<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Here are some logs from scenario 1 with user ‘login1’ which only exists in our openLDAP instance. The user has issues with the FormatDnResolver for Active Directory,
as expected.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">But, these FormatDnResolver issues seem to cause authentication to fail. It seems to be doing a search against our openLDAP and a bind against our Active Directory.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,824 - DEBUG [org.springframework.webflow.execution.ActionExecutor:49] - Executing
<a href="mailto:net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP@1ef9e927">
net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP@1ef9e927</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,824 - DEBUG [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:131] - Profile Action ValidateUsernamePasswordAgainstLDAP:
Attempting to authenticate user login1<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,826 - DEBUG [org.ldaptive.auth.AggregateDnResolver:158] - submitted DN resolver [org.ldaptive.auth.PooledSearchDnResolver@70985093::factory=[org.ldaptive.pool.PooledConnectionFactory@750857363::pool=[org.ldaptive.pool.BlockingConnectionPool@972662499::name=search-pool,
poolConfig=[org.ldaptive.pool.PoolConfig@263777208::minPoolSize=3, maxPoolSize=10, validateOnCheckIn=false, validateOnCheckOut=false, validatePeriodically=true, validatePeriod=300], activator=null, passivator=null, validator=[org.ldaptive.pool.SearchValidator@1608024946::searchRequest=[org.ldaptive.SearchRequest@1736332787::baseDn=,
searchFilter=[org.ldaptive.SearchFilter@1642584434::filter=(objectClass=*), parameters={}], returnAttributes=[1.1], searchScope=OBJECT, timeLimit=0, sizeLimit=1, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null,
searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null]] pruneStrategy=[org.ldaptive.pool.IdlePruneStrategy@2091945142::prunePeriod=300, idleTime=600], connectOnCreate=true, connectionFactory=[org.ldaptive.DefaultConnectionFactory@783558968::provider=org.ldaptive.provider.jndi.JndiProvider@474d16e3,
config=[org.ldaptive.ConnectionConfig@1340261334::ldapUrl=ldap://open.ldap.domain.name:389, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig@518795353::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@3bd31309,
trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer@1223147848::bindDn=cn=bindAccount,dc=domain1,dc=domain2,
bindSaslConfig=null, bindControls=null]]], initialized=true, availableCount=3, activeCount=0]], baseDn=ou=oUnit,dc=domain1,dc=domain2, userFilter=(sn={user}), userFilterParameters=null, allowMultipleDns=false, subtreeSearch=true, derefAliases=null, followReferrals=false]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,826 - DEBUG [org.ldaptive.auth.PooledSearchDnResolver:244] - resolve user=login1<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,827 - DEBUG [org.ldaptive.auth.AggregateDnResolver:158] - submitted DN resolver [org.ldaptive.auth.FormatDnResolver@168467718::formatString=AD\%s,
formatArgs=null, escapeUser=true]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,827 - DEBUG [org.ldaptive.auth.AggregateDnResolver:162] - waiting on DN resolver …<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,834 - DEBUG [org.ldaptive.auth.FormatDnResolver:157] - Formatting DN for login1 with AD\%s<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,835 - DEBUG [org.ldaptive.auth.AggregateDnResolver:165] - DN resolver …, availableCount=2, activeCount=1 … resolved dn adDirectory:AD\login1<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:23,836 - DEBUG [org.ldaptive.SearchOperation:138] - execute request=[org.ldaptive.SearchRequest@-936973022::baseDn=ou=oUnit,dc=domain1,dc=domain2,
searchFilter=[org.ldaptive.SearchFilter@-194221250::filter=(sn={user}), parameters={user=login1}], returnAttributes=[1.1], searchScope=SUBTREE, timeLimit=0, sizeLimit=0, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=null,
searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null] with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection@1458652852::config=[org.ldaptive.ConnectionConfig@1340261334::ldapUrl=ldap://open.ldap.domain.name:389,
connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig@518795353::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@3bd31309, trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null],
useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer@1223147848::bindDn=cn=bindAccount,dc=domain1,dc=domain2, bindSaslConfig=null, bindControls=null]], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiConnectionFactory@1306434347::metadata=[ldapUrl=ldap://open.ldap.domain.name:389,
