Multiple LDAPs and Research Services

Janemarie Duh duhj at udel.edu
Thu Oct 19 16:46:54 UTC 2023


Those of you who support FIM4R and have run into the case of a local LDAP
separate from the enterprise directory, how are you handling
authentication?

A use case we have is access to several research CI webapps using an LDAP
that contains both external collaborators and internal users, plus
attributes specific to research services. The internal users also exist in
the enterprise LDAP but without the attributes. There is no person registry
at present, so this RCI LDAP is effectively authoritative for the
attributes and the external collaborators. Our IdP is running v4.3.1.

I'm trying to avoid having RCI set up their own IdP and proxying to it from
the central IdP and instead looking at configuring a second LDAP connector
on our central IdP to return the research-specific attributes and
authenticate the external users.

The solution I'm looking at is https://tinyurl.com/authUsersDifferentLDAPs.
The one unknown is how this configuration would behave for non-research
service authentication. Only RCI apps should auth against the RCI LDAP.

We view this use case as the first phase of bringing RCI into the central
IAM fold, so we want to get it right and are interested in best practice.

If you've encountered a similar use case, what solution did you implement?

-- 

*Janemarie Duh*
UD Information Technologies
*Identity and Access Management Specialist*
duhj at udel.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20231019/0c93150a/attachment.htm>


More information about the users mailing list