Authentication to two ldap directories

Ignacio Amoeiro Bosch ignacio.amoeiro at extern.ibsalut.es
Mon Jun 17 04:25:20 EDT 2019


Hello,

Repplication is not an option. 


The idp-process.log error:

2019-06-14 20:57:44,492 - DEBUG [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:142] - Profile Action ValidateUsernamePasswordAgainstLDAP: Attempting to authenticate user s011741
2019-06-14 20:57:44,492 - DEBUG [org.ldaptive.auth.AggregateDnResolver:177] - submitted DN resolver [org.ldaptive.auth.PooledSearchDnResolver at 2110347044::factory=[org.ldaptive.pool.PooledConnectionFactory at 1324814000::pool=[org.ldaptive.p
ool.BlockingConnectionPool at 208221255::name=adSearch-pool1, poolConfig=[org.ldaptive.pool.PoolConfig at 149330628::minPoolSize=3, maxPoolSize=10, validateOnCheckIn=false, validateOnCheckOut=false, validatePeriodically=true, validatePeriod=30
0, validateTimeout=5000], activator=null, passivator=null, validator=[org.ldaptive.pool.SearchValidator at 1096093049::searchRequest=[org.ldaptive.SearchRequest at -1243745726::baseDn=, searchFilter=[org.ldaptive.SearchFilter at 1642584434::filte
r=(objectClass=*), parameters={}], returnAttributes=[1.1], searchScope=OBJECT, timeLimit=0, sizeLimit=1, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null, searchReferenceHandlers
=null, controls=null, followReferrals=false, intermediateResponseHandlers=null]] pruneStrategy=[org.ldaptive.pool.IdlePruneStrategy at 1086373301::prunePeriod=300, idleTime=600], connectOnCreate=true, connectionFactory=[org.ldaptive.Default
ConnectionFactory at 1011401036::provider=org.ldaptive.provider.jndi.JndiProvider at 65f9a9fa, config=[org.ldaptive.ConnectionConfig at 1218166060::ldapUrl=ldap://adcorp.ssib.es, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ss
l.SslConfig at 529632830::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig at 13145247, trustManagers=null, hostnameVerifier=null, hostnameVerifierConfig=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer at 1220822989::bindDn=shibboleth_apl_user at aplssib, bindSaslConfig=null, bindControls=null]]], initialized=true, availableCount=3, activeCount=0]], baseDn=OU=Usuarios,dc=aplssib, userFilter=(cn={user}), userFilterParameters=null, allowMultipleDns=false, subtreeSearch=true, derefAliases=null, followReferrals=false]
2019-06-14 20:57:44,493 - DEBUG [org.ldaptive.auth.AggregateDnResolver:177] - submitted DN resolver [org.ldaptive.auth.PooledSearchDnResolver at 1914806968::factory=[org.ldaptive.pool.PooledConnectionFactory at 344206717::pool=[org.ldaptive.pool.BlockingConnectionPool at 175686610::name=adSearch-pool2, poolConfig=[org.ldaptive.pool.PoolConfig at 923050641::minPoolSize=3, maxPoolSize=10, validateOnCheckIn=false, validateOnCheckOut=false, validatePeriodically=true, validatePeriod=300, validateTimeout=5000], activator=null, passivator=null, validator=[org.ldaptive.pool.SearchValidator at 2062239471::searchRequest=[org.ldaptive.SearchRequest at -1243745726::baseDn=, searchFilter=[org.ldaptive.SearchFilter at 1642584434::filter=(objectClass=*), parameters={}], returnAttributes=[1.1], searchScope=OBJECT, timeLimit=0, sizeLimit=1, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null, searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null]] pruneStrategy=[org.ldaptive.pool.IdlePruneStrategy at 203377490::prunePeriod=300, idleTime=600], connectOnCreate=true, connectionFactory=[org.ldaptive.DefaultConnectionFactory at 638948346::provider=org.ldaptive.provider.jndi.JndiProvider at 4c67fb7e, config=[org.ldaptive.ConnectionConfig at 165748577::ldapUrl=ldap://sdesldalin1.caib.es, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig at 529632830::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig at 13145247, trustManagers=null, hostnameVerifier=null, hostnameVerifierConfig=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer at 689825939::bindDn=cn=uIBSalut,dc=caib,dc=es, bindSaslConfig=null, bindControls=null]]], initialized=true, availableCount=0, activeCount=0]], baseDn=dc=caib,dc=es, userFilter=(cn={user}), userFilterParameters=null, allowMultipleDns=false, subtreeSearch=false, derefAliases=null, followReferrals=false]
