V4 LDAP Authentication

Craig Pluchinsky craigp at iup.edu
Mon Jul 6 14:00:01 UTC 2020


In v3 we configured our ldap authentication to use an aggregate dn resolver as we wanted to authenticate against a select set of OUs.  I'm trying to simplify this config by using the v4 chaining of ldap validators.  Everything seems to be working as expected except for fail-over.  The v4 config appears to only be using the last server that is defined in ldapURL.  So when that server is offline authentication fails.  We have three domain controllers and have them all listed for the ldapURL property.  For v3 I got around this issue by setting the connection strategy to random.  Is there a way to do this with the v4 style of config?  If not I can just keep our current config with adjustments to work with v4.



-------------------------------
Craig Pluchinsky
IT Services
Indiana University of Pennsylvania
724-357-3327
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200706/a4680bb8/attachment.htm>


More information about the users mailing list