<div dir="ltr"><div class="gmail_default" style="font-family:trebuchet ms,sans-serif">Yes FreeIPA does have the LDAP component and IdP can authenticate against it but without OTP. Only thru Kerberos OTP is usable. </div></div><div class="gmail_extra"><br><div class="gmail_quote">On 2 March 2016 at 20:53, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Prashant Bapat <<a href="mailto:prashant@apigee.com">prashant@apigee.com</a>> [2016-03-02 15:38]:<br>
<span class="">> > I doubt you can, short of writing your own code to invoke native<br>
> > code to get around the above issue.<br>
><br>
> Are there any pointers? Is there an example code?<br>
<br>
</span>I'd first check whether FreeIPA can be used with clients that don't<br>
support that specific feature/transport.<br>
Doesn't FreeIPA also offer an LDAP service, if so can you use that for<br>
authentication?<br>
Failing that maybe look into setting up a proxy/forwarder on the<br>
machine hosting the IDP, and point your IDP to that. (No idea whether<br>
that would work, but seems easier than extending the IDP with native<br>
code.)<br>
<span class="HOEnZb"><font color="#888888">-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>