<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Jun 22, 2016, at 12:16 PM, Michael A Grady <<a href="mailto:mgrady@unicon.net" class="">mgrady@unicon.net</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><meta http-equiv="Content-Type" content="text/html charset=us-ascii" class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div class=""><blockquote type="cite" class=""><div class="">On Jun 22, 2016, at 9:06 AM, Daniel Fisher <<a href="mailto:dfisher@vt.edu" class="">dfisher@vt.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div dir="ltr" class=""><div class="gmail_extra"><div class="gmail_quote">On Tue, Jun 21, 2016 at 6:32 PM, Michael A Grady <span dir="ltr" class=""><<a href="mailto:mgrady@unicon.net" target="_blank" class="">mgrady@unicon.net</a>></span> wrote:<br class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word" class=""><div class=""><div class="h5"><span style="color:rgb(34,34,34)" class="">If one does aggregate DN resolvers/authn handlers, what happens if the user is found in both, but authentication succeeds in one and fails in the other? </span></div></div></div></blockquote><div class=""><br class=""></div><div class="">Only one authentication event occurs. The DN resolver will throw by default if more than one DN is found. If you configure it to allow multiple DNs, the first one found in the underlying collection will be used.</div><div class=""><br class=""></div><div class="">--Daniel Fisher</div><div class=""><br class=""></div></div></div></div></div></blockquote></div><div apple-content-edited="true" class=""><br class=""></div><div apple-content-edited="true" style="orphans: 2; widows: 2; " class="">So, given one configures to allow multiple DNs, the first one found in the collection will then determine which LDAP instance the BIND attempt as the user will be done with, correct? </div><div apple-content-edited="true" class=""><br class=""></div></div></div></blockquote><br class=""></div><div>And, more to the point, if you want the SUFFICIENT behavior of JAAS, you need to use JAAS, you can't easily get it to try the second DN in the collection if the first one chosen "fails"?</div><br class=""><div class="">
<br class="">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.

</div>
<br class=""></body></html>