IDPv3.1.2 LDAP connector: using two distinct LDAP servers?

Raymond Gardner r.gardner at ntta.com
Fri Jun 24 19:55:03 EDT 2016


On 06/06/16 Etienne Dysli-Metref wrote:

>On 01/06/16 15:29, Guenther Schreiner wrote:

>>  Currently we're trying to use two distinct LDAP server clusters which serve completely independent user groups.

>>  With the help of

>>  https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-AggregateDNResolver

>>  we have tried to setup an IDP providing information of the two user groups.

>

>That link points to the example under "Single Directory with multiple

>branches" which is probably not what you want since you have more than

>one server. Try the next example further down on the same page under

>"Multiple Directories > Aggregate DN Resolver".

>

>  Etienne



We are trying to do the same thing.  I have seen the "Multiple Directories > Aggregate DN Resolver" section.

I tried it out.  My experience is that it requires successful authentication against both directories configured.



We are looking for a setup that attempts one LDAP server 1st, and if it fails then it tries a 2nd LDAP server which will contain a completely different set of users.

If both fail, then authentication fails.  If either binding succeeds then authentication succeeds.



I saw with IDP 2 an example of "stacking" LDAP directories.  This seems to be what we are attempting but the configuration details are completely different with IDP 3.2.1, which is what we are using.  I am currently working on a custom authentication flow.  I have not been able to find an example of this.



Thanks,

Raymond

________________________________
This email message is intended for the use of the person to whom it has been sent, and may contain information that is confidential or legally protected. If you are not the intended recipient or have received this message in error, you are not authorized to copy, distribute, or otherwise use this message or its attachments. Please notify the sender immediately by return e-mail and permanently delete this message and any attachments. NTT America makes no warranty that this email is error or virus free. Thank you.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160624/a7b0dab9/attachment.html>


More information about the users mailing list