Shibboleth IdP v3.2.1 & LDAP+AD Authentication

Marvin Addison marvin.addison at gmail.com
Wed Jun 22 08:01:23 EDT 2016


On Tue, Jun 21, 2016 at 6:33 PM Michael A Grady <mgrady at unicon.net> wrote:

> If one does aggregate DN resolvers/authn handlers, what happens if the
> user is found in both, but authentication succeeds in one and fails in the
> other?
>

The order in which the subordinate directories are searched is
indeterminate since they're performed concurrently, though multiple results
are disallowed by default. That's good default behavior. If you configure
multiple authentication systems of record that don't have namespace
controls, then the behavior when the same user is found in multiple systems
becomes very unclear. Deployers have to think very carefully about the
consequences of advanced configuration like this, and I would argue that in
most cases it's so challenging that it can be a source of self-inflicted
security vulnerabilities. One should allow multiple results only on very
careful analysis.

M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160622/af43104b/attachment.html>


More information about the users mailing list