  *   Tomcat 9
  *   OpenJDK 11
  *   RHEL 8
  *   openLDAP 2.4 (a RHEL 7 package )

We are in the initial development stages of implementing a new identity management system IdentityIQ from Sailpoint.
We use openLDAP as our authentication backend.

One of our use cases is when the HelpDesk resets a user's password it must be changed with 24 hours or the account is disabled.
They have suggested we set

  *   pwdReset: TRUE
  *   pwdMustChange: TRUE
and hopefully we can get the SSO login screen to display an appropriate message.
Has anyone done this?

As part of the testing using ldapsearch I get a resultCode(49) Invalid credentials returned so I don't think the above is possible.

A point to note when using Shibboleth SSO with

  *   idp.authn.LDAP.authenticator = bindSearchAuthenticator
     *   authentication is successful
  *   idp.authn.LDAP.authenticator = directAuthenticator
  *   idp.authn.LDAP.dnFormat                         = uid=%s,ou=people,o=csu.edu.au
     *   authentication is successful

The openldap log shows returncode(0) for both methods on the BIND

With both attributes set to FALSE authentication is successful with both authentication types also.
I have

  *   idp.authn.LDAP.usePasswordPolicy = true
  *   idp.authn.LDAP.usePasswordExpiration = true

Is there a ldap.properties  or  ldaptive setting for the  I've missed.


Regards

Gary


Gary Lipscomb
Technical Officer, Systems
IT Infrastructure & Security | Division of Information Technology






[cid:CSU_Logo_01(1)_4d6858d2-0063-4b9a-b775-e0889d59b027.png]<http://www.csu.edu.au/>

|  ALBURY-WODONGA  |  BATHURST  |  CANBERRA  |  DUBBO  |  GOULBURN  |  ORANGE  |  PARRAMATTA  |  PORT MACQUARIE  |  WAGGA WAGGA  |

________________________________
LEGAL NOTICE
This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email are not necessarily those of Charles Sturt University.

Charles Sturt University in Australia<http://www.csu.edu.au> The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551). Charles Sturt University - TEQSA Provider Identification: PRV12018 (Australian University). CRICOS Provider: 00005F.

Consider the environment before printing this email.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220823/971f87e3/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: CSU_Logo_01(1)_4d6858d2-0063-4b9a-b775-e0889d59b027.png
Type: image/png
Size: 9984 bytes
Desc: CSU_Logo_01(1)_4d6858d2-0063-4b9a-b775-e0889d59b027.png
URL: <http://shibboleth.net/pipermail/users/attachments/20220823/971f87e3/attachment.png>


More information about the users mailing list