<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">To all,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am currently running a 2.3.6 IdP Instance on JBOSS 5 (RHEL 5) that is configured for UserPassword and PreviousSession for the login handlers. I have JAAS configured correctly to use one of our LDAP sources (it is in production and working
correctly). I was just handed a requirement to integrate with an application that wants to authenticate against a differing version of LDAP. I read through the section on JAAS configuration and felt confident I could stack the LDAP servers in the configuration
to allow for auth to either service. However, this new LDAP that I am adding is a superset of the current system. More precisely, when we add a new user to our system we add that user in LDAP1(currently configured) and LDAP2(want to add). We keep these systems
in sync for the user while they are here. When they leave, we disable the user in LDAP1 (but leave their entry) and stop updating LDAP2. So the user is in both but is only able to login to LDAP2. Now, the concern is that if a user leaves and now is able
to login to LDAP2, they will be able to get access to an application that assumes they are enabled in LDAP1. I have been given till tomorrow to dream up a way to ensure that if a user is auth’ed in LDAP2 that they will not be allowed in any of the current
applications that are configured now. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Hope this makes sense,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b><span style="font-size:12.0pt;font-family:"Times New Roman","serif";color:#666666">Lee Brewer | Directory Services Architect | Information Technology | Vanderbilt University</span></b><span style="font-size:12.0pt;font-family:"Times New Roman","serif";color:#666666">
<br>
lee.brewer@vanderbilt.edu | phone 615.343.2802 | <a href="http://it.vanderbilt.edu/" title="Vanderbilt IT">
<span style="color:blue">it.vanderbilt.edu</span></a> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:12.0pt;font-family:"Times New Roman","serif""><img border="0" width="380" height="95" id="Picture_x0020_1" src="cid:image002.jpg@01CE9F4A.BDAD71A0" alt="Vanderbilt IT logo"><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>