On Sat, 16 Jan 2016, YunQiang Su wrote:

Hi,
http://www.udel.edu/it/help/CAS/usernames.html

says that they can login with both email and uid etc to login.

I am wonder how to archive this?
I cannot find any documents about this.

We do something similar here. Our CAS server authenticates against LDAP. We changed the filter to be:

<!-- The query made to find the Principal ID. "%u" will be replaced by the 
resolved Principal -->
<property name="filter" value="(|(uid=%u)(eduPersonPrincipalName=%u))" />

"%u" is whatever the person typed into the username field of the web form. We check it against both uid (bare username) and against eduPersonPrincipalName ([email protected]).

Just make sure your search filter can only return 1 entry. Don't search against an attribute that could match multiple entries.

        Andy

Reply via email to