<p dir="ltr">Hi Dave,</p>
<p dir="ltr">Would you mind sharing your code in login.config that how you are defining multiple search base? </p>
<p dir="ltr">I have to achieve same scenario. </p>
<p dir="ltr">Kind regards, </p>
<p dir="ltr">Farzan Qureshi <br>
------------------<br>
Network Administrator & Helpdesk support<br>
Rosmini College<br>
</p>
<div class="gmail_quote">On 8/10/2014 6:53 AM, "Dave Vernon" <<a href="mailto:dvernon@loyalistcollege.com">dvernon@loyalistcollege.com</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Thanks Kevin,<br>
<br>
I missed the login.config file! That's what I needed. I've updated my files and things are working great.<br>
<br>
Dave Vernon<br>
Technology Infrastructure Specialist<br>
<a href="mailto:dvernon@loyalistc.on.ca">dvernon@loyalistc.on.ca</a><br>
<a href="http://loyalistcollege.com" target="_blank">loyalistcollege.com</a><br>
<br>
<br>
<br>
<br>
-----Original Message-----<br>
From: <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>] On Behalf Of Kevin Foote<br>
Sent: Tuesday, October 07, 2014 1:33 PM<br>
To: Shib Users<br>
Subject: Re: Shib / ldap search base<br>
<br>
<br>
<br>
On Oct 7, 2014, at 10:25 AM, Dave Vernon <<a href="mailto:dvernon@loyalistcollege.com">dvernon@loyalistcollege.com</a>> wrote:<br>
<br>
> Hello again,<br>
><br>
> As you know, yesterday was an exciting day for me, getting my first Shibboleth project running in my dev environment. My users are held in a Microsoft Active Directory (2008 R2 DC's, 2003 functional level). I was aware that the default search base is CN=Users so I had put my test user there.<br>
><br>
> Today I went to expand that and I've run into issues. I'd like to be<br>
> able to search from the root of my AD dc=ad,dc=loyalistcollege,dc=ca ,<br>
> so I edited my attribute-resolver.xml file on my IdP, restarted the<br>
> service, and tested. I found that it wasn't working - users NOT in<br>
> the cn=users container were rejected by Shib, and my test user in the<br>
> cn=users container was authenticated by Shib but rejected by the<br>
> resource I'm protecting (remote_user not set)<br>
<br>
....<br>
<br>
<br>
And a snip from my idp-process.log<br>
<br>
javax.security.auth.login.LoginException: Cannot authenticate dn, invalid dn<br>
<br>
<br>
Dave,<br>
<br>
In the IdP authentication and resolving attributes are two different functions.<br>
Both are handled by the vt-ldap package but through different means..<br>
Recall during setup you configured authentication in the "login.config" file while you configured attribute resolution in the "attribute-resolver.xml" file<br>
<br>
--------<br>
thanks<br>
kevin.foote<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>
<br>
<font style="font-family:Verdana" size="1">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager (<span style="font-weight:bold;font-style:italic"><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></span>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, the recipient should check this email and any attachments for the presence of viruses. <span style="font-weight:bold">Rosmini College</span> accepts no liability for any damage caused by any virus transmitted by this email.</font>