On Mon, Sep 26, 2011 at 11:01 AM, Leonard Kroll <span dir="ltr">&lt;<a href="mailto:Leonard.Kroll@umb.edu">Leonard.Kroll@umb.edu</a>&gt;</span> wrote:<br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">









<u></u>
<u></u>
<u></u>





<div lang="EN-US" link="blue" vlink="blue">

<div>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">Hi, I got the DN to work when <span>Binding</span> a user to perform the LDAP lookup.<u></u><u></u></span></font></p>


<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">I am using MS LDAP if that makes any
difference.<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">But I get the email and DN error that
follows. <span>Any Ideas?</span><u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue"><u></u> <u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">I would like to authenticate against either
the email address or the <span>sAMAddressName</span> in the <span>ldap</span>.<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue"><u></u> <u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">&lt;<span>resolver<span>:AttributeDefinition</span></span> <span>xsi:type</span>=&quot;<span>ad:Simple</span>&quot; id=&quot;email&quot; <span>sourceAttributeID</span>=&quot;mail&quot;&gt;<u></u><u></u></span></font></p>


<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">&lt;<span>resolver<span>:Dependency</span></span> ref=&quot;<span>myLDAP</span>&quot;
/&gt;<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">&lt;<span>resolver<span>:AttributeEncoder</span></span> <span>xsi:type</span>=&quot;enc:SAML1String&quot;
name=&quot;<span>urn:mace:dir:attribute-def:mail</span>&quot;
/&gt;<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">&lt;<span>resolver<span>:AttributeEncoder</span></span> <span>xsi:type</span>=&quot;enc:SAML2String&quot;
name=&quot;urn:oid:0.9.2342.19200300.100.1.3&quot; <span>friendlyName</span>=&quot;mail&quot;
/&gt;<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">&lt;/<span>resolver<span>:AttributeDefinition</span></span>&gt;<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue"><u></u> <u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue"><u></u> <u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">10:47:22.385 - INFO
[edu.vt.middleware.ldap.auth.SearchDnResolver:161] - Search for user: <a href="mailto:Aaaaaaa.bbbbbbb@umb.edu" target="_blank">Aaaaaaa.bbbbbbb@umb.edu</a>
fail<u></u><u></u></span></font></p>

<p class="MsoNormal"><span><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">ed</span></font></span><font size="4" color="blue"><span style="font-size:14.0pt;color:blue"> using filter:
email={0}<u></u><u></u></span></font></p>

<p class="MsoNormal"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue">10:47:22.386 - DEBUG
[edu.vt.middleware.ldap.jaas.LdapLoginModule:136] - Authentication failed <span>javax.naming.AuthenticationException</span>: Cannot authenticate <span><span>dn</span></span>, invalid <span>dn</span><u></u><u></u></span></font></p>


<div style="border:none;border-bottom:double windowtext 2.25pt;padding:0in 0in 1.0pt 0in">

<p class="MsoNormal" style="border:none;padding:0in"><font size="4" color="blue" face="Times New Roman"><span style="font-size:14.0pt;color:blue"><u></u></span></font></p></div></div></div></blockquote><div><br></div><div>
<br></div><div>Ok, looks like you&#39;re getting closer. I don&#39;t use Active Directory, but I&#39;m guessing that filter should be &#39;mail={0}&#39;. At this point you should be able to diagnose your problems by checking your AD logs.</div>
<div><br></div><div>--Daniel Fisher</div><div><br></div></div>