<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hello,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
this is a new server with shibboleth and i'm only one person that configures and tests it so i'm 100% sure that i manually typed username without any non-printable characters.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
As per advice i went through all configuraton files that i could have modified previously using vi in :set list   mode - and i removed all ^I characters.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
To my surprise - that eventually solved the problem and now our new shibboleth server is working fine.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Unfortunately, i've removed many ^I characters at once so i don't know exactly which were crucial to fix the problem...</div>
<div id="Signature" class="elementToProof">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<p class="elementToProof" style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Verdana, sans-serif; font-size: 10pt; color: rgb(51, 51, 51); background-color: white;">Best regards,</span></p>
<div class="elementToProof" style="margin: 0cm; font-family: Verdana, sans-serif; font-size: 10pt; color: rgb(51, 51, 51);">
<span style="background-color: white;">Marcin</span></div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Scott Cantor via users <users@shibboleth.net><br>
<b>Sent:</b> Tuesday, July 28, 2026 9:24 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Scott Cantor <scott@restingparrotsoftware.com><br>
<b>Subject:</b> Re: problem with adAuthenticator - non printable characters added to username</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Ta wiadomość jest wysłana spoza domeny WUM.<br>
Jeśli nie jest od zaufanego nadawcy, Bądź Ostrożny w otwieraniu załączników i klikaniu na linki.<br>
<br>
> On Jul 28, 2026, at 3:11 PM, Peter Schober via users <users@shibboleth.net> wrote:<br>
><br>
> Scott Cantor via users <users@shibboleth.net> [2026-07-28 18:38 CEST]:<br>
>> The obvious inference is that the user is entering it and no cleanup<br>
>> is being done to prevent them from getting through to that step.<br>
><br>
> Not all that easy getting linefeed, tab and esp NUL byte chars entered<br>
> into a username form field. Password manager run amok?<br>
<br>
I don't even pretend to wonder how users do some of the stuff they manage to do anymore. A screen scraper (they call it AI now) is a possibility I guess.<br>
<br>
I'm just saying, what else is even possible here? We don't mess with the value unless it's configured to mess with the value. If it's not the client, then the web server is corrupting it I guess.<br>
<br>
Notably, this is not attribute resolution. The LDAP authenticator classes are only used during authentication and the log trace there is pretty clear about it being the authenticator.<br>
<br>
We probably have some AD-related settings I don't know about in the resolver perhaps, but that class is not part of that step.<br>
<br>
-- Scott<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>