<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Tue, Jun 14, 2016 at 4:38 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">So the attributes there come back even if the bind fails?<br></blockquote><div><br></div><div>Not by default, but you can set idp.authn.LDAP.resolveEntryOnFailure=true.</div><div>That will attempt to get the attributes on the same connection that the bind failed on.</div><div>If ACLs prevent that from working, a custom entry resolver can be wired up.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>