<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Hope you are doing great and staying safe, I would like to let you know that we are facing an issue to connect shibboleth IDP 4.1 with google LDAP, we have tried our best to configure the LDAP, although google did not show how to configure
LDAP with shibboleth IDP.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">It keeps showing the following error "<span style="color:red">Login Failure: Pool is empty, and connection creation failed</span>" , when we tried to enter the user conditionals on authentication page. On the log file, we keep getting the
below errors:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Please assets on how to solve this issue.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">“<i><span style="color:blue">DEBUG [org.ldaptive.provider.unboundid.UnboundIDConnectionFactory:90] - Error connecting to LDAP URL: ldap://ldap.google.com:636<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue">org.ldaptive.provider.ConnectionException: LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to connect to server ldap.google.com:636: IOException(LDAPException(resultCode=91
(connect error), errorMessage='An error occurred while attempting to establish a connection to server ldap.google.com/216.239.32.58:636: ConnectException(Connection timed out: connect), ldapSDKVersion=4.0.14, revision=c0fb784eebf9d36a67c736d0428fb3577f2e25bb'))')<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue"> at org.ldaptive.provider.unboundid.UnboundIDConnectionFactory.createInternal(UnboundIDConnectionFactory.java:65)<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue">Caused by: com.unboundid.ldap.sdk.LDAPException: An error occurred while attempting to connect to server ldap.google.com:636: IOException(LDAPException(resultCode=91 (connect error), errorMessage='An error occurred
while attempting to establish a connection to server ldap.google.com/216.239.32.58:636: ConnectException(Connection timed out: connect), ldapSDKVersion=4.0.14, revision=c0fb784eebf9d36a67c736d0428fb3577f2e25bb'))<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue"> at com.unboundid.ldap.sdk.LDAPConnection.connect(LDAPConnection.java:875)<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue">Caused by: java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='An error occurred while attempting to establish a connection to server ldap.google.com/216.239.32.58:636: ConnectException(Connection
timed out: connect), ldapSDKVersion=4.0.14, revision=c0fb784eebf9d36a67c736d0428fb3577f2e25bb')<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue"> at com.unboundid.ldap.sdk.LDAPConnectionInternals.<init>(LDAPConnectionInternals.java:185)<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue">Caused by: com.unboundid.ldap.sdk.LDAPException: An error occurred while attempting to establish a connection to server ldap.google.com/216.239.32.58:636: ConnectException(Connection timed out: connect), ldapSDKVersion=4.0.14,
revision=c0fb784eebf9d36a67c736d0428fb3577f2e25bb<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue"> at com.unboundid.ldap.sdk.ConnectThread.getConnectedSocket(ConnectThread.java:269)<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue">Caused by: java.net.ConnectException: Connection timed out: connect<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="color:blue"> at java.base/java.net.PlainSocketImpl.waitForConnect(Native Method)</span></i>”<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">ldap.properties <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># LDAP authentication (and possibly attribute resolver) configuration<o:p></o:p></p>
<p class="MsoNormal"># Note, this doesn't apply to the use of JAAS authentication via LDAP<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## Authenticator strategy, either anonSearchAuthenticator, bindSearchAuthenticator, directAuthenticator, adAuthenticator<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.authenticator = bindSearchAuthenticator<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## Connection properties ##<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.ldapURL = ldap://ldap.google.com:636<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.useStartTLS = true<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"># Time in milliseconds that connects will block<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.connectTimeout = PT120S<o:p></o:p></p>
<p class="MsoNormal"># Time in milliseconds to wait for responses<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.responseTimeout = PT120S<o:p></o:p></p>
<p class="MsoNormal"># Connection strategy to use when multiple URLs are supplied, either ACTIVE_PASSIVE, ROUND_ROBIN, RANDOM<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.connectionStrategy = ACTIVE_PASSIVE<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.sslConfig = certificateTrust<o:p></o:p></p>
<p class="MsoNormal">## If using certificateTrust above, set to the trusted certificate's path<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.trustCertificates = %{idp.home}/credentials/ldap-client.p12<o:p></o:p></p>
<p class="MsoNormal">## If using keyStoreTrust above, set to the truststore path<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.trustStore = %{idp.home}/credentials/ldap-server.truststore<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## Return attributes during authentication<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.returnAttributes = passwordExpirationTime,loginGraceRemaining<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">## DN resolution properties ##<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># Search DN resolution, used by anonSearchAuthenticator, bindSearchAuthenticator<o:p></o:p></p>
<p class="MsoNormal"># for AD: CN=Users,DC=example,DC=org<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.baseDN = ou=Users,dc=example,dc=edu,dc=om<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.subtreeSearch = false<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.userFilter = (uid={user})<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">idp.authn.LDAP.userFilter = (sAMAccountName={uid})<o:p></o:p></p>
<p class="MsoNormal"># bind search configuration<o:p></o:p></p>
<p class="MsoNormal"># for AD: <a href="mailto:idp.authn.LDAP.bindDN=adminuser@domain.com">
idp.authn.LDAP.bindDN=adminuser@domain.com</a><o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.bindDN = uid=myservice,ou=<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.bindDN = Myusername<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># Format DN resolution, used by directAuthenticator, adAuthenticator<o:p></o:p></p>
<p class="MsoNormal"># for AD use <a href="mailto:idp.authn.LDAP.dnFormat=%25s@domain.com">
idp.authn.LDAP.dnFormat=%s@domain.com</a><o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.dnFormat = dc=example ,dc=edu,dc=om<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># pool passivator, either none, bind or anonymousBind<o:p></o:p></p>
<p class="MsoNormal">#idp.authn.LDAP.bindPoolPassivator = bind<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"># LDAP attribute configuration, see attribute-resolver.xml<o:p></o:p></p>
<p class="MsoNormal"># Note, this likely won't apply to the use of legacy V2 resolver configurations<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.ldapURL = %{idp.authn.LDAP.ldapURL}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.connectTimeout = %{idp.authn.LDAP.connectTimeout:PT3S}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.responseTimeout = %{idp.authn.LDAP.responseTimeout:PT3S}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.connectionStrategy = %{idp.authn.LDAP.connectionStrategy:ACTIVE_PASSIVE}#<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.baseDN = %{idp.authn.LDAP.baseDN:undefined}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.bindDN = %{idp.authn.LDAP.bindDN:undefined}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.useStartTLS = %{idp.authn.LDAP.useStartTLS:true}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.trustCertificates = %{idp.authn.LDAP.trustCertificates:undefined}<o:p></o:p></p>
<p class="MsoNormal">#idp.attribute.resolver.LDAP.searchFilter = (uid=$resolutionContext.principal)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.ldapURL = %{idp.authn.LDAP.ldapURL}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.connectTimeout = %{idp.authn.LDAP.connectTimeout:PT3S}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.responseTimeout = %{idp.authn.LDAP.responseTimeout:PT3S}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.baseDN = %{idp.authn.LDAP.baseDN:undefined}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.bindDN = %{idp.authn.LDAP.bindDN:undefined}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.useStartTLS = %{idp.authn.LDAP.useStartTLS:false}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.trustCertificates = %{idp.authn.LDAP.trustCertificates:undefined}<o:p></o:p></p>
<p class="MsoNormal">idp.attribute.resolver.LDAP.searchFilter = (uid=$resolutionContext.principal)<i><o:p></o:p></i></p>
<p class="MsoNormal"><span style="font-size:12.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>