<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#44546A;}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A">Absolutely!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A">This is my login.config<o:p></o:p></span></p>
<div style="mso-element:para-border-div;border:none;border-bottom:solid windowtext 1.0pt;padding:0in 0in 1.0pt 0in">
<p class="MsoNormal" style="border:none;padding:0in"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> edu.vt.middleware.ldap.jaas.LdapLoginModule required<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> host="horus.ADS.LOYALISTCOLLEGE.CA"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> port="3268"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> base="DC=ads,DC=loyalistcollege,DC=ca"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> tls="false"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> serviceCredential="removed from post”<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> userRoleAttribute="sAMAccountName"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> serviceUser="ldapqsvc@ads.loyalistcollege.ca"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> subtreeSearch = "true"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> userField="samAccountName";<o:p></o:p></span></p>
<div style="mso-element:para-border-div;border:none;border-bottom:solid windowtext 1.0pt;padding:0in 0in 1.0pt 0in">
<p class="MsoNormal" style="border:none;padding:0in"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A">(Where “horus” is a global catalog)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<div style="mso-element:para-border-div;border:none;border-bottom:solid windowtext 1.0pt;padding:0in 0in 1.0pt 0in">
<p class="MsoNormal" style="border:none;padding:0in"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A">And then in addition my attribute-resolver is set to match<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <resolver:DataConnector id="myLDAP" xsi:type="LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc"
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> useStartTLS="false"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> ldapURL="ldap://horus.ADS.LOYALISTCOLLEGE.CA:3268" baseDN="DC=ads,DC=loyalistcollege,DC=ca" principal="ldapqsvc@ads.loyalistcollege.ca"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> principalCredential="removed from post"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <FilterTemplate><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <![CDATA[<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> (sAMAccountName=$requestContext.principalName)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> ]]><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> </FilterTemplate><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <!-- We rely on the uniqueness of the objectSid. But it is binary so we *must* make it so --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <LDAPProperty name="java.naming.ldap.attributes.binary" value="objectSid"/><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <!-- If we are following from the GC we need thus on --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> <LDAPProperty name="java.naming.referral" value="follow"/><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"> </resolver:DataConnector><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<div style="mso-element:para-border-div;border:none;border-bottom:solid windowtext 1.0pt;padding:0in 0in 1.0pt 0in">
<p class="MsoNormal" style="border:none;padding:0in"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A">Once I made those changes, and restarted the service, I am able to login with any users in my AD domain, regardless of where the user is.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:#E51937">Dave Vernon<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:#002A5C">Technology Infrastructure Specialist<o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black"><a href="mailto:dvernon@loyalistc.on.ca">dvernon@loyalistc.on.ca</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black"><a href="http://loyalistcollege.com/">loyalistcollege.com</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Arial","sans-serif";color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><a href="http://www.loyalistcollege.com/"><span style="font-size:13.5pt;text-decoration:none"><img border="0" width="76" height="66" id="Picture_x0020_1" src="cid:image001.png@01CFE23E.C1259870" alt="Loyalist College"></span></a><a href="https://www.facebook.com/loyalistcollege"><span style="font-size:13.5pt;text-decoration:none"><img border="0" width="43" height="33" id="Picture_x0020_2" src="cid:image002.png@01CFE23E.C1259870" alt="Facebook"></span></a><a href="https://twitter.com/loyalistcollege"><span style="font-size:13.5pt;text-decoration:none"><img border="0" width="33" height="33" id="Picture_x0020_3" src="cid:image003.png@01CFE23E.C1259870" alt="Twitter"></span></a><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#44546A"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Farzan Qureshi<br>
<b>Sent:</b> Tuesday, October 07, 2014 2:48 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> RE: Shib / ldap search base<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p>Hi Dave,<o:p></o:p></p>
<p>Would you mind sharing your code in login.config that how you are defining multiple search base?
<o:p></o:p></p>
<p>I have to achieve same scenario. <o:p></o:p></p>
<p>Kind regards, <o:p></o:p></p>
<p>Farzan Qureshi <br>
------------------<br>
Network Administrator & Helpdesk support<br>
Rosmini College<br>
<o:p></o:p></p>
<div>
<p class="MsoNormal">On 8/10/2014 6:53 AM, "Dave Vernon" <<a href="mailto:dvernon@loyalistcollege.com">dvernon@loyalistcollege.com</a>> wrote:<o:p></o:p></p>
<p class="MsoNormal">Thanks Kevin,<br>
<br>
I missed the login.config file! That's what I needed. I've updated my files and things are working great.<br>
<br>
Dave Vernon<br>
Technology Infrastructure Specialist<br>
<a href="mailto:dvernon@loyalistc.on.ca">dvernon@loyalistc.on.ca</a><br>
<a href="http://loyalistcollege.com" target="_blank">loyalistcollege.com</a><br>
<br>
<br>
<br>
<br>
-----Original Message-----<br>
From: <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>] On Behalf Of Kevin Foote<br>
Sent: Tuesday, October 07, 2014 1:33 PM<br>
To: Shib Users<br>
Subject: Re: Shib / ldap search base<br>
<br>
<br>
<br>
On Oct 7, 2014, at 10:25 AM, Dave Vernon <<a href="mailto:dvernon@loyalistcollege.com">dvernon@loyalistcollege.com</a>> wrote:<br>
<br>
> Hello again,<br>
><br>
> As you know, yesterday was an exciting day for me, getting my first Shibboleth project running in my dev environment. My users are held in a Microsoft Active Directory (2008 R2 DC's, 2003 functional level). I was aware that the default search base is CN=Users
so I had put my test user there.<br>
><br>
> Today I went to expand that and I've run into issues. I'd like to be<br>
> able to search from the root of my AD dc=ad,dc=loyalistcollege,dc=ca ,<br>
> so I edited my attribute-resolver.xml file on my IdP, restarted the<br>
> service, and tested. I found that it wasn't working - users NOT in<br>
> the cn=users container were rejected by Shib, and my test user in the<br>
> cn=users container was authenticated by Shib but rejected by the<br>
> resource I'm protecting (remote_user not set)<br>
<br>
....<br>
<br>
<br>
And a snip from my idp-process.log<br>
<br>
javax.security.auth.login.LoginException: Cannot authenticate dn, invalid dn<br>
<br>
<br>
Dave,<br>
<br>
In the IdP authentication and resolving attributes are two different functions.<br>
Both are handled by the vt-ldap package but through different means..<br>
Recall during setup you configured authentication in the "login.config" file while you configured attribute resolution in the "attribute-resolver.xml" file<br>
<br>
--------<br>
thanks<br>
kevin.foote<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
<p class="MsoNormal"><br>
<span style="font-size:7.5pt;font-family:"Verdana","sans-serif"">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please
notify the system manager (<b><i><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></i></b>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those
of the company. Finally, the recipient should check this email and any attachments for the presence of viruses.
<b>Rosmini College</b> accepts no liability for any damage caused by any virus transmitted by this email.</span><o:p></o:p></p>
</div>
</body>
</html>