<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Jun 22, 2016, at 9:06 AM, Daniel Fisher <<a href="mailto:dfisher@vt.edu" class="">dfisher@vt.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div dir="ltr" class=""><div class="gmail_extra"><div class="gmail_quote">On Tue, Jun 21, 2016 at 6:32 PM, Michael A Grady <span dir="ltr" class=""><<a href="mailto:mgrady@unicon.net" target="_blank" class="">mgrady@unicon.net</a>></span> wrote:<br class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word" class=""><div class=""><div class="h5"><span style="color:rgb(34,34,34)" class="">If one does aggregate DN resolvers/authn handlers, what happens if the user is found in both, but authentication succeeds in one and fails in the other? </span></div></div></div></blockquote><div class=""><br class=""></div><div class="">Only one authentication event occurs. The DN resolver will throw by default if more than one DN is found. If you configure it to allow multiple DNs, the first one found in the underlying collection will be used.</div><div class=""><br class=""></div><div class="">--Daniel Fisher</div><div class=""><br class=""></div></div></div></div></div></blockquote></div><div apple-content-edited="true" class=""><br class=""></div><div apple-content-edited="true" style="orphans: 2; widows: 2; " class="">So, given one configures to allow multiple DNs, the first one found in the collection will then determine which LDAP instance the BIND attempt as the user will be done with, correct? </div><div apple-content-edited="true" class=""><br class="">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.

</div>
<br class=""></body></html>