Shibboleth IdP v3.2.1 & LDAP+AD Authentication

IAM David Bantz dabantz at alaska.edu
Wed Jun 22 13:33:06 EDT 2016


To be pedantic and check my understanding of Daniel's reply:
 if configured to check Directories A and B, and either or both may contain
a user's record,
and the result in either is 0 (not found) + (succeed) or - (fail) the mixed
cases are:

[image: Inline image 4]

Or did you mean by "The DN resolver will throw" that something even more
dramatic?

David Bantz






On Wed, Jun 22, 2016 at 6:06 AM, Daniel Fisher <dfisher at vt.edu> wrote:

> On Tue, Jun 21, 2016 at 6:32 PM, Michael A Grady <mgrady at unicon.net>
> wrote:
>
>> If one does aggregate DN resolvers/authn handlers, what happens if the
>> user is found in both, but authentication succeeds in one and fails in the
>> other?
>>
>
> Only one authentication event occurs. The DN resolver will throw by
> default if more than one DN is found. If you configure it to allow multiple
> DNs, the first one found in the underlying collection will be used.
>
> --Daniel Fisher
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160622/d7f26d6e/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/png
Size: 22680 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20160622/d7f26d6e/attachment-0001.png>


More information about the users mailing list