<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hello, I am in need a little assistance regarding planning and design.<o:p></o:p></p>
<p class="MsoNormal">I am fairly new to Shibboleth, and have been playing around with it for about 3 weeks now.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">A project assigned is requesting that Shibboleth be implemented.<o:p></o:p></p>
<p class="MsoNormal">This will consist of over 30 remote directories, which will either be AD or OpenLDAP.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Currently, I have setup a Test Shibboleth IdP pointing to our LDAP directory with some Test SP's. Attributes and custom attributes configured are being passed as expected.<o:p></o:p></p>
<p class="MsoNormal">I have also setup a Test IdP that is bound with our AD. The attributes are also being passed after configuring it.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I have a few questions that I cannot seem to find after extensive searching.<o:p></o:p></p>
<p class="MsoNormal">What is the best solution for this design?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Is it better to have one IdP with 30+ directories or will this cause logins to take forever. Is it even possible to have a mix of AD and LDAP on one IdP.<o:p></o:p></p>
<p class="MsoNormal">I've read the docs at https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration but could not determine an answer regarding multiple directories.<o:p></o:p></p>
<p class="MsoNormal">Attribute translation would also need to somehow occur, such as sAMAccountName --> uid<o:p></o:p></p>
<p class="MsoNormal">We could probably have all the remote directories replicate to our building so latency and schools dropping off the network will not cause an issue.<o:p></o:p></p>
<p class="MsoNormal">This is what I am preferring now, as the searchfilter would use mail to find the user, eliminating the need for WAYF DS.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Or, would it be better to have multiple IdP's, one per school. This would end up with over 30 IdP's which sounds like a management nightmare.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Also, is it possible to get multiple IdP's to "trust" eachother?<o:p></o:p></p>
<p class="MsoNormal">We will have an IdP (simpleSAMLphp) provided by the state to serve state SP's<o:p></o:p></p>
<p class="MsoNormal">Our own Shibboleth IdP will serve specific instances in the region, with regional SP's provided by us.<o:p></o:p></p>
<p class="MsoNormal">Both of these IdP's will pull from the same data sources. <o:p>
</o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Other than setting the SP to accept multiple IdP's, is there a way to configure IdP "trust"<o:p></o:p></p>
<p class="MsoNormal">I've read up on some of the relying party docs but don't know if this is the correct thing to read.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">To complicate things further (for me at least) Is there a way to configure complex queries?
<o:p></o:p></p>
<p class="MsoNormal">Currently with CAS, there is an attribute that is passed from the entries group.<o:p></o:p></p>
<p class="MsoNormal">The LDAP query will need to perform a query based on an ou entry from the uid, retrieve the information it needs, and construct a new query to return the correct attribute (such as a District ID).
<o:p></o:p></p>
<p class="MsoNormal">If there is no way to do this, the common attribute could probably just be included with every user record as a workaround.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any design suggestions will be appreciated.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks!<o:p></o:p></p>
</div>
</body>
</html>