<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I *think* this should work for any directory servers that support the password policy standard - OpenLDAP and ODSEE, at least.<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
On <a href="https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration">
https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration</a>, under Advanced Features > Account State, I don't see why we would include the Spring configuration for adding the handlers. That is taken care of automatically with the usePasswordPolicy
property. Should I update the page by removing the Spring Configuration block and adding the property instead? I'm happy to help if you want me to.</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Andy<br>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Tuesday, February 16, 2021 12:27 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: IDPv4 LDAP account state</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">[This email originated from outside of OSU. Use caution with links and attachments.]<br>
<br>
On 2/16/21, 3:16 PM, "users on behalf of Andrew Jason Morgan" <users-bounces@shibboleth.net on behalf of morgan@oregonstate.edu> wrote:<br>
<br>
> After setting up some tests and cranking up the logging, I found that all I needed to do was set<br>
> idp.authn.LDAP.usePasswordPolicy=true. This flag adds the PasswordPolicyAuthenticationRequestHandler() and<br>
> PasswordPolicyAuthenticationResponseHandler() handlers to the Authenticator. I didn't need to modify beans to add the<br>
> handlers.<br>
<br>
That's good, thanks. I think it's pretty directory-specific unfortunately but good to know it can work at least. The idea was to try and auto-wire as much as possible with simple flags, it's just not maintainable to expose all those objects nor would anybody
want to see them.<br>
<br>
I guess it would be good to maintain a list of the systems it seems to work for.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>