<div dir="ltr">Well, I guess talking to ldap and messing with attributes seemed like much more comfortable territory to me, since I've really not messed with Java at all. I mean, I'm a total noob who can only rely on examples to guide me. <div><br></div><div>I know what you mean about people being fooled into giving out their passwords by even the most flimsy attempt - I am constantly amazed at what people will fall for -  but when the phishing uses our actual login images, that seems a bit too much to expect people to watch out for. I don't know.</div><div><br></div><div>Sigh.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Oct 14, 2016 at 3:46 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> But maybe if I set it up so that the ldap server port is only open to my IdP to<br>
> read that attribute, then,,,they couldn't fake it because they couldn't see it,<br>
> right? I have to think about that.<br>
<br>
</span>No, they wouldn't have access to your LDAP server anyway.<br>
<br>
If you're really worried about people phishing your users, I suspect you're spending a lot of time to accomplish very little but your original idea is as good as any.<br>
<br>
Phishing doesn't require that people spoof your page. Those users will hand over their password to anybody for any reason. They simply don't value it.<br>
<span class=""><br>
> Can you use the ldap connector to look up a user and read an attribute<br>
> before the authn completes? (I assume the attribute resolver doesn't kick in<br>
> until the person authenticates.) I mean, it's going to have to find them to<br>
> authenticate them, obviously, but...<br>
<br>
</span>No, that's all custom login flow work, way beyond simply coding some Java into a template.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div></div>
</div>