<div dir="ltr">This isn't too hard to build in a scripted attribute - we do exactly this with sources MS AD and Oracle LDAP sources: map attribute to the preferred source attribute if it exists, otherwise to the secondary source. (happy to provide our example if requested)<div><br></div><div>David Bantz</div><div>UA OIT IAM<br><div><div><div><br></div><div> </div>
<p class=""><span class=""></span></p>
<p class=""><span class=""></span></p>
<p class=""><span class=""></span></p>
<p class=""><span class=""></span></p>
</div></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Mar 31, 2016 at 5:50 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> My organization is in the process of moving a new Directory Server. As such I<br>
> have configure DataConnector for each. What I have started to notice that<br>
> for a subset of users that have had information updated in the new system I<br>
> am getting multivalued attributes for things like surname. ex Directory 1 has<br>
> Surname=Smith, Directory 2 has Surname=Smith Sr. This would result in the<br>
> attribute Surname=Smith;Smith Sr.<br>
><br>
> Is there any way to say Directory 1 is authoritative for Surname since I cannot<br>
> prevent both Directories from responding?<br>
<br>
</span>Not without your own logic to do it. Generally you should have one directory be a failover for the other, not access both.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>