count=1], environment={com.sun.jndi.ldap.connect.timeout=3000, java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig@2088272085::operationExceptionResultCodes=[PROTOCOL_ERROR,
SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy@1738c37e, controlProcessor=org.ldaptive.provider.ControlProcessor@508972a, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED,
SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null]],
<a href="mailto:providerConnection=org.ldaptive.provider.jndi.JndiConnection@7a5eaace">
providerConnection=org.ldaptive.provider.jndi.JndiConnection@7a5eaace</a>]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,238 - DEBUG [org.ldaptive.SearchOperation:168] - execute response=[org.ldaptive.Response@1413423838::result=[org.ldaptive.SearchResult@154843235::entries=[[dn=cn=login1,ou=oUnit,dc=domain1,dc=domain2[],
responseControls=null, messageId=-1]], references=[]], resultCode=SUCCESS, message=null, matchedDn=null, responseControls=null, referralURLs=null, messageId=-1] for request=[org.ldaptive.SearchRequest@-936973022::…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,240 - DEBUG [org.ldaptive.auth.AggregateDnResolver:165] - DN resolver [org.ldaptive.auth.FormatDnResolver@168467718::formatString=AD\%s, formatArgs=null,
escapeUser=true] resolved dn openLDAPDirectory:cn=login1,ou=oUnit,dc=domain1,dc=domain2<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,242 - DEBUG [org.ldaptive.BindOperation:138] - execute request=[org.ldaptive.BindRequest@928813590::bindDn=AD\login1, saslConfig=null, controls=null]
with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection@1640130246::config=[org.ldaptive.ConnectionConfig@378789712::ldapUrl=ldap://ad.domain.name:389, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig@518795353::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@3bd31309,
trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=null], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiConnectionFactory@2135050842::metadata=[ldapUrl=ldap://ad.domain.name:389,
count=1], environment={com.sun.jndi.ldap.connect.timeout=3000, java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig@1001747042::operationExceptionResultCodes=[PROTOCOL_ERROR,
SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy@1738c37e, controlProcessor=org.ldaptive.provider.ControlProcessor@5dd8908d, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED,
SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null]], providerConnection=org.ldaptive.provider.jndi.JndiConnection@25b0833c]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,324 - DEBUG [org.ldaptive.auth.PooledBindAuthenticationHandler:85] - authenticate response=[org.ldaptive.auth.AuthenticationHandlerResponse@963447754::…,
result=false, resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 52e, v2580^@], controls=null] for criteria=[org.ldaptive.auth.AuthenticationCriteria@808830405::dn=AD\login1,
authenticationRequest=[org.ldaptive.auth.AuthenticationRequest@1838494916::user=login1, retAttrs=[*, +]]]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,324 - TRACE [org.ldaptive.auth.Authenticator:386] - resolved entry=[dn=AD\login1[]] with resolver=[org.ldaptive.auth.NoOpEntryResolver@682793413]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,325 - INFO [org.ldaptive.auth.Authenticator:259] - Authentication failed for dn: adDirectory:AD\login1<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,326 - DEBUG [org.ldaptive.auth.Authenticator:284] - authenticate response=[org.ldaptive.auth.AuthenticationHandlerResponse@963447754::…, result=false,
resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 52e, v2580^@], controls=null] for dn=adDirectory:AD\login1 with request=[org.ldaptive.auth.AuthenticationRequest@1838494916::user=login1,
retAttrs=[*, +]]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,326 - TRACE [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:137] - Profile Action ValidateUsernamePasswordAgainstLDAP:
Authentication response [org.ldaptive.auth.AuthenticationResponse@1642715148::authenticationResultCode=AUTHENTICATION_HANDLER_FAILURE, ldapEntry=[dn=AD\login1[]], accountState=null, result=false, resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException:
[LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903D0, comment: AcceptSecurityContext error, data 52e, v2580^@], controls=null]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">2016-06-29 15:50:24,326 - INFO [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:152] - Profile Action ValidateUsernamePasswordAgainstLDAP: Login
by 'login1' failed<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Daniel Fisher<br>
<b>Sent:</b> Thursday, June 30, 2016 9:54 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: IDPv3.1.2 LDAP connector: using two distinct LDAP servers?<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<div>
