<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div>Preferable to just ignore that specific account expired state; that results in desired effect without having to craft a tool for a service IAM doesn't run then asking user to do something. Also has less impact on the services run by others that "use" expired flag for their access control.<br><br><a href="mailto:David.Bantz@me.com">David.Bantz@me.com</a><div>David.Bantz<span class="Apple-style-span" style="-webkit-composition-fill-color: rgba(175, 192, 227, 0.231373); -webkit-composition-frame-color: rgba(77, 128, 180, 0.231373); ">@Alaska.edu</span><div><span class="Apple-style-span" style="-webkit-composition-fill-color: rgba(175, 192, 227, 0.230469); -webkit-composition-frame-color: rgba(77, 128, 180, 0.230469);"><br></span></div></div></div><div><br>On May 25, 2017, at 12:07, Daniel Fisher <<a href="mailto:dfisher@vt.edu">dfisher@vt.edu</a>> wrote:<br><br></div><blockquote type="cite"><div><div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, May 25, 2017 at 2:23 PM, IAM David Bantz <span dir="ltr"><<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Is it feasible in IdP 3.3 to intercept an authN failure against AD LDAP due to expired account (error 49, data 701) and treat as though successful authN? ("701" data is supposed to be returned ONLY if the supplied credentials were otherwise valid, so this does not bypass expired password, locked account, or bad password, but only those attempts that would have been successful but for the account being marked expired.)</div></div></blockquote><div><br></div><div>So do you want to ignore this particular account state or will you be sending these users somewhere to unexpire their account in a self-service fashion?</div><div><br></div><div>--Daniel Fisher</div><div> </div></div></div></div>
</div></blockquote><blockquote type="cite"><div><span>-- </span><br><span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></span></div></blockquote></body></html>