2019-06-14 20:57:44,494 - DEBUG [org.ldaptive.auth.PooledSearchDnResolver:261] - resolve user=[org.ldaptive.auth.User at 585501125::identifier=s011741, context=org.apache.velocity.VelocityContext at 39a65c8a]
2019-06-14 20:57:44,494 - DEBUG [org.ldaptive.auth.PooledSearchDnResolver:343] - searching for DN using userFilter
2019-06-14 20:57:44,495 - DEBUG [org.ldaptive.auth.PooledSearchDnResolver:261] - resolve user=[org.ldaptive.auth.User at 585501125::identifier=s011741, context=org.apache.velocity.VelocityContext at 39a65c8a]
2019-06-14 20:57:44,495 - DEBUG [org.ldaptive.auth.PooledSearchDnResolver:343] - searching for DN using userFilter
2019-06-14 20:57:44,495 - DEBUG [org.ldaptive.SearchOperation:138] - execute request=[org.ldaptive.SearchRequest at -1975327709::baseDn=OU=Usuarios,dc=aplssib, searchFilter=[org.ldaptive.SearchFilter at 1385483104::filter=(cn={user}), parameters={context=org.apache.velocity.VelocityContext at 39a65c8a, user=s011741}], returnAttributes=[1.1], searchScope=SUBTREE, timeLimit=0, sizeLimit=0, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null, searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null] with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection at 169201979::config=[org.ldaptive.ConnectionConfig at 1218166060::ldapUrl=ldap://adcorp.ssib.es, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig at 529632830::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig at 13145247, trustManagers=null, hostnameVerifier=null, hostnameVerifierConfig=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer at 1220822989::bindDn=shibboleth_apl_user at aplssib, bindSaslConfig=null, bindControls=null]], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiConnectionFactory at 394930493::metadata=[ldapUrl=ldap://adcorp.ssib.es, count=1], environment={com.sun.jndi.ldap.connect.timeout=3000, java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig at 2146308497::operationExceptionResultCodes=[PROTOCOL_ERROR, SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy at 6983350c, controlProcessor=org.ldaptive.provider.ControlProcessor at 324a824d, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED, SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null]], providerConnection=org.ldaptive.provider.jndi.JndiConnection at 4f871ec8]
2019-06-14 20:57:44,498 - DEBUG [org.ldaptive.SearchOperation:168] - execute response=[org.ldaptive.Response at 762672365::result=[org.ldaptive.SearchResult at -596631446::entries=[[dn=CN=S011741,OU=Usuarios,DC=aplssib[], responseControls=null, messageId=-1]], references=[]], resultCode=SUCCESS, message=null, matchedDn=null, responseControls=null, referralURLs=null, messageId=-1] for request=[org.ldaptive.SearchRequest at -1975327709::baseDn=OU=Usuarios,dc=aplssib, searchFilter=[org.ldaptive.SearchFilter at 1385483104::filter=(cn={user}), parameters={context=org.apache.velocity.VelocityContext at 39a65c8a, user=s011741}], returnAttributes=[1.1], searchScope=SUBTREE, timeLimit=0, sizeLimit=0, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null, searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null] with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection at 169201979::config=[org.ldaptive.ConnectionConfig at 1218166060::ldapUrl=ldap://adcorp.ssib.es, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig at 529632830::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig at 13145247, trustManagers=null, hostnameVerifier=null, hostnameVerifierConfig=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer at 1220822989::bindDn=shibboleth_apl_user at aplssib, bindSaslConfig=null, bindControls=null]], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiConnectionFactory at 394930493::metadata=[ldapUrl=ldap://adcorp.ssib.es, count=1], environment={com.sun.jndi.ldap.connect.timeout=3000, java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig at 2146308497::operationExceptionResultCodes=[PROTOCOL_ERROR, SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy at 6983350c, controlProcessor=org.ldaptive.provider.ControlProcessor at 324a824d, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED, SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null]], providerConnection=org.ldaptive.provider.jndi.JndiConnection at 4f871ec8]