<p class="MsoNormal">On Thu, Jun 30, 2016 at 7:42 PM, Raymond Gardner <<a href="mailto:r.gardner@ntta.com" target="_blank">r.gardner@ntta.com</a>> wrote:<o:p></o:p></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:4.5pt">
<span style="color:#1F497D"><br>
Authentication for login1 fails:</span><o:p></o:p></p>
<p style="margin-left:58.5pt"><span style="font-family:"Courier New";color:#1F497D">o</span><span style="font-size:7.0pt;color:#1F497D">
</span><span style="color:#1F497D">Successful authentication against LDAP1</span><o:p></o:p></p>
<p style="margin-left:58.5pt"><span style="font-family:"Courier New";color:#1F497D">o</span><span style="font-size:7.0pt;color:#1F497D">
</span><span style="color:#1F497D">Failed authentication against LDAP2</span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D">Authentication for login2 succeeds:</span><o:p></o:p></p>
<p style="margin-left:58.5pt"><span style="font-family:"Courier New";color:#1F497D">o</span><span style="font-size:7.0pt;color:#1F497D">
</span><span style="color:#1F497D">Successful authentication against LDAP1 – I don’t understand this; this should not be successful as this user does not exist in this LDAP instance; I’m positive</span><o:p></o:p></p>
<p style="margin-left:58.5pt"><span style="font-family:"Courier New";color:#1F497D">o</span><span style="font-size:7.0pt;color:#1F497D">
</span><span style="color:#1F497D">Successful authentication against LDAP2</span><o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">I'd have to see some logs to make sense of this. Only one bind should be occurring, so this is strange.<o:p></o:p></p>
<p class="MsoNormal"><b><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">[Raymond Gardner] I tried sending more logs but your email server limits the size of emails to < 65K. I’m not sure if there is something specific that
I am missing.</span></i></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D">Let me offer some snippets from my conf/authn/ldap-authn-config.xml file. Any assistance will be greatly appreciated:</span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D"> <alias name="%{idp.authn.custom.LDAP.authenticator:aggregateAuthenticator}" alias="shibboleth.authn.custom.LDAP.authenticator" /></span><o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">So are you setting the idp.authn.custom.LDAP.authenticator property or is the default being used? <o:p></o:p></p>
<p class="MsoNormal"><b><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">[Raymond Gardner]
</span></i></b><b><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Correct. ‘idp.authn.custom.LDAP.authenticator’ is set in my conf/idp.properties file. And, I set it to the same ‘aggregateAuthenticator’ value that is listed
here as a default.</span></i></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="color:#1F497D"> <!—I set the ‘…-ref’ property to this new alias for the bean definition of ‘ValidateUsernamePasswordAgainstLDAP’ --></span><o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Why did you make that change?<o:p></o:p></p>
<p class="MsoNormal"><b><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">[Raymond Gardner]
</span></i></b><b><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I made this change because I am supporting two different SPs with two different authentications. SP1 uses the standard ‘adAuthenticator’ that Shibboleth provides.<o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I’m trying to also support SP2 which will need the ‘aggregateAuthenticator’. So, I created a 2<sup>nd</sup> validate bean. I have also created a 2<sup>nd</sup>
password authentication flow. So, any requests coming from SP2 uses the 2<sup>nd</sup> password authentication flow, which uses the 2<sup>nd</sup> validate bean, which uses the ‘aggregateAuthenticator’. It all seems to flow correctly except for the LDAP
binding and the authentication result.</span></i></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">--Daniel Fisher<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
<p>****************************************************************
This email message is intended for the use of the person to whom it has been sent, and may contain information that is confidential or legally protected. If you are not the intended recipient or have received this message in error, you are not authorized to copy, distribute, or otherwise use this message or its attachments. Please notify the sender immediately by return e-mail and permanently delete this message and any attachments. NTT America makes no warranty that this email is error or virus free. Thank you.
****************************************************************
</p>
</body>
</html>