IDPv3.1.2 LDAP connector: using two distinct LDAP servers?
Daniel Fisher
dfisher at vt.edu
Thu Jun 30 22:53:52 EDT 2016
On Thu, Jun 30, 2016 at 7:42 PM, Raymond Gardner <r.gardner at ntta.com> wrote:
>
> Authentication for login1 fails:
>
> o Successful authentication against LDAP1
>
> o Failed authentication against LDAP2
>
>
>
> Authentication for login2 succeeds:
>
> o Successful authentication against LDAP1 – I don’t understand this;
> this should not be successful as this user does not exist in this LDAP
> instance; I’m positive
>
> o Successful authentication against LDAP2
>
I'd have to see some logs to make sense of this. Only one bind should be
occurring, so this is strange.
>
>
> Let me offer some snippets from my conf/authn/ldap-authn-config.xml file.
> Any assistance will be greatly appreciated:
>
>
>
> <alias
> name="%{idp.authn.custom.LDAP.authenticator:aggregateAuthenticator}"
> alias="shibboleth.authn.custom.LDAP.authenticator" />
>
So are you setting the idp.authn.custom.LDAP.authenticator property or is
the default being used?
> <!—I set the ‘…-ref’ property to this new alias for the bean
> definition of ‘ValidateUsernamePasswordAgainstLDAP’ -->
>
Why did you make that change?
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160630/ff3bd110/attachment.html>
More information about the users
mailing list