<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On May 31, 2016, at 12:16 PM, IAM David Bantz <<a href="mailto:dabantz@alaska.edu" class="">dabantz@alaska.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div dir="ltr" class="">FWIW, UA has what seems a similar use case (Oracle DSEE LDAP and AD as well) except that we need to fail over to multiple instances of AD.<div class=""><br class=""></div><div class="">David Bantz</div><div class="">UA OIT IAM</div></div><div class="gmail_extra"><br class=""><div class="gmail_quote">On Tue, May 31, 2016 at 7:25 AM, Daniel Fisher <span dir="ltr" class=""><<a href="mailto:dfisher@vt.edu" target="_blank" class="">dfisher@vt.edu</a>></span> wrote:<br class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr" class=""><div class="gmail_extra"><div class="gmail_quote"><span class="">On Tue, May 31, 2016 at 11:06 AM, Marco Malavolti <span dir="ltr" class=""><<a href="mailto:marco.malavolti@garr.it" target="_blank" class="">marco.malavolti@garr.it</a>></span> wrote:<br class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  

    
  
  <div bgcolor="#FFFFFF" text="#000000" class="">Someone of you already know a solution for this use case? What I
    need to do to solve this situation and authenticate the users
    provided by both directories?<br class=""></div></blockquote><div class=""><br class=""></div></span><div class="">Can you describe your directory infrastructure? Are we talking about a single instance of OpenLDAP and a single instance of AD?</div><span class="HOEnZb"><font color="#888888" class=""><div class=""><br class=""></div><div class="">--Daniel fisher</div><div class=""><br class=""></div></font></span></div></div></div></blockquote></div></div></div></blockquote></div><div class=""><br class="webkit-block-placeholder"></div><div apple-content-edited="true" class="">
There are examples in the Wiki on the following page:</div><div apple-content-edited="true" class=""><br class=""></div><div apple-content-edited="true" class=""> <a href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration" class="">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration</a></div><div apple-content-edited="true" class=""><br class=""></div><div apple-content-edited="true" class="">under DN resolution and Account State, of having more than one. But once you have to start replicating all that config, the advantage versus just going back to using JAAS to configure the multiple sources gets unclear. The JAAS config is simpler, but perhaps doesn't get you all the same account state options -- if you are going to use those. And it sounds like the JAAS options are going to get more flexible with 3.3 when it becomes available.</div><div apple-content-edited="true" class=""><br class=""></div><div apple-content-edited="true" class=""><br class="">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.

</div>

<br class=""></body></html>