<div dir="ltr"><div><div><div><div><div><div>Hi Scott,<br><br></div>You are the man! Thanks a lot.<br><br></div>I have now added as below and there are no erros now:<br><br><!-- Example LDAP Connector --><br><br> <resolver:DataConnector id="myLDAP" xsi:type="dc:LDAPDirectory"<br>
ldapURL="ldap://<a href="http://ldap.myorg.com">ldap.myorg.com</a>"<br> baseDN="ou=Users,dc=myorg,dc=com"<br> principal="CN=ServiceUser,OU=Users,DC=myorg,DC=com"<br> principalCredential="t3st3tye"><br>
<dc:FilterTemplate><br> <![CDATA[<br> (uid=$requestContext.principalName)<br> ]]><br> </dc:FilterTemplate><br><br><dc:LDAPProperty name="java.naming.ldap.attributes.binary" value="objectGUID"/><br>
<br> </resolver:DataConnector><br><br><br><br></div>Microsoft documentation is full of errors and sytax errors I tell you :-)<br><br></div>Thanks for guiding me.<br><br></div>Kind regards,<br><br></div>Farzan<br>
</div><div class="gmail_extra"><br><br><div class="gmail_quote">On 15 August 2014 09:41, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="">On 8/14/14, 5:34 PM, "Farzan Qureshi" <<a href="mailto:fqureshi@rosmini.school.nz">fqureshi@rosmini.school.nz</a>> wrote:<br>
<br>
>It says that to convert the AD records to binary when they are fetched by<br>
>Shibboleth, we have to add an LDAPPROPERTY. For example:<br>
<br>
</div>If that's their example, it's wrong.<br>
<div class=""><br>
><LDAPProperty name="java.naming.ldap.attributes.binary"<br>
>value="objectGUID"/><br>
<br>
</div>Unless the default namespace is set to the data connector namespace, you<br>
need a dc: prefix on the element.<br>
<div class=""><br>
>When I add the above configuration in attribute-resolver.xml and restart<br>
>tomcat services I get following errors.<br>
<br>
</div>Read the error. It's telling you the mistake.<br>
<div class=""><br>
>Caused by: org.xml.sax.SAXParseException; lineNumber: 345; columnNumber:<br>
>78; cvc-complex-type.2.4.a: Invalid content was found starting with<br>
>element 'LDAPProperty'. One of<br>
>'{"urn:mace:shibboleth:2.0:resolver:dc":ReturnAttributes,<br>
>"urn:mace:shibboleth:2.0:resolver:dc":LDAPProperty,<br>
> "urn:mace:shibboleth:2.0:resolver:dc":StartTLSTrustCredential,<br>
>"urn:mace:shibboleth:2.0:resolver:dc":StartTLSAuthenticationCredential,<br>
>"urn:mace:shibboleth:2.0:resolver:dc":ConnectionPool,<br>
>"urn:mace:shibboleth:2.0:resolver:dc":ResultCache}' is expected.<br>
<br>
</div>See the namespace in front of the LDAPProperty element in the expected<br>
content list?<br>
<br>
See how the "starting with" line doesn't have that?<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br><br clear="all"><br>-- <br><font face="tahoma, sans-serif"><b>Farzan Qureshi</b> | Network Administrator & Help-desk Support | Rosmini College | (09) 487 0 530</font>
</div>
<br>
<font style="font-family:Verdana" size="1">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager (<span style="font-weight:bold;font-style:italic"><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></span>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, the recipient should check this email and any attachments for the presence of viruses. <span style="font-weight:bold">Rosmini College</span> accepts no liability for any damage caused by any virus transmitted by this email.</font>