<div dir="ltr">On Tue, Jun 25, 2013 at 1:15 PM, David Bantz <span dir="ltr">&lt;<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>&gt;</span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">

<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><div style="word-wrap:break-word"><div><br><div><div class="im">

<div>On Tue, 25 Jun 2013, at 06:18 , Peter Schober &lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt; wrote:</div><br></div><blockquote type="cite"><div class="im"><span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">Before sending all subjects&#39; passwords in the clear (which might not</span><br style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">

<span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">be such an issue on a switched network you tighly control access to)</span><br style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">

<span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">consider stacking several modules with the &quot;sufficient&quot; flag[1], one</span><br style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">

</div><span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">for each server.*</span></blockquote>

</div><br></div><div>That would definitely be my choice.  And in our IdP I do already have a non-AD LDAP in parallel to the AD authenticator with both as &quot;sufficient.&quot;    The non-AD LDAP is an 8-node cluster, but the AD instances are not clustered, so I have to specify individual servers, which I&#39;ve been doing with <br>

<div><span style><font face="Andale Mono">edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient</font></span></div><div><span style><font face="Andale Mono">    ldapUrl=&quot;<a>ldap://ad01.ua.ad.alaska.edu:3269</a> <a>ldap://ad02.ua.ad.alaska.edu:3269</a>&quot;</font></span></div>

</div><div style="font-size:11px">  <span style="white-space:pre-wrap">        </span>  ...</div></div></blockquote><div><br></div><div style>I&#39;m still unclear on your configuration.  You&#39;re specifying failover hosts in the ldapUrl parameter and you&#39;re putting trust material for only the first host in a file that is specified with <span style="font-family:Helvetica;text-align:-webkit-auto">sslSocketFactory=&quot;{</span><span style="font-family:Helvetica;text-align:-webkit-auto">trustCertificates=file:/path/</span><span style="font-family:Helvetica;text-align:-webkit-auto">to/my/trust.crt}&quot; ? Is that correct?</span></div>

<div style><span style="font-family:Helvetica;text-align:-webkit-auto"><br></span></div><div style><span style="font-family:Helvetica;text-align:-webkit-auto">--Daniel Fisher</span></div><div style><span style="font-family:Helvetica;text-align:-webkit-auto"><br>

</span></div></div></div></div>