<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi Peter,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Is there a way to tell if the idp.authn.LDAP.usePasswordPolicy = true is active.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Further testing also shows that the LOCKED Account not working as well.</div>
<div id="Signature" class="elementToProof">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
 </div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
regards</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Gary</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<p><span style="font-family: Arial, sans-serif; font-size: 10pt; color: rgb(218, 61, 15);"><b>Gary Lipscomb</b></span></p>
<p><span style="font-family: Arial, sans-serif; font-size: 9pt;">Technical Officer, Systems</span></p>
<p><span style="font-family: Arial, sans-serif; font-size: 9pt;">IT </span><span style="font-family: Arial, sans-serif; font-size: 9pt; color: rgb(65, 65, 65);">Infrastructure & Security | Division of Information Technology</span></p>
<p> </p>
</div>
<div id="appendonsend"></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div id="divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> Lipscomb, Gary <glipscomb@csu.edu.au><br>
<b>Sent:</b> Thursday, 14 November 2024 13:05<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> Re: Expired Password message not displaying. IdP v5</span>
<div> </div>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi Peter,</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
When the password has expired we get our custom bad-password.message  from messages.properties, not the default "Your password has expired" message.</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b>ldap.properties</b></div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
idp.authn.LDAP.authenticator = bindSearchAuthenticator<br>
idp.authn.LDAP.usePasswordPolicy = true</div>
<div style="direction: ltr; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
idp.authn.LDAP.usePasswordExpiration = true</div>
<div style="direction: ltr; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b><br>
</b></div>
<div style="direction: ltr; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b>TRACE output</b></div>
<div style="direction: ltr; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; line-height: 19px; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,738 - 10.0.2.2 - TRACE [net.shibboleth.idp.profile.support.RethrowingFlowHandlerAdapter:405] - Applying default cacheSeconds=0</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,739 - 10.0.2.2 - TRACE [net.shibboleth.idp.profile.support.ProfileRequestContextFlowExecutionListener:62] - Updating ProfileRequestContext in servlet request</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,739 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.csrf.impl.CSRFTokenFlowExecutionListener:155] - Event 'proceed' signaled from view 'DisplayUsernamePasswordPage' requires a CSRF token</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,740 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.csrf.impl.CSRFTokenFlowExecutionListener:180] - Stored (viewScoped) CSRF Token '_adace3b3019d25394f0e3cfd53163b27796c38e1',
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      CSRF Token in HTTP request '_adace3b3019d25394f0e3cfd53163b27796c38e1'</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,742 - 10.0.2.2 - TRACE [net.shibboleth.idp.authn.impl.ValidateCredentials:183] - Profile Action ValidateCredentials: Attempting credential validation via ldap</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,742 - 10.0.2.2 - TRACE [net.shibboleth.idp.authn.AbstractUsernamePasswordCredentialValidator:290] - Credential Validator ldap: Trimming whitespace of input string 'REDACTED_USER'</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,742 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.LDAPCredentialValidator:147] - Credential Validator ldap: Attempting to authenticate user REDACTED_USER</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,742 - 10.0.2.2 - TRACE [net.shibboleth.idp.authn.TemplateSearchDnResolver:242] - resolve user=[org.ldaptive.auth.User@225729519::identifier=REDACTED_USER,
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      context=org.apache.velocity.VelocityContext@57f5c5c9]</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:27,963 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.TemplateSearchDnResolver:278] - Resolved dn=uid=REDACTED_USER,ou=People,o=REDACTED
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      for user=[org.ldaptive.auth.User@225729519::identifier=REDACTED_USER, context=org.apache.velocity.VelocityContext@57f5c5c9]</div>
<div style="direction: ltr; line-height: 19px; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,102 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.LDAPCredentialValidator:173] - Credential Validator ldap: Authentication response [org.ldaptive.auth.AuthenticationResponse@-1282951634</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::authenticationHandlerResponse=[org.ldaptive.auth.AuthenticationHandlerResponse@1428864695</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::connection=org.ldaptive.transport.netty.NettyConnection@2111045129</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::ldapUrl=[org.ldaptive.LdapURL@876348420</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::scheme=ldap, hostname=REDACTED.REDACTED, port=-1, baseDn=null, attributes=null, scope=null, filter=null, inetAddress=null], isOpen=true, connectTime=2024-11-14T01:11:41.705813678Z,
