<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Tue, Jun 21, 2016 at 6:32 PM, Michael A Grady <span dir="ltr"><<a href="mailto:mgrady@unicon.net" target="_blank">mgrady@unicon.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word"><div><div class="h5"><span style="color:rgb(34,34,34)">If one does aggregate DN resolvers/authn handlers, what happens if the user is found in both, but authentication succeeds in one and fails in the other? </span></div></div></div></blockquote><div><br></div><div>Only one authentication event occurs. The DN resolver will throw by default if more than one DN is found. If you configure it to allow multiple DNs, the first one found in the underlying collection will be used.</div><div><br></div><div>--Daniel Fisher</div><div> </div></div></div></div>