<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:"Calibri Light";
panose-1:2 15 3 2 2 2 4 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
h5
{mso-style-priority:9;
mso-style-link:"Heading 5 Char";
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:10.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
{mso-style-priority:99;
mso-style-link:"Plain Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
{mso-style-priority:34;
margin-top:0in;
margin-right:0in;
margin-bottom:0in;
margin-left:.5in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.Heading5Char
{mso-style-name:"Heading 5 Char";
mso-style-priority:9;
mso-style-link:"Heading 5";
font-family:"Calibri Light",sans-serif;
color:#2E74B5;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:"Courier New";}
span.PlainTextChar
{mso-style-name:"Plain Text Char";
mso-style-priority:99;
mso-style-link:"Plain Text";
font-family:"Calibri",sans-serif;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
span.EmailStyle24
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.apple-converted-space
{mso-style-name:apple-converted-space;}
span.EmailStyle26
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:#1F497D;}
span.EmailStyle27
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
/* List Definitions */
@list l0
{mso-list-id:511913086;
mso-list-type:hybrid;
mso-list-template-ids:-947214050 1120727246 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
{mso-level-start-at:8;
mso-level-number-format:bullet;
mso-level-text:-;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:22.5pt;
text-indent:-.25in;
font-family:"Calibri",sans-serif;
mso-fareast-font-family:Calibri;
mso-bidi-font-family:"Times New Roman";}
@list l0:level2
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:58.5pt;
text-indent:-.25in;
font-family:"Courier New";}
@list l0:level3
{mso-level-number-format:bullet;
mso-level-text:\F0A7;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:94.5pt;
text-indent:-.25in;
font-family:Wingdings;}
@list l0:level4
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:130.5pt;
text-indent:-.25in;
font-family:Symbol;}
@list l0:level5
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:166.5pt;
text-indent:-.25in;
font-family:"Courier New";}
@list l0:level6
{mso-level-number-format:bullet;
mso-level-text:\F0A7;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:202.5pt;
text-indent:-.25in;
font-family:Wingdings;}
@list l0:level7
{mso-level-number-format:bullet;
mso-level-text:\F0B7;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:238.5pt;
text-indent:-.25in;
font-family:Symbol;}
@list l0:level8
{mso-level-number-format:bullet;
mso-level-text:o;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:274.5pt;
text-indent:-.25in;
font-family:"Courier New";}
@list l0:level9
{mso-level-number-format:bullet;
mso-level-text:\F0A7;
mso-level-tab-stop:none;
mso-level-number-position:left;
margin-left:310.5pt;
text-indent:-.25in;
font-family:Wingdings;}
ol
{margin-bottom:0in;}
ul
{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Well, that ExamplefortwoActiveDirectorieswithtwoDNResolversforeach is a very involved configuration. I have not noticed that before.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Mine is kind of similar, but different. The one big difference for me is, I’m not using two Active Directory LDAP instances.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I’m using one Active Directory LDAP instance and one OpenLDAP instance. So, I have one using ‘adAuthenticator’ and one using ‘bindSearchAuthenticator’.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Maybe I have something misconfigured.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">The behavior I observe is:<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:22.5pt;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="color:#1F497D"><span style="mso-list:Ignore">-<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="color:#1F497D">login1 – exists in LDAP1, which is OpenLDAP instance<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:22.5pt;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="color:#1F497D"><span style="mso-list:Ignore">-<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="color:#1F497D">login2 – exists in LDAP2, which is Active Directory instance<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:4.5pt"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:4.5pt"><span style="color:#1F497D">Authentication for login1 fails:<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:58.5pt;text-indent:-.25in;mso-list:l0 level2 lfo1">
<![if !supportLists]><span style="font-family:"Courier New";color:#1F497D"><span style="mso-list:Ignore">o<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="color:#1F497D">Successful authentication against LDAP1<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:58.5pt;text-indent:-.25in;mso-list:l0 level2 lfo1">
<![if !supportLists]><span style="font-family:"Courier New";color:#1F497D"><span style="mso-list:Ignore">o<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="color:#1F497D">Failed authentication against LDAP2<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Authentication for login2 succeeds:<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:58.5pt;text-indent:-.25in;mso-list:l0 level2 lfo1">
<![if !supportLists]><span style="font-family:"Courier New";color:#1F497D"><span style="mso-list:Ignore">o<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="color:#1F497D">Successful authentication against LDAP1 – I don’t understand this; this should not be successful as this user does not exist in this LDAP instance; I’m positive<o:p></o:p></span></p>
<p class="MsoListParagraph" style="margin-left:58.5pt;text-indent:-.25in;mso-list:l0 level2 lfo1">
<![if !supportLists]><span style="font-family:"Courier New";color:#1F497D"><span style="mso-list:Ignore">o<span style="font:7.0pt "Times New Roman"">
