One IdP serving separate security (LDAP) domains

Cantor, Scott cantor.2 at osu.edu
Fri Apr 5 15:13:10 EDT 2013


On 4/5/13 1:26 PM, "Mosior, Benjamin" <BEMosior at ship.edu> wrote:

>I am also opinionated, so I'm open to your thoughts on the matter.

I don't disagree with anything you wrote, I just thought you had something
more specific in mind.

I would say that the handshaking latency is potentially less an issue than
you might assume. Current versions pool the LDAP connections for attribute
queries, and I'm pretty sure pooling the authentication binds is either
already there or in a later LDAP library version. I can't imagine that
making much difference, again assuming a well-performing back-end.

-- Scott




More information about the users mailing list