Aggregate Authenticator LDAP multiple directories
Ioannis Kakavas
ikakavas at noc.grnet.gr
Wed Jul 15 06:04:02 EDT 2015
Hi Peter,
On 15/07/2015 12:29 μμ, Peter Schober wrote:
> * Ioannis Kakavas <ikakavas at noc.grnet.gr> [2015-07-15 10:01]:
>> My use case is that the IdP needs to be able to authenticate users
>> against two different LDAP directories. The tricky part is that users
>> can be non exclusively in both with the same uid ( but with potentially
>> different password ).
>
> I claim that you can't do that savely. If the two uids happen one day
> to also set the same password the subject controlling uid2 could
> "become" uid1 and have access to hir data/services.
The subject is always the same. I guess you could say that these two
entries in the directory servers are two accounts of one user, and I am
attempting to provide them with passthrough authenication.
>
>> In IDP2 we used to handle this with defining two ds, one sufficient and
>> one requisite in login.conf as follows :
> [...]
>> Any suggestions on how this can be achieved using the
>> aggregateAuthenticator ?
>
> Not literally, but you could continue to use JAAS for authentication
> and thereby use the same login.conf as before.
Thanks, I will roll back to JAAS if I don't find a solution with using
the ldap-authn.
> -peter
>
--
-----------------------------------------------------------
Ioannis Kakavas - ikakavas at grnet.gr
Identity and Access Management Engineer
GRNET Network Operations Centre
Greek Research & Technology Network - http://www.grnet.gr
56, Mesogion Av., Ampelokipi, 11527 Athens, Greece
Office: +30 2107474255
------------------------------------------------------------
More information about the users
mailing list