Suggestion about Idp ldap configuration

Monica Petrella petrella at istat.it
Tue Nov 20 03:36:28 EST 2018


Good morning, 

could you kindly give us an answer to this question ? 
We have an idp server versin 3.3.2 configured with 2 ldap repository. Each ldap server has different from the other one and 
has his own configuration (base dn, entries, acl, etc.), so we have many applications using idp to authenticate users 
that are located on different ldap. The problem arise when one of the two ldap server is, for example, unavailable. 
When it occurs , if a user that is located into the working ldap server tries to authenticate itself through idp, 
it doesn't work and it receives an error message like "Pool is empty and connection creation failed". 

The question is: 
is it possible to configure idp whith more than one ldap, each different from the other one, in order to handle 
the user's authentication against the other working ldap servers, even if one ldap server wouldn't have been available? 

ldap-authn-config-ldap.xml is configured as describe https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration 
Data connectors in attribute-resolver.xml have validatorRef="shibboleth.NonFailFastValidator" 

Best regards and thank's a lot for any suggestion. 


-- 
Monica Petrella 
ISTAT - Direzione centrale per le tecnologie informatiche e della comunicazione 
Servizio gestione della infrastruttura IT 
telefono: 0646732602 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181120/1c8b3da2/attachment.html>


More information about the users mailing list