<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Jun 30, 2016 at 7:42 PM, Raymond Gardner <span dir="ltr"><<a href="mailto:r.gardner@ntta.com" target="_blank">r.gardner@ntta.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
<div lang="EN-US" link="#0563C1" vlink="#954F72">
<div>
<p class="MsoNormal" style="margin-left:4.5pt"><span style="color:rgb(31,73,125)"><br>Authentication for login1 fails:<u></u><u></u></span></p>
<p style="margin-left:58.5pt">
<u></u><span style="font-family:"Courier New";color:rgb(31,73,125)"><span>o<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span></span><u></u><span style="color:rgb(31,73,125)">Successful authentication against LDAP1<u></u><u></u></span></p>
<p style="margin-left:58.5pt">
<u></u><span style="font-family:"Courier New";color:rgb(31,73,125)"><span>o<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span></span><u></u><span style="color:rgb(31,73,125)">Failed authentication against LDAP2<u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)">Authentication for login2 succeeds:<u></u><u></u></span></p>
<p style="margin-left:58.5pt">
<u></u><span style="font-family:"Courier New";color:rgb(31,73,125)"><span>o<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span></span><u></u><span style="color:rgb(31,73,125)">Successful authentication against LDAP1 – I don’t understand this; this should not be successful as this user does not exist in this LDAP instance; I’m positive<u></u><u></u></span></p>
<p style="margin-left:58.5pt">
<u></u><span style="font-family:"Courier New";color:rgb(31,73,125)"><span>o<span style="font-style:normal;font-variant:normal;font-weight:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span></span><u></u><span style="color:rgb(31,73,125)">Successful authentication against LDAP2</span></p></div></div></blockquote><div><br></div><div>I'd have to see some logs to make sense of this. Only one bind should be occurring, so this is strange.</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><div lang="EN-US" link="#0563C1" vlink="#954F72"><div><p style="margin-left:58.5pt"><span style="color:rgb(31,73,125)"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)">Let me offer some snippets from my conf/authn/ldap-authn-config.xml file. Any assistance will be greatly appreciated:<u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)"> <alias name="%{idp.authn.custom.LDAP.authenticator:aggregateAuthenticator}" alias="shibboleth.authn.custom.LDAP.authenticator" /></span></p></div></div></blockquote><div><br></div><div>So are you setting the idp.authn.custom.LDAP.authenticator property or is the default being used? </div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><div lang="EN-US" link="#0563C1" vlink="#954F72"><div><p class="MsoNormal"><span style="color:rgb(31,73,125)"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:rgb(31,73,125)"> <!—I set the ‘…-ref’ property to this new alias for the bean definition of ‘ValidateUsernamePasswordAgainstLDAP’ --></span></p></div></div></blockquote><div><br></div><div>Why did you make that change?</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>