<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Jun 30, 2016 at 12:14 PM, James McCartin <span dir="ltr"><<a href="mailto:jmccartin@loyola.edu" target="_blank">jmccartin@loyola.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I also see the following if I turn on trace for net.shibboleth.idp:<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">2016-06-30 12:08:39,410 - TRACE [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:137] - Profile Action ValidateUsernamePasswordAgainstLDAP:
 Authentication response [org.ldaptive.auth.AuthenticationResponse@1451698118::authenticationResultCode=AUTHENTICATION_HANDLER_FAILURE, ldapEntry=[dn=CN=jmccartin,OU=Loyola,DC=adtest,DC=loyola,DC=edu[]], accountState=null, result=false, resultCode=INVALID_CREDENTIALS,
 message=javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 773, v2580 ], controls=null]</span></p></div></div></blockquote><div><br></div><div>That appears to be a response from Active Directory, but you've modified your configuration to support an OpenLDAP ppolicy implementation.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>