So it seems the format string property is not being resolved:

> [org.ldaptive.auth.FormatDnResolver] - Formatting DN for myuser with 
> ${ldap.authn.searchFilter}
> [org.ldaptive.auth.Authenticator] - <authenticate 
> dn=${ldap.authn.searchFilter} with ...

The issue looks to have been identified/covered during earlier development:

  https://github.com/vt-middleware/ldaptive/issues/28

with the workaround being to 'bake in' part of the %s substitution string:

   cn=%s,${ldap.baseDn}

Or similar.

If I have to bake in the RDN attribute name (cn=%s), then (to me) the
substitution isn't entirely useful, and I may as well 'bake in' the rest
of the format string (my RDN is uid). Funny, it does resolve the
${ldap.url} property, though.

Perhaps for certain aspects of the new <ldaptive:foo> authentication
config it makes sense to go back to the earlier configuration style:

>     <bean id="authenticator" class="org.ldaptive.auth.Authenticator"
>           c:resolver-ref="dnResolver"
>           c:handler-ref="authHandler" />
etc.

Thanks.
Tom.

On 01/20/2016 04:26 PM, Tom Poage wrote:
> I'm working out LDAP direct bind with 4.2.0 RC1.
> 
> Relying on mostly default ldaptive configuration, the following works
> when I directly wire in the bind DN format arguments:
> 
> <ldaptive:direct-authenticator id="authenticator"
>     format="uid=%1$s,ou=...,dc=ucdavis,dc=edu"
>     ldapUrl="${ldap.url}" />
> 
> Try as I might, I can't seem to come up with the magic escaping
> incantation on the format (searchFilter) to make the documented way of
> doing this work:
> 
> <ldaptive:direct-authenticator id="authenticator"
>     format="${ldap.authn.searchFilter}"
>     ldapUrl="${ldap.url}" />
> 
> These properties are in cas.properties.
> 
> Any hints? I've tried HTML character encodings, UTF-8 encoding, layers
> of backslashes, all to no avail (I'm no Java/Spring/... expert).
> 
> Thanks for any assistance!
> 
> Tom.
> 

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to