<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Mon, Dec 12, 2016 at 3:34 PM, O'Dowd, Josh <span dir="ltr"><<a href="mailto:Josh.O'Dowd@mso.umt.edu" target="_blank">Josh.O'Dowd@mso.umt.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_-8606621135622372911gmail-m_384067685364435653m_4358240468518425304WordSection1">
<p class="MsoNormal"><span style="font-size:11pt;font-family:calibri,sans-serif;color:rgb(31,73,125)">Sure. The following is DEBUG output from ldaptive packages. I believe we are seeing a successful bind followed by a failed search operation. The search operation
appears to be restricted from the list of current allowed operations. I believe this is due to the fact that the directory is enforcing a password-must-change policy that is active. I am concluding that because search operations are not being restricted
for accounts with normal account state.</span></p></div></div></blockquote><div><br></div><div>That's what I expected. If you need that attribute for your flow, you'll have to wire up a connection factory to read it.</div><div>See <a href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-AttributeRetrieval">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-AttributeRetrieval</a></div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>