One IdP serving separate security (LDAP) domains

Cantor, Scott cantor.2 at osu.edu
Fri Apr 5 10:10:50 EDT 2013


On 4/5/13 3:41 AM, "Mosior, Benjamin" <BEMosior at ship.edu> wrote:
>
>For anyone encountering this scenario in the future:
>1) There are inherent design and performance issues with the failover
>method. If possible and appropriate, an effort should be made to join the
>different authentication sources as part of the overall system design
>(outside of the IdP) or, as Scott mentioned, separate the Shibboleth
>component such that each authentication source is utilized by a separate
>IdP.

Can you elaborate? Any well-performing system on the back-end should make
that a non-issue. I use failover extensively in both authn and attribute
lookup and it works fine.

-- Scott




More information about the users mailing list