<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Garamond;
        panose-1:2 2 4 4 3 3 1 1 8 3;}
@font-face
        {font-family:"Bradley Hand ITC";
        panose-1:3 7 4 2 5 3 2 3 2 3;}
@font-face
        {font-family:David;
        panose-1:2 14 5 2 6 4 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Garamond",serif;
        color:windowtext;
        font-weight:normal;
        font-style:normal;
        text-decoration:none none;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">We are in the process of upgrading from Shibboleth V2.3 to V3.3 and I can’t seem to get the ldap connection to work properly. Authentication fails each time with a password incorrect.<o:p></o:p></p>
<p class="MsoNormal">The password is correct because the same process is working on the V2.3<o:p></o:p></p>
<p class="MsoNormal">I have worked with changing the idp.authn.LDAP.authenticator to
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333;background:white">
bindSearchAuthenticator in which the ldap connection would fail. I changed it back to adAuthenticatior but as you can see by the logs user is still unable to login.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,321 - DEBUG [net.shibboleth.idp.authn.AbstractExtractionAction:137] - Profile Action ExtractUsernamePasswordFromFormRequest: Trimming whitespace of input string '*****'<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,347 - DEBUG [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:131] - Profile Action ValidateUsernamePasswordAgainstLDAP: Attempting to authenticate user *****<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,348 - DEBUG [org.ldaptive.auth.Authenticator:236] - authenticate dn= with request=[org.ldaptive.auth.AuthenticationRequest@1887069008::user=tolock, retAttrs=[passwordExpirationTime, loginGraceRemaining]]<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,360 - INFO [org.ldaptive.auth.Authenticator:259] - Authentication failed for dn:
<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,360 - DEBUG [org.ldaptive.auth.Authenticator:284] - authenticate response=[org.ldaptive.auth.AuthenticationHandlerResponse@729642348::connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection@1010890713::config=[org.ldaptive.ConnectionConfig@2139568793::ldapUrl=ldap://captain.uncp.edu:389,
 connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig@681334126::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@6c2174c8, trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null],
 useSSL=false, useStartTLS=false, connectionInitializer=null], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiConnectionFactory@1742175146::metadata=[ldapUrl=ldap://ldap.****.edu:389, count=1], environment={com.sun.jndi.ldap.connect.timeout=3000,
 java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig@1188928125::operationExceptionResultCodes=[PROTOCOL_ERROR, SERVER_DOWN], properties={},
<a href="mailto:connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy@5c13ea16">
<span style="color:#0563C1">connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy@5c13ea16</span></a>,
<a href="mailto:controlProcessor=org.ldaptive.provider.ControlProcessor@7db67354">
<span style="color:#0563C1">controlProcessor=org.ldaptive.provider.ControlProcessor@7db67354</span></a>, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED, SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null,
 hostnameVerifier=null]], <a href="mailto:providerConnection=org.ldaptive.provider.jndi.JndiConnection@21e05d63">
<span style="color:#0563C1">providerConnection=org.ldaptive.provider.jndi.JndiConnection@21e05d63</span></a>], result=false, resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042F,
 comment: AcceptSecurityContext error, data 52e, v2580], controls=null] for dn= with request=[org.ldaptive.auth.AuthenticationRequest@1887069008::user=*****, retAttrs=[passwordExpirationTime, loginGraceRemaining]]<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,361 - INFO [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:152] - Profile Action ValidateUsernamePasswordAgainstLDAP: Login by '*****' failed<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,383 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:360] - Found matching scheme, returning name of 'federation.northcarolina.edu'<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,384 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:783] - No UIInfo or logos returning null<o:p></o:p></p>
<p class="MsoNormal">2018-06-26 18:22:34,384 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:529] - No description matching the languages found, returning null<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">configuration from <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Relying-party.xml<o:p></o:p></p>
<p class="MsoNormal"><resolver:DataConnector id="myAD" xsi:type="LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc"<o:p></o:p></p>
