<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p><br>
</p>
<meta content="text/html; charset=UTF-8">
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size: 12pt; color: rgb(0, 0, 0); font-family: Calibri, Helvetica, sans-serif, "EmojiFont", "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols;">
<p>Dear Peter,</p>
<p><br>
</p>
<p>many thanks for your reply.</p>
<p><br>
</p>
<p>in ldap.properties we have</p>
<p><span>idp.authn.LDAP.dnFormat                         = %s@ista.ac.at</span><br>
</p>
<p><span>idp.authn.LDAP.baseDN                           = dc=ista,dc=ac,dc=at</span><br>
</p>
<p><span>idp.authn.LDAP.userFilter                       = (sAMAccountName={user})</span></p>
<p><span><br>
</span></p>
<p><span>I have tested with a few users and the message appears for everyone.<br>
</span></p>
<p><span>Attribute resolver is working, aacli shows all the attributes.</span></p>
<p><span><br>
</span></p>
<p><span><font size="2"><span style="font-size:10pt">> INVALID_DN_SYNTAX (coming from your LDAP server) still seems clear?</span></font><br>
</span></p>
<p>I'm not sure what do you mean? <br>
</p>
<p><br>
</p>
<p>Best,<br>
</p>
<div id="x_Signature">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:rgb(0,0,0); font-family:Calibri,Helvetica,sans-serif,"EmojiFont","Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols">
<p><span lang="en-US"></span></p>
<div style="margin:0"><font face="Calibri,sans-serif" size="2" style="font-family:Calibri,sans-serif,serif,"EmojiFont""><span style="font-size:11pt"><font size="2"><span style="font-size:8.5pt"><b>David Stava</b></span></font></span></font></div>
<br>
<p></p>
</div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> Tuesday, April 2, 2024 5:19:56 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Cc:</b> Peter Schober<br>
<b>Subject:</b> Re: ldap warning "Unsuccessful search response" after upgrade to IDP 5</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt">
<div class="PlainText">Peter Schober via users <users@shibboleth.net> [2024-04-02 17:14 CEST]:<br>
> David Stava via users <users@shibboleth.net> [2024-04-02 17:00 CEST]:<br>
> > org.ldaptive.LdapException: Error resolving entry for<br>
> >     username@domain. Unsuccessful search response:<br>
> >     org.ldaptive.SearchResponse@1220993256::messageID=2,<br>
> >     controls=[], resultCode=INVALID_DN_SYNTAX, matchedDN=,<br>
> >     diagnosticMessage=0000208F: NameErr: DSID-03100233, problem 2006<br>
> >     (BAD_NAME), data 8350, best match of:<br>
> >     'username@domain'<br>
> <br>
> What is your idp.authn.LDAP.authenticator property currently set to<br>
> (in conf/ldap.properties)?<br>
<br>
Sorry, I skipped over that where you already wrote:<br>
<br>
> when using password authentication with ldap adAuthenticator<br>
<br>
INVALID_DN_SYNTAX (coming from your LDAP server) still seems clear?<br>
<br>
Besides idp.authn.LDAP.authenticator=adAuthenticator what are the<br>
values of other relevant settings (e.g. idp.authn.LDAP.dnFormat)?<br>
Does the above exception occur with any/all user names or just with<br>
some?  Does the resover work using those same user names, e.g. using<br>
aacli?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="LPlnk826438" previewremoved="true">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>