jaas authentication failover
Liam Hoekenga
liamr at umich.edu
Tue Mar 26 12:55:36 EDT 2019
As we retire our legacy SSO, we will need to try to authenticate both
against our KDC and a SQL backend (based on whether the principle has an @
in it).
Defining multiple backends in a single configuration using "sufficient" is
not doing what I expect. (In fact, "sufficient" just seems to let people
into our QA id regardless of whether the password they provide is correct
or not).
I found this thread, with Scott's suggestion to use chained JAAS modules.
https://marc.info/?l=shibboleth-users&m=146211861020340&w=2
Anyone have an example of the "advance usage" as described at
https://wiki.shibboleth.net/confluence/display/IDP30/JAASAuthnConfiguration#JAASAuthnConfiguration-AdvancedJAASUsage3.3
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190326/77d320f4/attachment.html>
More information about the users
mailing list