<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
SOLVED. Thought I'd share the solution.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
I looked at the IdP4 Authentication documentation, and it mentioned the authn folder - so I looked in there on the old server, and checked when files had been modified. One had been modified 2 years ago, not 5 - IdP\conf\authn\password-authn-config.xml.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof ContentPasted0">
Starting at line 29 (on the 4.2.1 install), I copied over the following bean:parent line from the 4.1.5 config same file:<br>
    <!-- Apply any regular expression replacement pairs to username before validation. -->
<div class="ContentPasted0">    <util:list id="shibboleth.authn.Password.Transforms"></div>
<div class="ContentPasted0">            <!--YSJ - enables user to enter username OR email address --></div>
<div class="ContentPasted0">            <bean parent="shibboleth.Pair" p:first="^(.+)@yorksj\.ac\.uk$" p:second="$1" /></div>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof ContentPasted0">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof ContentPasted0">
Tested the change via hosts file, and now the new server will be rolled back in tomorrow (once I've had another user, from the team that raised the issue, test it tomorrow for safety).</div>
<div class="elementToProof">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span class="ContentPasted0 ContentPasted1" style="font-size:12pt;margin:0px;background-color:rgb(255, 255, 255)">This explains why looking for mail and userPrincipalName attribute usage (beyond the resolver file) in the conf folder was futile. I'm not convinced
 I'd have found that via the documentation (now it's been mentioned to me, it seems a reasonably obvious case, as an example).</span><br class="ContentPasted1">
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span class="ContentPasted0" style="font-size:12pt;margin:0px;background-color:rgb(255, 255, 255)"></span><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Dave</div>
<div id="Signature">
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;">_________________________________________________</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;"></span></div>
<table style="border-collapse:collapse;border:none;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;mso-border-insideh:none;mso-border-insidev:none">
<tbody>
<tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:96.45pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt 0cm 5.4pt;height:96.45pt">
<p style="margin:0cm 0cm 8pt;line-height:120%;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<a><b><span style="font-size:10.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes">Dave Perry</span></b></a><span style="mso-bookmark:_Hlk16669093"><span style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB"><br>
</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes">Application Analyst<span style="mso-spacerun:yes">  </span><b>|<span style="mso-spacerun:yes"> 
</span></b>Innovation & Technology Services<br>
<br>
</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-language:EN-GB">York St John University<o:p> </o:p></span></span></p>
<p style="margin:0cm 0cm 8pt;line-height:120%;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-language:EN-GB">Lord Mayor’s Walk, York, YO31 7EX</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><br>
T: +44(0)1904 876 0000<br>
</span></span><a href="mailto:email@yorksj.ac.uk"><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">email@yorksj.ac.uk</span></span></a><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><span style="mso-spacerun:yes"> 
</span><b>|<span style="mso-spacerun:yes">  </span></b></span></span><a href="http://www.yorksj.ac.uk"><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">www.y</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;text-underline:none">orksj</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">.ac.uk</span></span></a><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><o:p> </o:p></span></p>
</td>
</tr>
<tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;height:74.7pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt 0cm 5.4pt;height:74.7pt">
<p style="margin:0cm 0cm 8pt;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<b><span style="font-size:12.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><o:p><img style="max-width:100%" data-outlook-trace="F:1|T:1" src="cid:8949970e-3fb0-43ba-a199-c2a23d0b4b76"> </o:p></span></b></p>
</td>
</tr>
</tbody>
</table>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;"></span></div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Dave Perry via users <users@shibboleth.net><br>
<b>Sent:</b> 24 November 2022 13:22<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Dave Perry <d.perry1@yorksj.ac.uk><br>
<b>Subject:</b> Re: How to allow LDAP lookup via email address as well as samaccountname (AD)</font>
<div> </div>
</div>
<style type="text/css" style="display:none">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<table border="0" cellspacing="0" cellpadding="0" align="left" width="100%">
<tbody>
<tr>
<td style="background:#ffb900; padding:5pt 2pt 5pt 2pt"></td>
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5; padding:5pt 4pt 5pt 12pt; word-wrap:break-word">
<div style="color:#222222"><span style="color:#222; font-weight:bold">Caution:</span> Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
</div>
</td>
</tr>
</tbody>
</table>
<br>
<div>
<div class="x_elementToProof" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
Peter</div>
<div class="x_elementToProof" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
Thanks for the initial response.</div>
<div class="x_elementToProof" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
<br>
</div>
<div class="x_elementToProof x_ContentPasted0" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
The config I copied over, does indeed set adAuthenticator at the top - and already has the line 'idp.authn.LDAP.dnFormat = %s@yorksj.ac.uk'.</div>
<div class="x_elementToProof x_ContentPasted0" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
<br>
</div>
