<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
{margin-top:0;
margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p><font size="2"><span style="font-size:10pt">> Do you have `idp.authn.LDAP.returnAttributes` set?<br>
> From your logs it looks like the EntryResolver is running and that should only happen if you’re asking for additional attributes at authentication.<br>
>If you do in fact need returnAttributes, I don’t believe the dnFormat configuration will work with that type of format.<br>
> In that case, you’d need to switch to using bindSearchAuthenticator with AD.<br>
</span></font></p>
<p><br>
</p>
<p>Dear Daniel,</p>
<p><br>
</p>
<p>yes, we have <font size="2"><span style="font-size:10pt">idp.authn.LDAP.returnAttributes</span></font> set. When I comment it out the message disappears. Many thanks for the hint! I will check whether to keep it and switch to
<font size="2"><span style="font-size:10pt">bindSearchAuthenticator</span></font>.<br>
</p>
<p><br>
</p>
<div id="x_Signature">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:rgb(0,0,0); font-family:Calibri,Helvetica,sans-serif,"EmojiFont","Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols">
<p><span lang="en-US"></span></p>
<div style="margin:0"><font face="Calibri,sans-serif" size="2" style="font-family:Calibri,sans-serif,serif,"EmojiFont""><span style="font-size:11pt"><font size="2"><span style="font-size:8.5pt"><b>David Stava</b></span></font></span></font></div>
<br>
<p></p>
</div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Fisher, Daniel via users <users@shibboleth.net><br>
<b>Sent:</b> Wednesday, April 3, 2024 1:31:12 PM<br>
<b>To:</b> Shib Users<br>
<b>Cc:</b> Fisher, Daniel<br>
<b>Subject:</b> Re: ldap warning "Unsuccessful search response" after upgrade to IDP 5</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText"><br>
> On Apr 3, 2024, at 4:02 AM, David Stava via users <users@shibboleth.net> wrote:<br>
> <br>
> <br>
> Dear Peter,<br>
> <br>
> many thanks for your reply.<br>
> <br>
> in ldap.properties we have<br>
> idp.authn.LDAP.dnFormat = %s@ista.ac.at<br>
> idp.authn.LDAP.baseDN = dc=ista,dc=ac,dc=at<br>
> idp.authn.LDAP.userFilter = (sAMAccountName={user})<br>
> <br>
<br>
Do you have `idp.authn.LDAP.returnAttributes` set?<br>
From your logs it looks like the EntryResolver is running and that should only happen if you’re asking for additional attributes at authentication.<br>
If you do in fact need returnAttributes, I don’t believe the dnFormat configuration will work with that type of format.<br>
In that case, you’d need to switch to using bindSearchAuthenticator with AD.<br>
<br>
—Daniel Fisher<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>