<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Mon, Jun 29, 2015 at 3:13 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Both of those use cases are things you can do more easily with the attribute resolver and without writing code or scripts, but that does mean extra LDAP binds, so I guess there's an efficiency argument in rare cases, but certainly not routinely.<br></blockquote><div><br></div><div>One reason to pull attributes during authentication is that it is the only time you can read attributes as the authenticating user. For some directory implementations it is attractive to simply exercise the user ACLs rather than configuring a service account to read that data.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>