<div dir="ltr">On Tue, Jun 25, 2013 at 1:15 PM, David Bantz <span dir="ltr"><<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>></span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><div style="word-wrap:break-word"><div><br><div><div class="im">
<div>On Tue, 25 Jun 2013, at 06:18 , Peter Schober <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>> wrote:</div><br></div><blockquote type="cite"><div class="im"><span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">Before sending all subjects' passwords in the clear (which might not</span><br style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
<span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">be such an issue on a switched network you tighly control access to)</span><br style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
<span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">consider stacking several modules with the "sufficient" flag[1], one</span><br style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
</div><span style="font-family:Helvetica;font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;float:none;display:inline!important">for each server.*</span></blockquote>
</div><br></div><div>That would definitely be my choice. And in our IdP I do already have a non-AD LDAP in parallel to the AD authenticator with both as "sufficient." The non-AD LDAP is an 8-node cluster, but the AD instances are not clustered, so I have to specify individual servers, which I've been doing with <br>
<div><span style><font face="Andale Mono">edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient</font></span></div><div><span style><font face="Andale Mono"> ldapUrl="<a>ldap://ad01.ua.ad.alaska.edu:3269</a> <a>ldap://ad02.ua.ad.alaska.edu:3269</a>"</font></span></div>
</div><div style="font-size:11px"> <span style="white-space:pre-wrap">        </span> ...</div></div></blockquote><div><br></div><div style>I'm still unclear on your configuration. You're specifying failover hosts in the ldapUrl parameter and you're putting trust material for only the first host in a file that is specified with <span style="font-family:Helvetica;text-align:-webkit-auto">sslSocketFactory="{</span><span style="font-family:Helvetica;text-align:-webkit-auto">trustCertificates=file:/path/</span><span style="font-family:Helvetica;text-align:-webkit-auto">to/my/trust.crt}" ? Is that correct?</span></div>
<div style><span style="font-family:Helvetica;text-align:-webkit-auto"><br></span></div><div style><span style="font-family:Helvetica;text-align:-webkit-auto">--Daniel Fisher</span></div><div style><span style="font-family:Helvetica;text-align:-webkit-auto"><br>
</span></div></div></div></div>