<div dir="ltr">On Thu, Jun 20, 2013 at 12:06 PM, Byte Flinger <span dir="ltr">&lt;<a href="mailto:byteflinger@gmail.com" target="_blank">byteflinger@gmail.com</a>&gt;</span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><p>Hi Christopher</p>
<p>Thanks for the answer. As mentioned, I did indeed manage to get the wanted information using an LDAP DataConnector however given that the role seems to be already returned by the login module, fast or not, it&#39;s still a waste to have to make yet another connection for information that&#39;s already been retrieved.<br>



Trying to get the info out of the principal is exactly what I have been trying to do (among other ways) however so far I have had no luck.</p>
<p>If this is not possible, what is the use of the role parameters in the Ldaploginmodule anyway since it works to login without it (The module simply won&#39;t &quot;commit&quot; any roles, whatever that means).</p></blockquote>

<div><br></div><div style>It&#39;s a general purpose JAAS module, the Shib IDP simply doesn&#39;t leverage those capabilities. (for reasons Scott enumerated...)</div><div style><br></div><div style>--Daniel Fisher</div><div style>

 </div></div></div></div>