Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disabling auth from LDAP directory #47

Open
altgilbers opened this issue May 1, 2018 · 2 comments
Open

Disabling auth from LDAP directory #47

altgilbers opened this issue May 1, 2018 · 2 comments

Comments

@altgilbers
Copy link

We have recently enabled this plugin and it is working well. We use an LDAP Synced directory to provision/maintain our user accounts. We had to leave local logins available for users who do not have University credentials.

Our problem is that users can enter their LDAP credentials in the "local login" and be authenticated, bypassing Shibboleth and associated 2FA. Does any know of a way to disable auth from a directory while still keeping it for user provisioning?

Atlassian punted and said to "ask the plugin developer".

@vladimir-mencl-eresearch
Copy link
Contributor

Hi,

The plugin can auto-create the identities when the user logs in - so you might drop the synchronization with the directory and (except for true local accounts), make the shib-auth plugin the only way to log in.

Would this (i.e., disabling the ldap sync) work for you?

Cheers,
Vlad

@altgilbers
Copy link
Author

sorry for the delayed reply...

We have all users provisioned so they can be granted access to spaces before they login. On-the-fly account creation means they need to login first, then someone has to add them to appropriate groups/spaces.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants