authN password source based on requesting party?
IAM David Bantz
dabantz at alaska.edu
Tue Aug 16 21:19:51 EDT 2016
Is there a way to base the LDAP authN source (this AD/LDAP directory or
that one) based on the service making the request? Preferably using
jaas.config in v3.
(FWIW, the use case is for AD accounts that are set as expired or locked by
the AD team, but who still should have access to a limited range of
services. For these accounts a proxy authenticator is provided with the API
of AD but which delivers a "success" even for these expired or locked
accounts. I don't want to list this authN proxy as the first LDAP for all
cases in a jaas.config, because it's a single point of failure and is only
needed in ~1% of cases; I can't put it after the primary sources because
they will (correctly) report failure before the proxy has its chance. A bad
conflation of authN and authZ perhaps, but there it is.)
David Bantz
UA OIT IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160816/586f0c47/attachment.html>
More information about the users
mailing list