<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
Peter</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
Thanks for the initial response.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof ContentPasted0">
The config I copied over, does indeed set adAuthenticator at the top - and already has the line 'idp.authn.LDAP.dnFormat = %s@yorksj.ac.uk'.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof ContentPasted0">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" class="elementToProof ContentPasted0">
It's the authentication stage that is failing. If I enter my email address as the username, I specifically get a password error. </div>
<div class="elementToProof">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks<br>
Dave</div>
<div id="Signature">
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;">_________________________________________________</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;"></span></div>
<table style="border-collapse:collapse;border:none;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;mso-border-insideh:none;mso-border-insidev:none">
<tbody>
<tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:96.45pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt 0cm 5.4pt;height:96.45pt">
<p style="margin:0cm 0cm 8pt;line-height:120%;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<a><b><span style="font-size:10.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes">Dave Perry</span></b></a><span style="mso-bookmark:_Hlk16669093"><span style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB"><br>
</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes">Application Analyst<span style="mso-spacerun:yes">  </span><b>|<span style="mso-spacerun:yes"> 
</span></b>Innovation & Technology Services<br>
<br>
</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-language:EN-GB">York St John University<o:p> </o:p></span></span></p>
<p style="margin:0cm 0cm 8pt;line-height:120%;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-language:EN-GB">Lord Mayor’s Walk, York, YO31 7EX</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><br>
T: +44(0)1904 876 0000<br>
</span></span><a href="mailto:email@yorksj.ac.uk"><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">email@yorksj.ac.uk</span></span></a><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><span style="mso-spacerun:yes"> 
</span><b>|<span style="mso-spacerun:yes">  </span></b></span></span><a href="http://www.yorksj.ac.uk"><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">www.y</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;text-underline:none">orksj</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">.ac.uk</span></span></a><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><o:p> </o:p></span></p>
</td>
</tr>
<tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;height:74.7pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt 0cm 5.4pt;height:74.7pt">
<p style="margin:0cm 0cm 8pt;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<b><span style="font-size:12.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><o:p><img style="max-width:100%" data-outlook-trace="F:1|T:1" src="cid:0c348a8d-a53d-4389-aa10-d0dc44c626d1"> </o:p></span></b></p>
</td>
</tr>
</tbody>
</table>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;"></span></div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> 24 November 2022 12:36<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> Re: How to allow LDAP lookup via email address as well as samaccountname (AD)</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.<br>
<br>
<br>
* Dave Perry via users <users@shibboleth.net> [2022-11-24 12:45]:<br>
> Looking at the old ldap.properties file (which was pasted in over<br>
> the stock 4.2.1.1 installed one) [...]<br>
<br>
So you did a "fresh" install of the current software and are now<br>
trying to make it behave as before by copying back some of the config<br>
files?  At least I can't see why copying over the old config over the<br>
"stock" one would have been necesssary otherwise.<br>
<br>
> the LDAP filter:<br>
> idp.authn.LDAP.userFilter= (sAMAccountName={user})<br>
><br>
> No mention of UPN, or mail, in that file.<br>
><br>
> I tried the following filter rule, to no avail (it didn't stop samaccountname logins working, just didn't pick up the email address ones):<br>
> idp.authn.LDAP.userFilter= (| (sAMAccountName={user}) (userPrincipalName={user}) )<br>
<br>
The first thing you'd need to decide (or determine) is what<br>
"authenticator strategy" to use (or is configured). Since your LDAP<br>
server implementation is M$-AD that (idp.authn.LDAP.authenticator =<br>
adAuthenticator) would be an obvious choice.<br>
<br>
That then determines whether the idp.authn.LDAP.userFilter setting is<br>
even used at all. With the adAuthenticator it's /not/ used for<br>
authentication, that instead relies on a M$-proprietary extension<br>
using direct lookups configured with the idp.authn.LDAP.dnFormat (note<br>
the comments above all of thesesettings), e.g.<br>
<br>
idp.authn.LDAP.dnFormat = %s@yorksj.ac.uk  # your domain<br>
<br>
Note that depending on your LDAP DataConnector configuration you may<br>
still need to configure an LDAP search filter in the property<br>
"idp.attribute.resolver.LDAP.searchFilter" (a bit further below in<br>
your ldap.properties). That's about attribute lookups and not<br>
authentication and so needs to be set correctly even using the<br>
adAuthenticator, e.g.:<br>
idp.attribute.resolver.LDAP.searchFilter = (|(sAMAccountName=$resolutionContext.principal)(userPrincipalName=$resolutionContext.principal))<br>
<br>
HTH,<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&amp;data=05%7C01%7Cd.perry1%40yorksj.ac.uk%7Cd17076e2fc204f4fa8b908dace188cab%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638048902071881728%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=HBoMoScKzjsxrFbn4rWqJXnChPAxtGAu5Jx8R%2FsdAA4%3D&amp;reserved=0">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&amp;data=05%7C01%7Cd.perry1%40yorksj.ac.uk%7Cd17076e2fc204f4fa8b908dace188cab%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638048902071881728%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=HBoMoScKzjsxrFbn4rWqJXnChPAxtGAu5Jx8R%2FsdAA4%3D&amp;reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>