jaas authentication failover

Liam Hoekenga liamr at umich.edu
Tue Mar 26 12:55:36 EDT 2019


As we retire our legacy SSO, we will need to try to authenticate both
against our KDC and a SQL backend (based on whether the principle has an @
in it).

Defining multiple backends in a single configuration using "sufficient" is
not doing what I expect.  (In fact, "sufficient" just seems to let people
into our QA id regardless of whether the password they provide is correct
or not).

I found this thread, with Scott's suggestion to use chained JAAS modules.

https://marc.info/?l=shibboleth-users&m=146211861020340&w=2

Anyone have an example of the "advance usage" as described at
https://wiki.shibboleth.net/confluence/display/IDP30/JAASAuthnConfiguration#JAASAuthnConfiguration-AdvancedJAASUsage3.3

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190326/77d320f4/attachment.html>


More information about the users mailing list