How to perform Conditional Authentication from LDAP and SQL based on SP name or any value?

Peter Schober peter.schober at univie.ac.at
Tue May 15 12:16:20 EDT 2018


* dalipcse91 <dalipcse91 at gmail.com> [2018-05-15 16:31]:
> Is there any way to tell shibboleth to use sql or ldap for
> authentication based on entered user email's domain name ?

Probably not (easily) when using JAAS.

Personally I'd try to work around my Identity Management mess so that
I can provide a unified interface to all serices, not just the
Shibboleth IDP.

Also expecting people to understand that they'd have to use credential
set A when accessing services of type X, Y or Z, but credential set B
when accessing services 1, 2 or 3 seems highly confusing and prone to
errors.
Add SSO on top of that that this becomes fully futile, IMO.

-peter


More information about the users mailing list