<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p>> <font size="2"><span style="font-size:10pt">Am I correct that you have been sanitising your posts containing<br>
> "user@domain" and that 'domain' really is ista.ac.at or ist.ac.at?</span></font><br>
</p>
<p>> <font size="2"><span style="font-size:10pt">Or does that error msg literally contain the string "user@domain"?<br>
</span></font></p>
<p><font size="2"><span style="font-size:10pt"><br>
</span></font></p>
<p><font size="2"><span style="font-size:10pt">It's not literal user@domain. It contains the "actual-username@ista.ac.at"<br>
</span></font></p>
<p><br>
</p>
<p>> <font size="2"><span style="font-size:10pt">From the config you posted there's no apparent invalid DN syntax so I<br>
> guess that leaves what Scott said wrt ldap-authn-config.xml.</span></font><br>
</p>
<p><br>
</p>
<p>I got rid of ldap-authn-config.xml by using the default <span>password-authn-config.xml</span> from the IDP 5 installation. If there are other config files involved please let me know.<br>
</p>
<p><br>
</p>
<p>Thanks for pointing out the LDAP result code 34, I will check if there might be some issue on the AD.<br>
</p>
<p><br>
</p>
<div id="x_Signature">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:rgb(0,0,0); font-family:Calibri,Helvetica,sans-serif,"EmojiFont","Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols">
<p><span lang="en-US"></span></p>
<div style="margin:0"><font face="Calibri,sans-serif" size="2" style="font-family:Calibri,sans-serif,serif,"EmojiFont""><span style="font-size:11pt"><font size="2"><span style="font-size:8.5pt"><b>David Stava</b></span></font></span></font></div>
<div style="margin:0"><font face="Calibri,sans-serif" size="2" style="font-family:Calibri,sans-serif,serif,"EmojiFont""><span style="font-size:11pt"><font size="2"><span style="font-size:8.5pt"><br>
</span></font></span></font></div>
<br>
<p></p>
</div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> Wednesday, April 3, 2024 12:29:06 PM<br>
<b>To:</b> Shib Users<br>
<b>Cc:</b> Peter Schober<br>
<b>Subject:</b> Re: ldap warning "Unsuccessful search response" after upgrade to IDP 5</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">David Stava <David.Stava@ist.ac.at> [2024-04-03 10:02 CEST]:<br>
> in ldap.properties we have<br>
<br>
Those look fine to me.<br>
<br>
> > INVALID_DN_SYNTAX (coming from your LDAP server) still seems clear?<br>
> <br>
> I'm not sure what do you mean?<br>
<br>
I just meant that as an error message result code 34 is quite<br>
specific. Also I was thinking that "user@domain" literally isn't a<br>
valid LDAP Distinguished Name (cf. RFC 4514) but then this error code<br>
comes from the M$ implementation and those allows for DNs of such<br>
format.<br>
<br>
Am I correct that you have been sanitising your posts containing<br>
"user@domain" and that 'domain' really is ista.ac.at or ist.ac.at?<br>
Or does that error msg literally contain the string "user@domain"?<br>
(Sanitising the user-specific part is of course fine.)<br>
<br>
> Error resolving entry for username@domain. Unsuccessful search response:<br>
> org.ldaptive.SearchResponse@1220993256::messageID=2, controls=[],<br>
> resultCode=INVALID_DN_SYNTAX, matchedDN=, diagnosticMessage=0000208F:<br>
> NameErr: DSID-03100233, problem 2006 (BAD_NAME), data 8350<br>
<br>
To me the main thing here is LDAP Result Code 34<br>
("INVALID_DN_SYNTAX"), but there's quite a bit of additional<br>
information above added by the server (starting with<br>
"diagnosticMessage") which you'd have to ask the vendor about.<br>
<br>
>From the config you posted there's no apparent invalid DN syntax so I<br>
guess that leaves what Scott said wrt ldap-authn-config.xml.<br>
  Nothing else makes much sense when you've been using the same LDAP<br>
server with earlier versions of the software but using the same<br>
ldap.properties.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>