#等待时间(以毫秒为单位) 对于响应
#idp.authn.LDAP.responseTimeout = PT3S
## SSL配置,jvmTrust、certificateTrust或keyStoreTrust
#idp.authn.LDAP.sslConfig = certificateTrust
##如果使用上面的certificateTrust,请设置为受信任证书的路径
idp.authn.LDAP.trustCertificates = %{idp.home}/credentials/ldap-server.crt
##如果使用上述keyStoreTrust,请设置为信任库路径
idp.authn.LDAP.trustStore = %{idp.home}/credentials/ldap-server.truststore
##身份验证期间返回属性
#idp.authn.LDAP.returnAttributes = userPrincipalName、sAMAccountName
idp.authn.LDAP.returnAttributes = *
## DN解析属性##
#搜索DN解析,由anonSearchAuthenticator、bindSearchAuthenticator使用
# 对于广告:CN=Users,DC=example,DC=org
idp.authn.LDAP.baseDN = CN=users,DC=cisco,DC=com
idp.authn.LDAP.subtreeSearch = true
*idp.authn.LDAP.userFilter =(sAMAccountName={user})*
#绑定搜索配置
# 对于广告:idp.authn.LDAP.bindDN=adminuser@domain.com
idp.authn.LDAP.bindDN =管理员@cisco.com
idp.authn.LDAP.bindDNCredential =思科@123
#格式化DN解析,由directAuthenticator和adAuthenticator使用
# 对于AD使用idp.authn.LDAP.dnFormat=%s@domain.com
#idp.authn.LDAP.dnFormat = %s@adfsserver.cisco.com
# LDAP属性配置,请参阅attribute-resolver.xml
#请注意, 此很可能不适用于传统V2解析器配置
idp.attribute.resolver.LDAP.ldapURL = %{idp.authn.LDAP.ldapURL}
idp.attribute.resolver.LDAP.connectTimeout = %{idp.authn.LDAP.connectTimeout:PT3S}
idp.attribute.resolver.LDAP.responseTimeout = %{idp.authn.LDAP.responseTimeout:PT3S}
idp.attribute.resolver.LDAP.baseDN = %{idp.authn.LDAP.baseDN:undefined}
idp.attribute.resolver.LDAP.bindDN = %{idp.authn.LDAP.bindDN:undefined}
idp.attribute.resolver.LDAP.bindDNCredential = %{idp.authn.LDAP.bindDNCredential:undefined}
idp.attribute.resolver.LDAP.useStartTLS = %{idp.authn.LDAP.useStartTLS:true}
idp.attribute.resolver.LDAP.trustCertificates = %{idp.authn.LDAP.trustCertificates:undefined}
idp.attribute.resolver.LDAP.searchFilter =(sAMAccountName=$resolutionContext.principal)