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            connectionConfig=[org.ldaptive.ConnectionConfig@1344972102</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::ldapUrl=ldap://REDACTED.REDACTED, connectTimeout=PT3S, startTLSTimeout=PT3S, responseTimeout=PT3S, reconnectTimeout=PT10S, autoReconnect=true,
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            autoReconnectCondition=ONE_RECONNECT_ATTEMPT, autoReplay=false, sslConfig=[org.ldaptive.ssl.SslConfig@1087228013</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@2f8837b8, trustManagers=null, hostnameVerifier=null, enabledCipherSuites=null, enabledProtocols=null,
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            handshakeCompletedListeners=null, handshakeTimeout=PT1M], useStartTLS=false, connectionInitializers=null, connectionStrategy=[org.ldaptive.ActivePassiveConnectionStrategy@2019751596</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::ldapURLSet=[org.ldaptive.LdapURLSet@1010303001</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::active=[[org.ldaptive.LdapURL@876348420</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::scheme=ldap, hostname=REDACTED.REDACTED, port=-1, baseDn=null, attributes=null, scope=null, filter=null, inetAddress=null]], inactive=[]], activateCondition=DEFAULT_ACTIVATE_CONDITION,
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            retryCondition=DEFAULT_RETRY_CONDITION, initialized=true], connectionValidator=null, transportOptions={}], channel=[id: 0x2731fa11, L:/10.0.2.15:58800 - R:REDACTED.REDACTED/REDACTED.69.157:389],
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            authenticationResultCode=AUTHENTICATION_HANDLER_FAILURE, resultCode=INVALID_CREDENTIALS, matchedDN=, diagnosticMessage=, referralURLs=[], messageID=6,
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            controls=[[org.ldaptive.control.PasswordPolicyControl@1756844979</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::criticality=false, timeBeforeExpiration=-1, graceAuthNsRemaining=-1, error=PASSWORD_EXPIRED]]], resolvedDn=uid=REDACTED_USER,ou=People,o=REDACTED, ldapEntry=org.ldaptive.LdapEntry@165355790</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::messageID=0, controls=[], dn=uid=REDACTED_USER,ou=People,o=REDACTED, attributes=[], accountState=[org.ldaptive.auth.ext.PasswordPolicyAccountState@1945312126</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::accountWarnings=null, </div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            accountErrors=[PASSWORD_EXPIRED]], resultCode=INVALID_CREDENTIALS, </div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            matchedDN=, diagnosticMessage=, referralURLs=[], messageID=6, controls=[[org.ldaptive.control.PasswordPolicyControl@1756844979</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
      ::criticality=false, timeBeforeExpiration=-1, graceAuthNsRemaining=-1, </div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
            error=PASSWORD_EXPIRED]]]</div>
<div style="direction: ltr; line-height: 19px; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,219 - 10.0.2.2 - INFO [net.shibboleth.idp.authn.impl.LDAPCredentialValidator:216] - Credential Validator ldap: Login by 'REDACTED_USER' failed</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
org.ldaptive.LdapException: PASSWORD_EXPIRED:INVALID_CREDENTIALS:</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
        at net.shibboleth.idp.authn.impl.LDAPCredentialValidator.doValidate(LDAPCredentialValidator.java:203)</div>
<div style="direction: ltr; line-height: 19px; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,244 - 10.0.2.2 - TRACE [net.shibboleth.idp.profile.support.RethrowingFlowHandlerAdapter:405] - Applying default cacheSeconds=0</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,244 - 10.0.2.2 - TRACE [net.shibboleth.idp.profile.support.ProfileRequestContextFlowExecutionListener:62] - Updating ProfileRequestContext in servlet request</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,250 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:551] - GetServiceName - looking browser Locales '{}', Falllback locales '{}'</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,250 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:553] - Looking in UI info for Browser Locales</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,251 - 10.0.2.2 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:574] - Found Name 'EASTS qa' for Locale 'en'</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,251 - 10.0.2.2 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:847] - No valid logos which fit found</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,251 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:592] - GetServiceDescription - looking browser Locales '{}', Falllback locales '{}'</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,252 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:594] - Looking in UI info for Browser Locales</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,252 - 10.0.2.2 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:604] - Looking in UI info for Fallback Locales</div>
