<div dir="ltr">Scott,<div><br></div><div>regarding the name space what others also mentioned, do you mean the well determined OIDs and URNs? Is there a recommended way for them? Because as I understand that I can guarantee that the intersection of user stores is nil, I can use the same attrib names.</div>

<div><br></div><div>Regarding SPs, they are usually able to use one IdP at the same time at least I saw only these.</div><div><br></div><div>Cheers,</div></div><div class="gmail_extra"><br clear="all"><div>VWOL<br>Tamas SZERB &lt;<a href="mailto:toma@rulez.org">toma@rulez.org</a>&gt;</div>


<br><br><div class="gmail_quote">On Wed, Jun 25, 2014 at 11:58 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div class="">&gt; OK, let me clarify the use case.<br>
&gt;<br>
&gt; 1) Authenticate against database<br>
&gt; 2) If no user there, try to authenticate against LDAP<br>
&gt; 3) if succeeded, then fetch the attribute from the data source where the<br>
&gt; user authenticated.<br>
<br>
</div>Then by definition your namespaces have to be unified, making (3) unnecessary. And in any case it&#39;s not possible, as several people have noted.<br>
<div class=""><br>
&gt; After investigating Shibboleth and the common practices (and other<br>
&gt; products), I think that would be the appropriate approach, since the IdP<br>
&gt; could be the common place where all the data aggregations would happen.<br>
<br>
</div>That isn&#39;t really the &quot;normal&quot; advice, the major point of an IDM strategy is to it outside the IdP, but it&#39;s hardly uncommon. It still remains unnecessary to guarantee anything about which data source gets checked. You build a failover chain between the two data sources so that it always gets the data and it&#39;s fine.<br>


<div class=""><br>
&gt; Each SP can be configured to use only one IdP, so the method of using<br>
&gt; different user/attrib stores would be up to the Shibboleth.<br>
<br>
</div>I don&#39;t know what that means. It&#39;s not true, unless you&#39;re talking about your SPs and some particular constraint you have. SPs can use any IdPs they want to.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>