Carl, Are you referring to surrogate authentication? https://apereo.github.io/cas/6.4.x/authentication/Surrogate-Authentication.html
Ray On Wed, 2022-05-18 at 16:23 -0400, Carl Waldbieser wrote: Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information. If I have an entry and an alias in an OpenLDAP DIT such that searching on "alias" dereferences "entry", is it possible to configure CAS to perform a 2 stage BIND in this way? I.e. 1. User enters "alias" and password at the CAS login form. 2. CAS searches the DIT with LDAP base "uid=alias,ou=aliases,o=myorg" and a filter like "(objectClass=*)". 3. The actual entry dereferenced has DN "uid=entry,ou=somedepartment,o=myorg". 4. CAS attempts a BIND against this DN with the provided password. It's not obvious from the documentation how one might configure that, or even if it is possible. Thanks, Carl Waldbieser -- Ray Bon Programmer Analyst Development Services, University Systems 2507218831 | CLE 019 | [email protected]<mailto:[email protected]> I acknowledge and respect the lək̓ʷəŋən peoples on whose traditional territory the university stands, and the Songhees, Esquimalt and WSÁNEĆ peoples whose historical relationships with the land continue to this day. -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/868a2f900c274818b9e38f466497d550f92d75a7.camel%40uvic.ca.