</span></span></span><![endif]><span style="color:#1F497D">Successful authentication against LDAP2<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Let me offer some snippets from my conf/authn/ldap-authn-config.xml file. Any assistance will be greatly appreciated:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <alias name="%{idp.authn.custom.LDAP.authenticator:aggregateAuthenticator}" alias="shibboleth.authn.custom.LDAP.authenticator" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!—I set the ‘…-ref’ property to this new alias for the bean definition of ‘ValidateUsernamePasswordAgainstLDAP’ -->
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- OpenLDAP Connection Configuration --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="openLDAPConnectionConfig" class="org.ldaptive.ConnectionConfig" abstract="true" p:ldapUrl="%{idp.authn.open.LDAP.ldapURL}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:useStartTLS="%{idp.authn.LDAP.useStartTLS:true}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:useSSL="%{idp.authn.LDAP.useSSL:false}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectTimeout="%{idp.authn.LDAP.connectTimeout:3000}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:sslConfig-ref="sslConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- Active Directory Connection Configuration --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adConnectionConfig" class="org.ldaptive.ConnectionConfig" abstract="true" p:ldapUrl="%{idp.authn.ad.LDAP.ldapURL}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:useStartTLS="%{idp.authn.LDAP.useStartTLS:true}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:useSSL="%{idp.authn.LDAP.useSSL:false}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectTimeout="%{idp.authn.LDAP.connectTimeout:3000}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:sslConfig-ref="sslConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- OpenLDAP Authentication handler --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="openLDAPAuthHandler" class="org.ldaptive.auth.PooledBindAuthenticationHandler" p:connectionFactory-ref="openLDAPBindPooledConnectionFactory" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="openLDAPBindPooledConnectionFactory" class="org.ldaptive.pool.PooledConnectionFactory" p:connectionPool-ref="openLDAPBindConnectionPool" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="openLDAPBindConnectionPool" class="org.ldaptive.pool.BlockingConnectionPool" parent="connectionPool"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectionFactory-ref="openLDAPBindConnectionFactory" p:name="open-bind-pool" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="openLDAPBindConnectionFactory" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="openLDAPBindConnectionConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="openLDAPBindConnectionConfig" parent="openLDAPConnectionConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- AD Authentication handler --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adAuthHandler" class="org.ldaptive.auth.PooledBindAuthenticationHandler" p:connectionFactory-ref="adBindPooledConnectionFactory" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adBindPooledConnectionFactory" class="org.ldaptive.pool.PooledConnectionFactory" p:connectionPool-ref="adBindConnectionPool" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adBindConnectionPool" class="org.ldaptive.pool.BlockingConnectionPool" parent="connectionPool"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectionFactory-ref="adBindConnectionFactory" p:name="ad-bind-pool" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adBindConnectionFactory" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="adBindConnectionConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adBindConnectionConfig" parent="adConnectionConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!—AD Format DN resolution --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="formatDnResolver" class="org.ldaptive.auth.FormatDnResolver" p:format="%{idp.authn.LDAP.dnFormat:undefined}" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- Bind Search Configuration --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean name="bindSearchAuthenticator" class="org.ldaptive.auth.Authenticator" p:resolveEntryOnFailure="%{idp.authn.LDAP.resolveEntryOnFailure:false}"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <constructor-arg index="0" ref="bindSearchDnResolver" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <constructor-arg index="1" ref="openLDAPAuthHandler" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </bean><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="bindSearchDnResolver" class="org.ldaptive.auth.PooledSearchDnResolver"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:baseDn="#{'%{idp.authn.open.LDAP.baseDN:undefined}'.trim()}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:subtreeSearch="%{idp.authn.open.LDAP.subtreeSearch:false}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:userFilter="#{'%{idp.authn.open.LDAP.userFilter:undefined}'.trim()}"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectionFactory-ref="bindSearchPooledConnectionFactory" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="bindSearchPooledConnectionFactory" class="org.ldaptive.pool.PooledConnectionFactory"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectionPool-ref="bindSearchConnectionPool" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="bindSearchConnectionPool" class="org.ldaptive.pool.BlockingConnectionPool" parent="connectionPool"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:connectionFactory-ref="bindSearchConnectionFactory" p:name="search-pool" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="bindSearchConnectionFactory" class="org.ldaptive.DefaultConnectionFactory" p:connectionConfig-ref="bindSearchConnectionConfig" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="bindSearchConnectionConfig" parent="openLDAPConnectionConfig" p:connectionInitializer-ref="bindConnectionInitializer" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="bindConnectionInitializer" class="org.ldaptive.BindConnectionInitializer"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:bindDn="#{'%{idp.authn.open.LDAP.bindDN:undefined}'.trim()}"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <property