ldap.properties and ldap for attribute-resolver
Lipscomb, Gary
glipscomb at csu.edu.au
Tue Dec 12 16:24:53 EST 2017
We access our ldap servers through a load balancer, makes configurations so much easier for all applications. Maintenance of the ldap serves then becomes a non event for the accessing applications, all handled via the load balancer.
Regards
Gary
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Joseph
> Fischetti
> Sent: Wednesday, 13 December 2017 06:03
> To: users at shibboleth.net
> Subject: ldap.properties and ldap for attribute-resolver
>
> I'm exploring other configuration options for ldap authn and attribute
> resolution.
>
> The data connector within attribute-resolver.xml can be set up with a space
> delimited list of ldap URLs per the documentation here [1].
> ldapURL - Space-delimited list of URLs - URL(s) to the LDAP server.
> Each listed URL is tried according to the connectionStrategy.
> I believe it would also be acceptable (though maybe unnecessary? ) to define
> a backup data connector instead. Which is preferable?
>
> Also, can ldap.properties be configured the same way?
> This [2] page gives the following description for the ldap.properties file:
> idp.authn.LDAP.ldapURL - LDAP URL - "Connection URI for LDAP directory"
>
> I put a dummy url (first) in a space separated list in ldap.properties and the
> configuration starts up and works fine, but that doesn't mean anything.
>
> Whats the right way to have failover ldap servers for both authn and
> attribute resolution?
>
> ------------------------------
> [1] https://wiki.shibboleth.net/confluence/display/IDP30/LDAPConnector
> [2]
> https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfigurat
> ion
>
>
>
>
>
> Joseph Fischetti
> Linux System Administrator
> Marist College
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net
More information about the users
mailing list