2019-06-14 20:57:44,498 - DEBUG [org.ldaptive.auth.PooledSearchDnResolver:296] - resolved dn=CN=S011741,OU=Usuarios,DC=aplssib for user=[org.ldaptive.auth.User at 585501125::identifier=s011741, context=org.apache.velocity.VelocityContext at 39a65c8a]
2019-06-14 20:57:44,498 - DEBUG [org.ldaptive.auth.AggregateDnResolver:166] - DN resolver [org.ldaptive.auth.PooledSearchDnResolver at 2110347044::factory=[org.ldaptive.pool.PooledConnectionFactory at 1324814000::pool=[org.ldaptive.pool.BlockingConnectionPool at 208221255::name=adSearch-pool1, poolConfig=[org.ldaptive.pool.PoolConfig at 149330628::minPoolSize=3, maxPoolSize=10, validateOnCheckIn=false, validateOnCheckOut=false, validatePeriodically=true, validatePeriod=300, validateTimeout=5000], activator=null, passivator=null, validator=[org.ldaptive.pool.SearchValidator at 1096093049::searchRequest=[org.ldaptive.SearchRequest at -1243745726::baseDn=, searchFilter=[org.ldaptive.SearchFilter at 1642584434::filter=(objectClass=*), parameters={}], returnAttributes=[1.1], searchScope=OBJECT, timeLimit=0, sizeLimit=1, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null, searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null]] pruneStrategy=[org.ldaptive.pool.IdlePruneStrategy at 1086373301::prunePeriod=300, idleTime=600], connectOnCreate=true, connectionFactory=[org.ldaptive.DefaultConnectionFactory at 1011401036::provider=org.ldaptive.provider.jndi.JndiProvider at 65f9a9fa, config=[org.ldaptive.ConnectionConfig at 1218166060::ldapUrl=ldap://adcorp.ssib.es, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig at 529632830::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig at 13145247, trustManagers=null, hostnameVerifier=null, hostnameVerifierConfig=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer at 1220822989::bindDn=shibboleth_apl_user at aplssib, bindSaslConfig=null, bindControls=null]]], initialized=true, availableCount=3, activeCount=0]], baseDn=OU=Usuarios,dc=aplssib, userFilter=(cn={user}), userFilterParameters=null, allowMultipleDns=false, subtreeSearch=true, derefAliases=null, followReferrals=false] resolved dn CN=S011741,OU=Usuarios,DC=aplssib for user [org.ldaptive.auth.User at 585501125::identifier=s011741, context=org.apache.velocity.VelocityContext at 39a65c8a]
2019-06-14 20:57:47,510 - DEBUG [org.ldaptive.provider.jndi.JndiConnectionFactory:105] - Error connecting to LDAP URL: ldap://sdesldalin1.caib.es
org.ldaptive.provider.ConnectionException: javax.naming.CommunicationException: sdesldalin1.caib.es:389 [Root exception is java.net.SocketTimeoutException: connect timed out]
        at org.ldaptive.provider.jndi.JndiConnectionFactory.createInternal(JndiConnectionFactory.java:102)
Caused by: javax.naming.CommunicationException: sdesldalin1.caib.es:389
        at com.sun.jndi.ldap.Connection.<init>(Connection.java:216)
Caused by: java.net.SocketTimeoutException: connect timed out
        at java.net.PlainSocketImpl.socketConnect(Native Method)
2019-06-14 20:57:47,512 - WARN [org.ldaptive.pool.BlockingConnectionPool:600] - unable to create active connection
2019-06-14 20:57:47,512 - ERROR [org.ldaptive.pool.BlockingConnectionPool:197] - Could not service check out request
2019-06-14 20:57:47,513 - WARN [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:192] - Profile Action ValidateUsernamePasswordAgainstLDAP: Login by s011741 produced exception




As you can see, is failing when trying to resolve the DN of the second LDAP (sdesldalin1.caib.es). It resolves succesfully the DN on the first Directory (resolved dn=CN=S011741,OU=Usuarios,DC=aplssib)

The configuration (ldap-authn-config.xml)

<?xml version="1.0" encoding="UTF-8"?>
<beans xmlns="http://www.springframework.org/schema/beans" xmlns:context="http://www.springframework.org/schema/context" xmlns:util="http://www.springframework.org/schema/util" xmlns:p="http://www.springframework.org/schema/p" xmlns:c="http://www.springframework.org/schema/c" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd                            http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context.xsd                            http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util.xsd" default-init-method="initialize" default-destroy-method="destroy" default-lazy-init="true">

    <alias name="%{idp.authn.LDAP.authenticator}" alias="shibboleth.authn.LDAP.authenticator"/>
    <bean id="shibboleth.authn.LDAP.returnAttributes" parent="shibboleth.CommaDelimStringArray">
        <constructor-arg type="java.lang.String" value="%{idp.authn.LDAP.returnAttributes:1.1}"/>
    </bean>

    <alias name="ValidateUsernamePasswordAgainstLDAP" alias="ValidateUsernamePassword"/>

<!-- Define Directory1 connection pool -->
    <bean id="adConnectionPool1" class="org.ldaptive.pool.BlockingConnectionPool" abstract="true" p:blockWaitTime="%{idp.pool.LDAP.blockWaitTime:3000}" p:poolConfig-ref="adPoolConfig1" p:pruneStrategy-ref="adPruneStrategy1" p:validator-ref="adSearchValidator1" p:failFastInitialize="%{idp.pool.LDAP.failFastInitialize:false}"/>
    <bean id="adPoolConfig1" class="org.ldaptive.pool.PoolConfig" p:minPoolSize="%{idp.pool.LDAP.minSize:3}" p:maxPoolSize="%{idp.pool.LDAP.maxSize:10}" p:validateOnCheckOut="%{idp.pool.LDAP.validateOnCheckout:false}" p:validatePeriodically="%{idp.pool.LDAP.validatePeriodically:true}" p:validatePeriod="%{idp.pool.LDAP.validatePeriod:300}"/>
    <bean id="adPruneStrategy1" class="org.ldaptive.pool.IdlePruneStrategy" p:prunePeriod="%{idp.pool.LDAP.prunePeriod:300}" p:idleTime="%{idp.pool.LDAP.idleTime:600}"/>
    <bean id="adSearchValidator1" class="org.ldaptive.pool.SearchValidator"/>
<!-- Directory1 connection pool settings -->
    <bean id="adConnectionConfig1" class="org.ldaptive.ConnectionConfig" abstract="true" p:ldapUrl="%{idp.authn.LDAP.ldapURL}" p:useStartTLS="%{idp.authn.LDAP.useStartTLS:true}" p:useSSL="%{idp.authn.LDAP.useSSL:false}" p:connectTimeout="%{idp.authn.LDAP.connectTimeout:3000}" p:sslConfig-ref="adSslConfig1"/>
    <alias name="%{idp.authn.LDAP.sslConfig:certificateTrust}" alias="adSslConfig1"/>
<!-- Define Directory2 connection pool -->
    <bean id="adConnectionPool2" class="org.ldaptive.pool.BlockingConnectionPool" abstract="true" p:blockWaitTime="%{idp.pool.LDAP.blockWaitTime:3000}" p:poolConfig-ref="adPoolConfig2" p:pruneStrategy-ref="adPruneStrategy2" p:validator-ref="adSearchValidator2" p:failFastInitialize="%{idp.pool.LDAP.failFastInitialize:false}"/>
    <bean id="adPoolConfig2" class="org.ldaptive.pool.PoolConfig" p:minPoolSize="%{idp.pool.LDAP.minSize:3}" p:maxPoolSize="%{idp.pool.LDAP.maxSize:10}" p:validateOnCheckOut="%{idp.pool.LDAP.validateOnCheckout:false}" p:validatePeriodically="%{idp.pool.LDAP.validatePeriodically:true}" p:validatePeriod="%{idp.pool.LDAP.validatePeriod:300}"/>
    <bean id="adPruneStrategy2" class="org.ldaptive.pool.IdlePruneStrategy" p:prunePeriod="%{idp.pool.LDAP.prunePeriod:300}" p:idleTime="%{idp.pool.LDAP.idleTime:600}"/>
    <bean id="adSearchValidator2" class="org.ldaptive.pool.SearchValidator"/>
<!-- Directory2 connection pool settings -->
    <bean id="adConnectionConfig2" class="org.ldaptive.ConnectionConfig" abstract="true" p:ldapUrl="%{idp.authn.LDAP.CAIB.ldapURL}" p:useStartTLS="%{idp.authn.LDAP.CAIB.useStartTLS:true}" p:useSSL="%{idp.authn.LDAP.CAIB.useSSL:false}" p:connectTimeout="%{idp.authn.LDAP.CAIB.connectTimeout:3000}" p:sslConfig-ref="adSslConfig2"/>
    <alias name="%{idp.authn.LDAP.CAIB.sslConfig:certificateTrust}" alias="adSslConfig2"/>


