<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Tue, Jun 21, 2016 at 6:33 PM Michael A Grady <<a href="mailto:mgrady@unicon.net">mgrady@unicon.net</a>> wrote:</div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word"><div>If one does aggregate DN resolvers/authn handlers, what happens if the user is found in both, but authentication succeeds in one and fails in the other? </div></div></blockquote><div><br></div><div>The order in which the subordinate directories are searched is indeterminate since they're performed concurrently, though multiple results are disallowed by default. That's good default behavior.<span style="line-height:1.5"> If you configure multiple authentication systems of record that don't have namespace controls, then the behavior when the same user is found in multiple systems becomes very unclear. Deployers have to think very carefully about the consequences of advanced configuration like this, and I would argue that in most cases it's so challenging that it can be a source of self-inflicted security vulnerabilities. One should allow multiple results only on very careful analysis.</span></div><div><br></div><div>M</div><div><br></div></div></div>