name="bindCredential"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean class="org.ldaptive.Credential"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <constructor-arg value="%{idp.authn.open.LDAP.bindDNCredential:undefined}" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </bean><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </property><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </bean><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- Active Directory Configuration --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="adAuthenticator" class="org.ldaptive.auth.Authenticator" p:authenticationResponseHandlers-ref="authenticationResponseHandler"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:resolveEntryOnFailure="%{idp.authn.LDAP.resolveEntryOnFailure:false}"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <constructor-arg index="0" ref="formatDnResolver" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <constructor-arg index="1" ref="adAuthHandler" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </bean><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="authenticationResponseHandler" class="org.ldaptive.auth.ext.ActiveDirectoryAuthenticationResponseHandler" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <!-- Setup an aggregate authentication approach to support multiple directories --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="aggregateAuthenticator" class="org.ldaptive.auth.Authenticator"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> c:resolver-ref="aggregateDnResolver"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> c:handler-ref="aggregateAuthHandler" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="aggregateDnResolver" class="org.ldaptive.auth.AggregateDnResolver"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> c:resolvers-ref="dnResolvers"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> p:allowMultipleDns="true" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <bean id="aggregateAuthHandler" class="org.ldaptive.auth.AggregateDnResolver$AuthenticationHandler" p:authenticationHandlers-ref="authHandlers" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <util:map id="dnResolvers"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <entry key="openLDAPDirectory" value-ref="bindSearchDnResolver" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <entry key="adDirectory" value-ref="formatDnResolver" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </util:map><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <util:map id="authHandlers"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <entry key="openLDAPDirectory" value-ref="openLDAPAuthHandler" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> <entry key="adDirectory" value-ref="adAuthHandler" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"> </util:map><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Thanks<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Raymond<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users [mailto:users-bounces@shibboleth.net] <b>
On Behalf Of </b>Brady, Jason W<br>
<b>Sent:</b> Monday, June 27, 2016 11:00 AM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> RE: IDPv3.1.2 LDAP connector: using two distinct LDAP servers?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoPlainText">On 6/24/16, 7:55 PM, "users on behalf of Raymond Gardner" <<a href="mailto:users-bounces@shibboleth.net%20on%20behalf%20of%20r.gardner@ntta.com">users-bounces@shibboleth.net on behalf of r.gardner@ntta.com</a>> wrote:<o:p></o:p></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">> </span><span style="color:black">My experience is that it requires successful authentication against both directories configured.</span><span style="color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">We are currently using this configuration and my experience is it doesn’t require authentication against both directories. Well, based on the Active Directory example (<a href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-ExamplefortwoActiveDirectorieswithtwoDNResolversforeach">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-ExamplefortwoActiveDirectorieswithtwoDNResolversforeach</a>)
and only in live starting this month.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">In what test did you experience this? I was able to login in with accounts from either directory.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">We have two Active Directory domains in the same forest, but use separate bind credentials and servers for each domain. Our setup makes sure to not have the same username in both domains. I noticed that this
caused an issue in v2 when using JAAS.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">However, do note that the generic Multiple Directories example and the Active Directory example are not exactly the same. I removed the extra resolvers in our config. With that change they seem to be equivalent
(though the generic seems to have updated syntax?).<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">Jason Brady * Web Developer * San Bernardino Community College District *
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">1289 Bryn Mawr Ave, Suite B, Redlands, CA 92374 *<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Tel 909-384-8691 * Mobile 951-295-9515 * Fax 909-796-6579 *
<a href="mailto:jbrady@sbccd.cc.ca.us">jbrady@sbccd.cc.ca.us</a><o:p></o:p></span></p>
</div>
</div>
<p>****************************************************************
This email message is intended for the use of the person to whom it has been sent, and may contain information that is confidential or legally protected. If you are not the intended recipient or have received this message in error, you are not authorized to copy, distribute, or otherwise use this message or its attachments. Please notify the sender immediately by return e-mail and permanently delete this message and any attachments. NTT America makes no warranty that this email is error or virus free. Thank you.
****************************************************************
</p>
</body>
</html>