Aggregate Authenticator LDAP multiple directories

Ioannis Kakavas ikakavas at noc.grnet.gr
Wed Jul 15 06:04:02 EDT 2015


Hi Peter,

On 15/07/2015 12:29 μμ, Peter Schober wrote:
> * Ioannis Kakavas <ikakavas at noc.grnet.gr> [2015-07-15 10:01]:
>> My use case is that the IdP needs to be able to authenticate users
>> against two different LDAP directories. The tricky part is that users
>> can be non exclusively in both with the same uid ( but with potentially
>> different password ).
> 
> I claim that you can't do that savely. If the two uids happen one day
> to also set the same password the subject controlling uid2 could
> "become" uid1 and have access to hir data/services.
The subject is always the same. I guess you could say that these two
entries in the directory servers are two accounts of one user, and I am
attempting to provide them with passthrough authenication.

> 
>> In IDP2 we used to handle this with defining two ds, one sufficient and
>> one requisite in login.conf as follows :
> [...]
>> Any suggestions on how this can be achieved using the
>> aggregateAuthenticator ?
> 
> Not literally, but you could continue to use JAAS for authentication
> and thereby use the same login.conf as before.

Thanks, I will roll back to JAAS if I don't find a solution with using
the ldap-authn.

> -peter
> 

-- 
-----------------------------------------------------------
Ioannis Kakavas - ikakavas at grnet.gr
Identity and Access Management Engineer
GRNET Network Operations Centre
Greek Research & Technology Network - http://www.grnet.gr
56, Mesogion Av., Ampelokipi, 11527 Athens, Greece
Office: +30 2107474255
------------------------------------------------------------


More information about the users mailing list