<div dir="ltr">Thanks Peter for your input. I agree with it and I will do it as suggested.</div><div class="gmail_extra"><br><div class="gmail_quote">On 9 October 2014 10:22, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Farzan Qureshi &lt;<a href="mailto:fqureshi@rosmini.school.nz">fqureshi@rosmini.school.nz</a>&gt; [2014-10-08 01:16]:<br>
<span class="">&gt; Thanks for the detailed response. Actually I was thinking you are querying<br>
&gt; multiple base DNs. Actually I don&#39;t want to use top level AD forest. I want<br>
&gt; to keep it restricted to three or four OUs. But I believe in your case you<br>
&gt; are using top level base DN and not multiple search base.<br>
<br>
</span>The LDAP protocol doesn&#39;t have a way to say &quot;search for this in those<br>
3 basedns&quot;. You (i.e., the LDAP client) would have to issue 3 seperate<br>
searches in each of those basedns.<br>
<br>
I&#39;d probably make sure the service DN used to perform the search does<br>
not have read/search access to the parts of the DIT you don&#39;t want it<br>
to search. Then you could still have simple configuration on the<br>
client side (and slightly more efficient than issueing multiple<br>
identical searches with different search bases) but limit the IDP to<br>
specific parts of the DIT.<br>
(If you&#39;re performing anonymous binds during the search, well, don&#39;t<br>
do that.)<br>
<span class="HOEnZb"><font color="#888888">-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><font face="tahoma, sans-serif"><b>Farzan Qureshi</b> | Network Administrator &amp; Help-desk Support | Rosmini College | (09) 487 0 530</font>
</div>

<br>
<font style="font-family:Verdana" size="1">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager (<span style="font-weight:bold;font-style:italic"><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></span>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, the recipient should check this email and any attachments for the presence of viruses. <span style="font-weight:bold">Rosmini College</span> accepts no liability for any damage caused by any virus transmitted by this email.</font>