Shibboleth IdP v3.2.1 & LDAP+AD Authentication

Michael A Grady mgrady at unicon.net
Wed Jun 22 13:22:01 EDT 2016


> On Jun 22, 2016, at 12:16 PM, Michael A Grady <mgrady at unicon.net> wrote:
> 
> 
>> On Jun 22, 2016, at 9:06 AM, Daniel Fisher <dfisher at vt.edu <mailto:dfisher at vt.edu>> wrote:
>> 
>> On Tue, Jun 21, 2016 at 6:32 PM, Michael A Grady <mgrady at unicon.net <mailto:mgrady at unicon.net>> wrote:
>> If one does aggregate DN resolvers/authn handlers, what happens if the user is found in both, but authentication succeeds in one and fails in the other?
>> 
>> Only one authentication event occurs. The DN resolver will throw by default if more than one DN is found. If you configure it to allow multiple DNs, the first one found in the underlying collection will be used.
>> 
>> --Daniel Fisher
>> 
> 
> 
> So, given one configures to allow multiple DNs, the first one found in the collection will then determine which LDAP instance the BIND attempt as the user will be done with, correct?
> 

And, more to the point, if you want the SUFFICIENT behavior of JAAS, you need to use JAAS, you can't easily get it to try the second DN in the collection if the first one chosen "fails"?


--
Michael A. Grady
IAM Architect, Unicon, Inc.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160622/d341ff13/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 842 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://shibboleth.net/pipermail/users/attachments/20160622/d341ff13/attachment.sig>


More information about the users mailing list