IDPv3.1.2 LDAP connector: using two distinct LDAP servers?
Brady, Jason W
jbrady at sbccd.cc.ca.us
Mon Jun 27 11:59:48 EDT 2016
On 6/24/16, 7:55 PM, "users on behalf of Raymond Gardner" <users-bounces at shibboleth.net on behalf of r.gardner at ntta.com<mailto:users-bounces at shibboleth.net%20on%20behalf%20of%20r.gardner at ntta.com>> wrote:
> My experience is that it requires successful authentication against both directories configured.
We are currently using this configuration and my experience is it doesn't require authentication against both directories. Well, based on the Active Directory example (https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-ExamplefortwoActiveDirectorieswithtwoDNResolversforeach) and only in live starting this month.
In what test did you experience this? I was able to login in with accounts from either directory.
We have two Active Directory domains in the same forest, but use separate bind credentials and servers for each domain. Our setup makes sure to not have the same username in both domains. I noticed that this caused an issue in v2 when using JAAS.
However, do note that the generic Multiple Directories example and the Active Directory example are not exactly the same. I removed the extra resolvers in our config. With that change they seem to be equivalent (though the generic seems to have updated syntax?).
Jason Brady * Web Developer * San Bernardino Community College District *
1289 Bryn Mawr Ave, Suite B, Redlands, CA 92374 *
Tel 909-384-8691 * Mobile 951-295-9515 * Fax 909-796-6579 * jbrady at sbccd.cc.ca.us<mailto:jbrady at sbccd.cc.ca.us>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160627/c614708e/attachment-0001.html>
More information about the users
mailing list