<bean id="certificateTrust" class="org.ldaptive.ssl.SslConfig">
        <property name="credentialConfig">
            <bean parent="shibboleth.X509ResourceCredentialConfig" p:trustCertificates="%{idp.authn.LDAP.trustCertificates:undefined}"/>
        </property>
    </bean>


<!-- ldap.properties "idp.authn.LDAP.authenticator = adAggregateAuthenticator" -->
    <bean id="adAggregateAuthenticator" class="org.ldaptive.auth.Authenticator" p:authenticationResponseHandlers-ref="adAuthenticationResponseHandler">
        <constructor-arg index="0" ref="adAggregateDnResolver"/>
        <constructor-arg index="1" ref="adAggregateAuthHandler"/>
    </bean>
    <bean id="adAuthenticationResponseHandler" class="org.ldaptive.auth.ext.ActiveDirectoryAuthenticationResponseHandler"/>
    <bean id="adAggregateDnResolver" class="org.ldaptive.auth.AggregateDnResolver">
        <constructor-arg index="0" ref="adDnResolvers"/>
    </bean>
    <bean id="adAggregateAuthHandler" class="org.ldaptive.auth.AggregateDnResolver$AuthenticationHandler" p:authenticationHandlers-ref="adAuthHandlers"/>
    <util:map id="adDnResolvers">
        <entry key="directory1_filter1" value-ref="adDnResolver1"/>
        <entry key="directory1_filter2" value-ref="adDnResolver2"/>
    </util:map>
<!-- Define  DN resolvers that use bind search against the Directory1 directory -->
    <bean id="adDnResolver1" class="org.ldaptive.auth.PooledSearchDnResolver" p:baseDn="%{idp.authn.LDAP.baseDN}" p:subtreeSearch="%{idp.authn.LDAP.subtreeSearch:false}" p:userFilter="%{idp.authn.LDAP.userFilter}" p:connectionFactory-ref="adBindSearchPooledConnectionFactory1"/>

<!-- Define DN resolvers that use bind search against the Directory2 directory -->
    <bean id="adDnResolver2" class="org.ldaptive.auth.PooledSearchDnResolver" p:baseDn="%{idp.authn.LDAP.CAIB.baseDN}" p:subtreeSearch="%{idp.authn.LDAP.CAIB.subtreeSearch:false}" p:userFilter="%{idp.authn.LDAP.CAIB.userFilter}" p:connectionFactory-ref="adBindSearchPooledConnectionFactory2"/>

