Configuring an Aggregate DN Resolver with IdP 4.0.1
Max Spicer
max.spicer at york.ac.uk
Wed Feb 3 17:16:34 UTC 2021
Using a new install of IdP 4.0.1, I am configuring an authenticator that
can combine the results of multiple DN resolvers, following the
documentation for *Single Directory with multiple branches* -> *Aggregate
DN Resolver* at
https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration#55804291ae05b98371814cefae58d3bb594a5067.
Note, my directory does not support extensible matching.
*I have got this working*, but in doing so found that I had to obtain a
copy of conf/authn/ldap-authn-config.xml from IdP 3.4 and then create a
new ldap-authn-config.xml that restores many of the beans that are now
removed from the default 4.0 version of the file. The docs do suggest that
this will be necessary, but the example I was following does not show this
explicitly and I can't help wondering if I am missing a trick.
I've attached a copy of my ldap-authn-config.xml. The only changes that I
have made to this from the default version are those that I have found
necessary to implement my aggregate dn resolver.
Does this look like a sensible approach, or should I be able to use a
simpler configuration?
Thanks,
Max Spicer
--
IT Services, University of York
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210203/a1a18aa6/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ldap-authn-config.xml
Type: text/xml
Size: 8523 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20210203/a1a18aa6/attachment.xml>
More information about the users
mailing list