<p class="MsoNormal">ldapURL="ldap://ldap.****.edu ldap" baseDN="dc=****,dc=local"<o:p></o:p></p>
<p class="MsoNormal">principal="cn=CGI PCA,ou=Service Accounts,dc=****,dc=local" principalCredential="**************"<o:p></o:p></p>
<p class="MsoNormal">searchScope="SUBTREE"><o:p></o:p></p>
<p class="MsoNormal"><dc:FilterTemplate><o:p></o:p></p>
<p class="MsoNormal">            <![CDATA[<o:p></o:p></p>
<p class="MsoNormal">                (&(sAMAccountName=$requestContext.principalName)(objectClass=user))<o:p></o:p></p>
<p class="MsoNormal">            ]]><o:p></o:p></p>
<p class="MsoNormal">        </dc:FilterTemplate><o:p></o:p></p>
<p class="MsoNormal">        <LDAPProperty name="java.naming.referral" value="follow"/><o:p></o:p></p>
<p class="MsoNormal">        <LDAPProperty name="com.sun.jndi.ldap.connect.timeout" value="3000"/><o:p></o:p></p>
<p class="MsoNormal">    </resolver:DataConnector><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Ldap.properties<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># LDAP authentication configuration, see authn/ldap-authn-config.xml<o:p></o:p></p>
<p class="MsoNormal"># Note, this doesn't apply to the use of JAAS<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## Authenticator strategy, either anonSearchAuthenticator, bindSearchAuthenticator, directAuthenticator, adAuthenticator<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.authenticator = adAuthenticator<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## Connection properties ##<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.ldapURL = ldap://ldap.****.edu:389<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.useStartTLS = false<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.useSSL = false<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.connectTimeout = 3000<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.sslConfig = certificateTrust<o:p></o:p></p>
<p class="MsoNormal">## If using certificateTrust above, set to the trusted certificate's path<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.trustCertificates = %{idp.home}/credentials/ldap-server.crt<o:p></o:p></p>
<p class="MsoNormal">## If using keyStoreTrust above, set to the truststore path<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.trustStore = %{idp.home}/credentials/ldap-server.truststore<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## Return attributes during authentication<o:p></o:p></p>
<p class="MsoNormal">## NOTE: there is a separate property used for attribute resolution<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.returnAttributes = passwordExpirationTime,loginGraceRemaining<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## DN resolution properties ##<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># Search DN resolution, used by anonSearchAuthenticator, bindSearchAuthenticator<o:p></o:p></p>
<p class="MsoNormal"># for AD: CN=Users,DC=example,DC=org<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.baseDN = dc=****,dc=local<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.subtreeSearch = true<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.userFilter = (uid={sAMAccountName})<o:p></o:p></p>
<p class="MsoNormal"># bind search configuration<o:p></o:p></p>
<p class="MsoNormal"># for AD: <a href="mailto:idp.authn.LDAP.bindDN=adminuser@domain.com">
<span style="color:#0563C1">idp.authn.LDAP.bindDN=adminuser@domain.com</span></a><o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.bindDN = uid=******,cn=CGI PCA,ou=Service Accounts,dc=****,dc=local<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.bindDNCredential = **********<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># Format DN resolution, used by directAuthenticator, adAuthenticator<o:p></o:p></p>
<p class="MsoNormal"># for AD use <a href="mailto:idp.authn.LDAP.dnFormat=%25s@domain.com">
<span style="color:#0563C1">idp.authn.LDAP.dnFormat=%s@domain.com</span></a><o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.dnFormat = <o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Garamond",serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Garamond",serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-family:"Bradley Hand ITC";color:#4472C4">Tabitha O. Locklear<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-family:"Bradley Hand ITC";color:#4472C4">MS Information Technology<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-family:"Bradley Hand ITC";color:#4472C4">Operations & Systems Analyst<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-family:"Bradley Hand ITC";color:#4472C4">Division of Information Technology<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-family:"Bradley Hand ITC";color:#4472C4">University of North Carolina at Pembroke<o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-family:"Bradley Hand ITC";color:#4472C4">tabithao.locklear@uncp.edu<o:p></o:p></span></b></p>
</div>
</body>
</html>