<!-- Define Directory1 Search-pool -->
    <bean id="adBindSearchPooledConnectionFactory1" class="org.ldaptive.pool.PooledConnectionFactory" p:connectionPool-ref="adBindSearchConnectionPool1"/>
    <bean id="adBindSearchConnectionPool1" class="org.ldaptive.pool.BlockingConnectionPool" parent="adConnectionPool1" p:connectionFactory-ref="adBindSearchConnectionFactory1" p:name="adSearch-pool1"/>
    <bean id="adBindSearchConnectionFactory1" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="adBindSearchConnectionConfig1"/>
    <bean id="adBindSearchConnectionConfig1" parent="adConnectionConfig1" p:connectionInitializer-ref="adBindConnectionInitializer1"/>
    <bean id="adBindConnectionInitializer1" class="org.ldaptive.BindConnectionInitializer" p:bindDn="%{idp.authn.LDAP.bindDN}">
        <property name="bindCredential">
            <bean class="org.ldaptive.Credential">
                <constructor-arg value="%{idp.authn.LDAP.bindDNCredential}"/>
            </bean>
        </property>
    </bean>
<!-- Define Directory2 Search-pool -->
    <bean id="adBindSearchPooledConnectionFactory2" class="org.ldaptive.pool.PooledConnectionFactory" p:connectionPool-ref="adBindSearchConnectionPool2"/>
    <bean id="adBindSearchConnectionPool2" class="org.ldaptive.pool.BlockingConnectionPool" parent="adConnectionPool2" p:connectionFactory-ref="adBindSearchConnectionFactory2" p:name="adSearch-pool2"/>
    <bean id="adBindSearchConnectionFactory2" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="adBindSearchConnectionConfig2"/>
    <bean id="adBindSearchConnectionConfig2" parent="adConnectionConfig2" p:connectionInitializer-ref="adBindConnectionInitializer2"/>
    <bean id="adBindConnectionInitializer2" class="org.ldaptive.BindConnectionInitializer" p:bindDn="%{idp.authn.LDAP.CAIB.bindDN}">
        <property name="bindCredential">
            <bean class="org.ldaptive.Credential">
                <constructor-arg value="%{idp.authn.LDAP.CAIB.bindDNCredential}"/>
            </bean>
        </property>
    </bean>
    <util:map id="adAuthHandlers">
        <entry key="directory1_filter1" value-ref="adAuthHandler1"/>
        <entry key="directory1_filter2" value-ref="adAuthHandler2"/>
    </util:map>
<!-- Use the same authentication handler for both Directory1 DN resolvers -->
    <bean id="adAuthHandler1" class="org.ldaptive.auth.PooledBindAuthenticationHandler" p:connectionFactory-ref="adBindPooledConnectionFactory1"/>
    <bean id="adBindPooledConnectionFactory1" class="org.ldaptive.pool.PooledConnectionFactory" p:connectionPool-ref="adBindConnectionPool1"/>
    <bean id="adBindConnectionPool1" class="org.ldaptive.pool.BlockingConnectionPool" parent="adConnectionPool1" p:connectionFactory-ref="adBindConnectionFactory1" p:name="adBind-pool1"/>
    <bean id="adBindConnectionFactory1" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="adBindConnectionConfig1"/>
    <bean id="adBindConnectionConfig1" parent="adConnectionConfig1"/>
<!-- Use the same authentication handler for both Directory2 DN resolvers -->
    <bean id="adAuthHandler2" class="org.ldaptive.auth.PooledBindAuthenticationHandler" p:connectionFactory-ref="adBindPooledConnectionFactory2"/>
    <bean id="adBindPooledConnectionFactory2" class="org.ldaptive.pool.PooledConnectionFactory" p:connectionPool-ref="adBindConnectionPool2"/>
    <bean id="adBindConnectionPool2" class="org.ldaptive.pool.BlockingConnectionPool" parent="adConnectionPool2" p:connectionFactory-ref="adBindConnectionFactory2" p:name="adBind-pool2"/>
    <bean id="adBindConnectionFactory2" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="adBindConnectionConfig2"/>
    <bean id="adBindConnectionConfig2" parent="adConnectionConfig2"/>

</beans>



Regards




-----Mensaje original-----
De: users <users-bounces at shibboleth.net> En nombre de Peter Schober
Enviado el: lunes, 17 de junio de 2019 10:14
Para: users at shibboleth.net
Asunto: Re: Authentication to two ldap directories

* Ignacio Amoeiro Bosch <ignacio.amoeiro at extern.ibsalut.es> [2019-06-16 14:47]:
> Hi peter, thanks for response. I agree with you 100%. The problem is 
> that one of the two ldap is not managed  by our company and also is 
> not connected by LAN (VPN) so sometimes could fail...... Our ldap 
> service has high availiability.

Is cloning/replicating that externally managed directory to a machine on site is an option? Or maybe they just need to stand up an IDP for themselfs (or you do it).

Anyway, I think you should provide more technical details, including logs for the relevant classes on DEBUG.
Somewhat naively I'd have thought maybe it's just a question of setting timeouts and adding a failover data connector but looking at those 150+ lines of XML config for the example you're using I wouldn't know where or how.

-peter
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list