<div style="direction: ltr; line-height: 19px; white-space: pre; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-11-14 12:17:28,252 - 10.0.2.2 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:619] - Nothing found</div>
<div style="direction: ltr; line-height: 19px; margin: 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="x_Signature" class="x_elementToProof">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
regards</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Gary</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-family: Arial, sans-serif; font-size: 10pt; color: rgb(218, 61, 15);"><b>Gary Lipscomb</b></span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-family: Arial, sans-serif; font-size: 9pt;">Technical Officer, Systems</span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"><span style="font-family: Arial, sans-serif; font-size: 9pt;">IT
</span><span style="font-family: Arial, sans-serif; font-size: 9pt; color: rgb(65, 65, 65);">Infrastructure & Security | Division of Information Technology</span></p>
<p style="margin-top: 0px; margin-bottom: 0px;"> </p>
</div>
<div id="x_appendonsend"></div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="direction: ltr; display: inline-block; width: 98%;">
<div id="x_divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> Thursday, 14 November 2024 01:28<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> Re: Expired Password message not displaying. IdP v5</span>
<div> </div>
</div>
<div style="direction: ltr; font-size: 11pt;">Lipscomb, Gary via users <users@shibboleth.net> [2024-11-13 07:44 CET]:<br>
> 2024-11-13 17:18:35,363 - 10.0.2.2 - INFO [net.shibboleth.idp.authn.impl.LDAPCredentialValidator:216] - Credential Validator ldap: Login by 'user1' failed<br>
> org.ldaptive.LdapException: PASSWORD_EXPIRED:INVALID_CREDENTIALS:<br>
>         at net.shibboleth.idp.authn.impl.LDAPCredentialValidator.doValidate(LDAPCredentialValidator.java:203)<br>
><br>
> Is there an entry in messages.properties or ldap.properties that I need to add to get this to work?<br>
<br>
Unlikely to be the case if<br>
<br>
> The expiring password intercept works.<br>
<br>
but you do have this set in your conf/ldap.properties?<br>
<br>
> idp.authn.LDAP.usePasswordPolicy = true<br>
<br>
See "Account State" on<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505688/LDAPAuthnConfiguration" id="OWA6f80d28e-5377-0440-44fa-c0ecf6c59f27" class="x_OWAAutoLink" data-auth="NotApplicable">https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FIDP5%2Fpages%2F3199505688%2FLDAPAuthnConfiguration&data=05%7C02%7Cglipscomb%40csu.edu.au%7Cdc96584c839f4b3a6e0a08dd03ef73de%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638671049196466833%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=AarS%2F84EuF7iGnywn9umqSbezIUczRcWMeFqVPEG2sE%3D&reserved=0</a><br>
for details. Accoring to that section you'd have to set<br>
  <logger name="net.shibboleth.idp" level="TRACE"/><br>
in conf/logback.xml (and reload-service.sh -id<br>
shibboleth.LoggingService or wait 10min, IIRC) to debug this.<br>
<br>
HTH,<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="OWA71bd4e57-4b55-bd5a-a96d-36501b464fe2" class="x_OWAAutoLink" data-auth="NotApplicable">
https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cglipscomb%40csu.edu.au%7Cdc96584c839f4b3a6e0a08dd03ef73de%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638671049196486905%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Tg%2FFc6qpPxO2Ync4wWWG1lyVJiF3HwktGAMQ4wPmAKI%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div>
<!DOCTYPE html>
<title>Charles Sturt University</title>
<style>p {font-family:arial, helvetica, sans-serif;font-size:9px;}</style>
<p><a href="https://www.csu.edu.au/" style="text-decoration:none;"><img alt="Charles Sturt" style="height:60px;padding:10px;" src="https://www.csu.edu.au/email/images/charles-sturt-logo/charles-sturt-university-logo.png"></a></p>
<hr>
<p style="font-weight:bold">LEGAL NOTICE</p>
<p>This email (including correspondence comprising an email chain and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in
 reliance on it or disclose it to anyone.<br>
Any confidentiality is not waived or lost by reason of mistaken delivery. Any email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email
 transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email
 are not necessarily those of Charles Sturt University.</p>
<p><a style="color:#da3d0f;" href="https://www.csu.edu.au/">Charles Sturt University in Australia</a> The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551). Charles Sturt University - TEQSA Provider Identification: PRV12018
 (Australian University). CRICOS Provider: 00005F.</p>
<p>Consider the environment before printing this email.</p>
</body>
</html>