<div class="x_elementToProof x_ContentPasted0" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0); background-color:rgb(255,255,255)">
It's the authentication stage that is failing. If I enter my email address as the username, I specifically get a password error. </div>
<div class="x_elementToProof">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thanks<br>
Dave</div>
<div id="x_Signature">
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:10pt">_________________________________________________</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:10pt"></span></div>
<table style="border-collapse:collapse; border:none">
<tbody>
<tr style="height:96.45pt">
<td width="405" valign="top" style="width:303.75pt; padding:0cm 5.4pt 0cm 5.4pt; height:96.45pt">
<p style="margin:0cm 0cm 8pt; line-height:120%; font-size:11pt; font-family:Calibri,sans-serif; margin-bottom:0cm">
<a><b><span style="font-size:10.0pt; font-family:"Arial",sans-serif">Dave Perry</span></b></a><span style=""><span style="font-size:12.0pt; font-family:"Times New Roman",serif"><br>
</span></span><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">Application Analyst<span style="">  </span><b>|<span style=""> 
</span></b>Innovation & Technology Services<br>
<br>
</span></span><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">York St John University </span></span></p>
<p style="margin:0cm 0cm 8pt; line-height:120%; font-size:11pt; font-family:Calibri,sans-serif; margin-bottom:0cm">
<span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">Lord Mayor’s Walk, York, YO31 7EX</span></span><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif"><br>
T: +44(0)1904 876 0000<br>
</span></span><a href="mailto:email@yorksj.ac.uk"><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">email@yorksj.ac.uk</span></span></a><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif"><span style=""> 
</span><b>|<span style="">  </span></b></span></span><a href="http://www.yorksj.ac.uk"><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">www.y</span></span><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">orksj</span></span><span style=""><span style="font-size:9.0pt; font-family:"Arial",sans-serif">.ac.uk</span></span></a><span style="font-size:9.0pt; font-family:"Arial",sans-serif"> </span></p>
</td>
</tr>
<tr style="height:74.7pt">
<td width="405" valign="top" style="width:303.75pt; padding:0cm 5.4pt 0cm 5.4pt; height:74.7pt">
<p style="margin:0cm 0cm 8pt; font-size:11pt; font-family:Calibri,sans-serif; margin-bottom:0cm">
<b><span style="font-size:12.0pt; font-family:"Arial",sans-serif"><img style="max-width:100%" data-outlook-trace="F:2|T:2" src="cid:0c348a8d-a53d-4389-aa10-d0dc44c626d1"> </span></b></p>
</td>
</tr>
</tbody>
</table>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:10pt"></span></div>
</div>
</div>
</div>
<div id="x_appendonsend"></div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> 24 November 2022 12:36<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> Re: How to allow LDAP lookup via email address as well as samaccountname (AD)</font>
<div> </div>
</div>
<div class="x_BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="x_PlainText">Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.<br>
<br>
<br>
* Dave Perry via users <users@shibboleth.net> [2022-11-24 12:45]:<br>
> Looking at the old ldap.properties file (which was pasted in over<br>
> the stock 4.2.1.1 installed one) [...]<br>
<br>
So you did a "fresh" install of the current software and are now<br>
trying to make it behave as before by copying back some of the config<br>
files?  At least I can't see why copying over the old config over the<br>
"stock" one would have been necesssary otherwise.<br>
<br>
> the LDAP filter:<br>
> idp.authn.LDAP.userFilter= (sAMAccountName={user})<br>
><br>
> No mention of UPN, or mail, in that file.<br>
><br>
> I tried the following filter rule, to no avail (it didn't stop samaccountname logins working, just didn't pick up the email address ones):<br>
> idp.authn.LDAP.userFilter= (| (sAMAccountName={user}) (userPrincipalName={user}) )<br>
<br>
The first thing you'd need to decide (or determine) is what<br>
"authenticator strategy" to use (or is configured). Since your LDAP<br>
server implementation is M$-AD that (idp.authn.LDAP.authenticator =<br>
adAuthenticator) would be an obvious choice.<br>
<br>
That then determines whether the idp.authn.LDAP.userFilter setting is<br>
even used at all. With the adAuthenticator it's /not/ used for<br>
authentication, that instead relies on a M$-proprietary extension<br>
using direct lookups configured with the idp.authn.LDAP.dnFormat (note<br>
the comments above all of thesesettings), e.g.<br>
<br>
idp.authn.LDAP.dnFormat = %s@yorksj.ac.uk  # your domain<br>
<br>
Note that depending on your LDAP DataConnector configuration you may<br>
still need to configure an LDAP search filter in the property<br>
"idp.attribute.resolver.LDAP.searchFilter" (a bit further below in<br>
your ldap.properties). That's about attribute lookups and not<br>
authentication and so needs to be set correctly even using the<br>
adAuthenticator, e.g.:<br>
idp.attribute.resolver.LDAP.searchFilter = (|(sAMAccountName=$resolutionContext.principal)(userPrincipalName=$resolutionContext.principal))<br>
<br>
HTH,<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cd.perry1%40yorksj.ac.uk%7C5d776fb7de49461d4b4408dace1f057a%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638048929869697495%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=msVTwwatWf6q9w3Iez7jzM3hZbpBRbfOR9tE7izFSVs%3D&reserved=0" originalsrc="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" shash="OCf6t6UIGzn5YUD+trBBZ6etIHLmGQTMjZ175wC6bZKSBWenTIIRRaaWgOx+dvLWmhEO9BLHgMUC7TeMKcwiBINTgqq00yTmoOM4MdnM5LmkygjI2f0QS/637mCEBC5wIu1gF/1DSL5ju9Z1FHFf9pYFlFsOhzydpXLQWFGCnyc=">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&amp;data=05%7C01%7Cd.perry1%40yorksj.ac.uk%7Cd17076e2fc204f4fa8b908dace188cab%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638048902071881728%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=HBoMoScKzjsxrFbn4rWqJXnChPAxtGAu5Jx8R%2FsdAA4%3D&amp;reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</div>
</body>
</html>