password expiration intercept code example request

Lee Foltz foltz2 at oakland.edu
Fri Jan 6 15:55:49 UTC 2023


We are running idp_version: 4.2.1 and jdk_version: 11.0.17 and it still
works as expected.  I am sure we might need to update this at some point as
I also thought it was going to be deprecated.

On Fri, Jan 6, 2023 at 10:48 AM David Alexander via users <
users at shibboleth.net> wrote:

> Thanks for sharing this example.
>
> Does the "org.joda.time.format.DateTimeFormat" reference work
> in expiring-password-intercept-config.xml in Shib 4.1.x?
>
> I thought that was deprecated a while back.
>
> On Fri, Jan 6, 2023 at 10:11 AM Lee Foltz via users <users at shibboleth.net>
> wrote:
>
>> We did this using epoch time from LDAP password last change date, but
>> used this setup to intercept the users when their password is about to
>> expire.
>> We display the intercept to people if the password is over 3 years old,
>> then show them the intercept every 24 hours to remind them to change
>> password.
>>
>> Hopefully this example will help some.
>>
>> attribute-resolver.xml
>>
>>  <AttributeDefinition id="passwordExpiration"
>> xsi:type="ScriptedAttribute" >
>>         <InputDataConnector ref="myLDAP"
>> attributeNames="shadowLastChange" />
>>         <Script>
>>           <![CDATA[
>>             logger =
>> Java.type("org.slf4j.LoggerFactory").getLogger("net.shibboleth.idp");
>>
>>             // get epoch last changed and convert from days to
>> milliseconds
>>             logger.info("--- shadowLastChange: {}",
>> shadowLastChange.getValues().get(0));
>>             String = Java.type("java.lang.String");
>>             Long = Java.type("java.lang.Long");
>>             pwls = new Long(shadowLastChange.getValues().get(0));
>>             pwls = pwls * 24 * 3600 * 1000;
>>
>>             // convert to Java date
>>             Date = Java.type("java.util.Date");
>>             expireDate = new Date(pwls);
>>
>>             // convert to format to match the expiring password intercept
>> config
>>             SimpleDateFormat = Java.type("java.text.SimpleDateFormat");
>>             passwordExpiration.addValue(new
>> SimpleDateFormat("yyyyMMdd").format(expireDate));
>>             logger.info("--- shadowLastChange Converted: {}", new
>> SimpleDateFormat("yyyyMMdd").format(expireDate));
>>           ]]>
>>         </Script>
>>
>>
>>
>> expiring-password-intercept-config.xml
>>
>>  <bean id="shibboleth.expiring-password.Condition"
>> class="net.shibboleth.idp.profile.logic.DateAttributePredicate"
>>             c:attribute="passwordExpiration" p:resultIfMissing="true">
>>         <constructor-arg name="formatter">
>>             <bean class="org.joda.time.format.DateTimeFormat"
>> factory-method="forPattern" c:_0="yyyyMMdd" />
>>         </constructor-arg>
>>         <property name="systemTimeOffset">
>>             <bean class="org.joda.time.Duration"
>> factory-method="standardDays" c:_0="1095" />
>>         </property>
>>     </bean>
>>
>>     <!-- Name of cookie to track when user was last notified. -->
>>     <bean id="shibboleth.expiring-password.NotifyCookieName"
>> class="java.lang.String" c:_0="shib_idp_exp_pwd" />
>>
>>     <!-- Interval (milliseconds) between notifications, default is 8
>> hours. We changed this to 4 hours -->
>>     <bean id="shibboleth.expiring-password.NotifyInterval"
>> class="java.lang.Long" c:_0="14400000" />
>>
>> On Fri, Jan 6, 2023 at 9:59 AM Cantor, Scott via users <
>> users at shibboleth.net> wrote:
>>
>>> > Would the offset be positive if I use the password last changed date?
>>>
>>> Probably positive "minus the amount of time you want to warn" or
>>> something like that. Needless to say it hurts my brain every time I go near
>>> it so once it works I leave it alone. But I think you're probably right.
>>>
>>> I'm just saying it's math, and two operations can always be combined
>>> into one, you just have to figure out what the combination of the two is.
>>>
>>> -- Scott
>>>
>>>
>>> --
>>> For Consortium Member technical support, see
>>> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>>> To unsubscribe from this list send an email to
>>> users-unsubscribe at shibboleth.net
>>>
>>
>>
>> --
>> Lee Foltz
>> Oakland University - UTS
>> Senior Identity and Access Management Engineer
>>
>> 248-370-2675
>> --
>> For Consortium Member technical support, see
>> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>


-- 
Lee Foltz
Oakland University - UTS
Senior Identity and Access Management Engineer

248-370-2675
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230106/34da6832/attachment.htm>


More information about the users mailing list