On Sat, 16 Jan 2016, YunQiang Su wrote:
Hi,
http://www.udel.edu/it/help/CAS/usernames.html
says that they can login with both email and uid etc to login.
I am wonder how to archive this?
I cannot find any documents about this.
We do something similar here. Our CAS server authenticates against LDAP.
We changed the filter to be:
<!-- The query made to find the Principal ID. "%u" will be replaced by the
resolved Principal -->
<property name="filter" value="(|(uid=%u)(eduPersonPrincipalName=%u))" />
"%u" is whatever the person typed into the username field of the web form.
We check it against both uid (bare username) and against
eduPersonPrincipalName ([email protected]).
Just make sure your search filter can only return 1 entry. Don't search
against an attribute that could match multiple entries.
Andy