Multiple LDAP connections

Peter Schober peter.schober at univie.ac.at
Mon Mar 17 09:11:32 EDT 2014


* Prasanna <PVBalachandar at imperosoftware.com> [2014-03-17 13:57]:
> Can we have multiple resolver and login config file in one idp?
> 
> I tried changing in handler xml, doesnt seems to work.

I would think it should be possible to have multiple resolver files
but haven't tried this myself.
Using multiple JAAS config files is possible (I recall e.g. the
Yubikey multi-factor login handler documentation in the Shib wiki
optionally using different login files) but really outside the
Shibboleth IDP.

> Thought of having a separate config file for each entity.

What's an "entity" in this context? You only wrote about connecting
the IDP to 300 LDAP DSAs, so I assumed this is all within a single
organization, resulting in one SAML IDP with one entityID.

Seems this really is about something else, mass-hosting virtualized
SAML IDPs, making one Shibboleth IDP software instance behave as if it
were 300 different IDPs, picking the right LDAP DSA based on the SAML
authentication request, or something along those lines?
-peter


More information about the users mailing list