<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Mon, May 16, 2016 at 7:21 PM, Mark Boyce <span dir="ltr"><<a href="mailto:Mark.Boyce@ucop.edu" target="_blank">Mark.Boyce@ucop.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal">When pooling AD Domain Controllers and adding “connectionHandler="edu.vt.middleware.ldap.handler.DefaultConnectionHandler{{connectionStrategy=ACTIVE_PASSIVE}}"” (as prescribed at <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthUserPass" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthUserPass</a>)
 I am seeing the following:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">1)            User enters bad password<u></u><u></u></p>
<p class="MsoNormal">2)            Shibboleth (yes, it is the underlying edu.vt.middleware.ldap.jaas.LdapLoginModule) attempts to authenticate the user at each DC in the pool; having failed to bind as the user, it would appear that edu.vt.middleware.ldap.jaas.LdapLoginModule
 is interpreting this as a failure of the server and promptly moving on to the next server in the pool</p></div></div></blockquote><div><br></div><div>Can you post some debug logs of this?</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>