ldap warning "Unsuccessful search response" after upgrade to IDP 5

David Stava David.Stava at ist.ac.at
Wed Apr 3 08:02:31 UTC 2024


Dear Peter,


many thanks for your reply.


in ldap.properties we have

idp.authn.LDAP.dnFormat                         = %s at ista.ac.at

idp.authn.LDAP.baseDN                           = dc=ista,dc=ac,dc=at

idp.authn.LDAP.userFilter                       = (sAMAccountName={user})


I have tested with a few users and the message appears for everyone.

Attribute resolver is working, aacli shows all the attributes.


> INVALID_DN_SYNTAX (coming from your LDAP server) still seems clear?

I'm not sure what do you mean?


Best,

David Stava


________________________________
From: users <users-bounces at shibboleth.net> on behalf of Peter Schober via users <users at shibboleth.net>
Sent: Tuesday, April 2, 2024 5:19:56 PM
To: users at shibboleth.net
Cc: Peter Schober
Subject: Re: ldap warning "Unsuccessful search response" after upgrade to IDP 5

Peter Schober via users <users at shibboleth.net> [2024-04-02 17:14 CEST]:
> David Stava via users <users at shibboleth.net> [2024-04-02 17:00 CEST]:
> > org.ldaptive.LdapException: Error resolving entry for
> >     username at domain. Unsuccessful search response:
> >     org.ldaptive.SearchResponse at 1220993256::messageID=2,
> >     controls=[], resultCode=INVALID_DN_SYNTAX, matchedDN=,
> >     diagnosticMessage=0000208F: NameErr: DSID-03100233, problem 2006
> >     (BAD_NAME), data 8350, best match of:
> >     'username at domain'
>
> What is your idp.authn.LDAP.authenticator property currently set to
> (in conf/ldap.properties)?

Sorry, I skipped over that where you already wrote:

> when using password authentication with ldap adAuthenticator

INVALID_DN_SYNTAX (coming from your LDAP server) still seems clear?

Besides idp.authn.LDAP.authenticator=adAuthenticator what are the
values of other relevant settings (e.g. idp.authn.LDAP.dnFormat)?
Does the above exception occur with any/all user names or just with
some?  Does the resover work using those same user names, e.g. using
aacli?

-peter
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240403/c9667e18/attachment.htm>


More information about the users mailing list