Generic LDAP Authentication Failure Mapper
Description
Maps messages returned in LDAP exceptions (in the case of bind failures) to authentication result types. Known Active Directory error message snippets are:
- data 525 - user not found
- data 52e - invalid credentials
- data 530 - not permitted to logon at this time
- data 531 - not permitted to logon at this workstation
- data 532 - password expired
- data 533 - account disabled
- data 701 - account expired
- data 773 - user must reset password
- data 775 - user account locked
May be used by
Properties
Password Change Enforced (
passwordChangeEnforced) Description
If defined, the string specified in this property is compared against the exception message returned when authentication fails. If the exception message contains the string specified here, the authentication result is PASSWORD_CHANGE_ENFORCED (rather than PASSWORD_WRONG).
For the Microsoft Active Directory, the value "data 773" has proven to be a good value.
Attributes
String
Optional
Example
data 773
User Locked (
userLocked) Description
If defined, the string specified in this property is compared against the exception message returned when authentication fails. If the exception message contains the string specified here, the authentication result is USER_LOCKED (rather than PASSWORD_WRONG).
Attributes
String
Optional
Example
data 775
User Invalid (
userInvalid) Description
If defined, the string specified in this property is compared against the exception message returned when authentication fails. If the exception message contains the string specified here, the authentication result is USER_INVALID (rather than PASSWORD_WRONG).
For the Microsoft Active Directory, the value "data 701" has proven to be a good value.
Attributes
String
Optional
Example
data 701
Credential Inactive (
credentialInactive) Description
If defined, the string specified in this property is compared against the exception message returned when authentication fails. If the exception message contains the string specified here, the authentication result is CREDENTIAL_INACTIVE (rather than PASSWORD_WRONG).
For the Microsoft Active Directory, the value "data 530" has proven to be a good value.
Attributes
String
Optional
Example
data 730
YAML Template (with default values)
type: GenericLdapAuthenticationFailureMapper
id: GenericLdapAuthenticationFailureMapper-xxxxxx
displayName:
comment:
properties:
credentialInactive:
passwordChangeEnforced:
userInvalid:
userLocked: