<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px"><div id="yui_3_16_0_1_1446495674868_5773" dir="ltr">Hello.  We have it set up in the ldap.properties to what you said below. "idp.authn.LDAP.bindDN                           = CN=shib_test_acct,OU=test,OU=dc,DC=com. </div><div id="yui_3_16_0_1_1446495674868_6918" dir="ltr"><br></div><div id="yui_3_16_0_1_1446495674868_6673" dir="ltr">1) Do we need quotes around it?</div><div id="yui_3_16_0_1_1446495674868_6617" dir="ltr">2) Are spaces allowed such as OU=test ou?</div><div id="yui_3_16_0_1_1446495674868_6674" dir="ltr"><br></div><div id="yui_3_16_0_1_1446495674868_6726" dir="ltr">Unfortunately, we are still getting this error. Any help would be great. <br></div><div id="yui_3_16_0_1_1446495674868_6760" dir="ltr"><br></div><div id="yui_3_16_0_1_1446495674868_6765" dir="ltr">To recap what we did.</div><div id="yui_3_16_0_1_1446495674868_6766" dir="ltr">1) we added the dc info to ldap.properties</div><div id="yui_3_16_0_1_1446495674868_6769" dir="ltr">2) we added the dc info to jaas.config<br></div><div id="yui_3_16_0_1_1446495674868_6803" dir="ltr"><br></div><div id="yui_3_16_0_1_1446495674868_6885" dir="ltr">I'm not sure if they are both required for active directory.</div><div id="yui_3_16_0_1_1446495674868_6917" dir="ltr"><br></div><div id="yui_3_16_0_1_1446495674868_6802" dir="ltr">Thank you.<br></div><div id="yui_3_16_0_1_1446495674868_5688"><span></span></div>  <br><div id="yui_3_16_0_1_1446495674868_6388" class="qtdSeparateBR"><br><br></div><div style="display: block;" id="yui_3_16_0_1_1446495674868_5898" class="yahoo_quoted"> <div id="yui_3_16_0_1_1446495674868_5897" style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div id="yui_3_16_0_1_1446495674868_5896" style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div id="yui_3_16_0_1_1446495674868_6243" dir="ltr"> <font id="yui_3_16_0_1_1446495674868_6242" face="Arial" size="2"> On Friday, October 30, 2015 4:05 PM, Brian Biggs <brian.biggs@sonoma.edu> wrote:<br> </font> </div>  <br><br> <div id="yui_3_16_0_1_1446495674868_6286" class="y_msg_container"><div id="yiv0805811811"><div id="yui_3_16_0_1_1446495674868_6387">
    For one thing, your idp.authn.LDAP.bindDN is definitely wrong.<br clear="none">
    Should be more like "cn=bind_account_name,ou=test,dc=domain,dc=com"<br clear="none">
    <br clear="none">
    -Brian<br clear="none">
    <br clear="none">
    <div class="yiv0805811811yqt1525453567" id="yiv0805811811yqt51935"><div id="yui_3_16_0_1_1446495674868_6386" class="yiv0805811811moz-cite-prefix">On 10/30/2015 12:57 PM, Ower All wrote:<br clear="none">
    </div>
    <blockquote type="cite">
      </blockquote></div></div><div class="yiv0805811811yqt1525453567" id="yiv0805811811yqt97220"><div id="yui_3_16_0_1_1446495674868_6285"><div id="yui_3_16_0_1_1446495674868_6284" style="color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;">
        <div id="yiv0805811811yui_3_16_0_1_1446234828684_2971">Thank you peter. We
          have decided to try JAAS since we could not get it working
          this way. Has anyone seen this error before?</div>
        <div id="yiv0805811811yui_3_16_0_1_1446234828684_2972"><br clear="none">
        </div>
        <div dir="ltr" id="yiv0805811811yui_3_16_0_1_1446234828684_3040">2015-10-30
          15:40:58,646 - ERROR
          [org.opensaml.profile.action.impl.DecodeMessage:73] - Profile
          Action DecodeMessage: Unable to decode incoming request<br class="yiv0805811811" id="yiv0805811811yui_3_16_0_1_1446234828684_3042" clear="none">
          org.opensaml.messaging.decoder.MessageDecodingException: No
          SAMLRequest or SAMLResponse query path parameter, invalid SAML
          2 HTTP Redirect message<br class="yiv0805811811" id="yiv0805811811yui_3_16_0_1_1446234828684_3044" clear="none">
                  at
org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder.doDecode(HTTPRedirectDeflateDecoder.java:73)<br class="yiv0805811811" id="yiv0805811811yui_3_16_0_1_1446234828684_3046" clear="none">
          2015-10-30 15:48:24,012 - INFO
          [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstJAAS:199]
          - Profile Action ValidateUsernamePasswordAgainstJAAS: Login by
          testuser failed<br class="yiv0805811811" id="yiv0805811811yui_3_16_0_1_1446234828684_3048" clear="none">
          javax.security.auth.login.LoginException: Authentication
          failed:
          [org.ldaptive.auth.AuthenticationResponse@1542122009::authenticationResultCode=DN_RESOLUTION_FAILURE,
          ldapEntry=null, accountState=null, result=false,
          resultCode=null, message=DN cannot be null, controls=null]<br class="yiv0805811811" id="yiv0805811811yui_3_16_0_1_1446234828684_3050" clear="none">
                  at
          org.ldaptive.jaas.LdapLoginModule.login(LdapLoginModule.java:160)</div>
        <div dir="ltr" id="yiv0805811811yui_3_16_0_1_1446234828684_3081"><br clear="none">
        </div>
        <div dir="ltr" id="yiv0805811811yui_3_16_0_1_1446234828684_3118">We edited
          JAAS.config with our information. Thank you<br clear="none">
        </div>
        <div id="yiv0805811811yui_3_16_0_1_1446234828684_2973"><br clear="none">
        </div>
        <div id="yiv0805811811yui_3_16_0_1_1446234828684_2911"><span></span></div>
        <br clear="none">
        <div class="yiv0805811811qtdSeparateBR"><br clear="none">
          <br clear="none">
        </div>
        <div id="yui_3_16_0_1_1446495674868_6385" class="yiv0805811811yahoo_quoted" style="display:block;">
          <div id="yui_3_16_0_1_1446495674868_6384" style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;">
            <div id="yui_3_16_0_1_1446495674868_6383" style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;">
              <div dir="ltr"> <font face="Arial" size="2"> On Thursday,
                  October 29, 2015 3:15 PM, Peter Schober
                  <a rel="nofollow" shape="rect" class="yiv0805811811moz-txt-link-rfc2396E" ymailto="mailto:peter.schober@univie.ac.at" target="_blank" href="mailto:peter.schober@univie.ac.at"><peter.schober@univie.ac.at></a> wrote:<br clear="none">
                </font> </div>
              <br clear="none">
              <br clear="none">
              <div id="yui_3_16_0_1_1446495674868_6382" class="yiv0805811811y_msg_container">First of all, you're missing
                an error description.<br clear="none">
                <div class="yiv0805811811yqt4452076203" id="yiv0805811811yqtfd86192"><br clear="none">
                  * Ower All <<a rel="nofollow" shape="rect" ymailto="mailto:owerall@yahoo.com" target="_blank" href="mailto:owerall@yahoo.com">owerall@yahoo.com</a>>
                  [2015-10-29 19:24]:<br clear="none">
                  >
                  idp.authn.LDAP.ldapURL                           =
                  <a href="" rel="nofollow" shape="rect" class="yiv0805811811moz-txt-link-freetext">ldaps://test.domain.com</a> (do I need a port # here?)<br clear="none">
                  > #idp.authn.LDAP.useStartTLS                   =
                  true<br clear="none">
                  > #idp.authn.LDAP.useSSL                          =
                  false<br clear="none">
                  > #idp.authn.LDAP.connectTimeout             = 3000<br clear="none">
                  > #idp.authn.LDAP.sslConfig                       =
                  jvmTrust<br clear="none">
                  > idp.authn.LDAP.baseDN                           
                  = ou=test,dc=domain,dc=com<br clear="none">
                  > #idp.authn.LDAP.subtreeSearch                =
                  false<br clear="none">
                  >
                  idp.authn.LDAP.bindDN                              = <a rel="nofollow" shape="rect" ymailto="mailto:testacct@test.domain.com" target="_blank" href="mailto:testacct@test.domain.com"></a><a rel="nofollow" shape="rect" class="yiv0805811811moz-txt-link-abbreviated" ymailto="mailto:testacct@test.domain.com" target="_blank" href="mailto:testacct@test.domain.com">testacct@test.domain.com</a><br clear="none">
                  > idp.authn.LDAP.bindDNCredential                 =
                  ***** </div>
                <br clear="none">
                <br clear="none">
                As per<br clear="none">
                <a rel="nofollow" shape="rect" target="_blank" href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration</a><br clear="none">
                the parameter idp.authn.LDAP.useStartTLS defaults to
                true (which will<br clear="none">
                be active if you leave it commented out), which won't
                work when you're<br clear="none">
                connecting with an ldapURL of ldaps.<br clear="none">
                So next I'd uncomment idp.authn.LDAP.useStartTLS and set
                it to false.<br clear="none">
                <br clear="none">
                Then your ldapURL is ldaps (implying useSSL, to me) but
                the default of<br clear="none">
                idp.authn.LDAP.useSSL=false is active. No idea what the
                libraries will<br clear="none">
                do in such a case, but it doesn't make much sense.<br clear="none">
                <br clear="none">
                To what port you should connect is up to your
                deployment, we can't<br clear="none">
                tell you. The libraries will pick the IANA-defined
                standard port from<br clear="none">
                the ldapURL, I'd expect. So once the scheme in the
                ldapURL is correct<br clear="none">
                you'd only have to add a port if you're not connecting
                to the<br clear="none">
                IANA-defined standard ports, but e.g. to MS-AD's "global
                catalog"<br clear="none">
                (AFAIK). In short: ask your MS-AD admins.<br clear="none">
                <br clear="none">
                There's also a section on MS-AD in the documentation.<br clear="none">
                <a rel="nofollow" shape="rect" target="_blank" href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-ActiveDirectoryConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-ActiveDirectoryConfiguration</a><br clear="none">
                <br clear="none">
                -peter<br clear="none">
                -- <br clear="none">
                To unsubscribe from this list send an email to <a rel="nofollow" shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net"></a><a rel="nofollow" shape="rect" class="yiv0805811811moz-txt-link-abbreviated" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br clear="none">
                <br clear="none">
              </div>
            </div>
          </div>
        </div>
      </div>
      <br clear="none">
      <fieldset class="yiv0805811811mimeAttachmentHeader"></fieldset>
      <br clear="none">
    
    <br clear="none">
    <pre class="yiv0805811811moz-signature">-- 

Brian Biggs
Sonoma State University
</pre>
  </div></div></div><br><div class="yqt1525453567" id="yqt51258">-- <br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div><br><br></div>  </div> </div>  </div></div></body></html>