<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.s1
        {mso-style-name:s1;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-GB" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Just use something like this:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">idp.authn.LDAP.baseDN                           = ou=accounts,dc=domain,dc=local (so dc=umb,dc=edu for you)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">idp.authn.LDAP.subtreeSearch                   = true<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">idp.authn.LDAP.userFilter                       = (samaccountname={user})<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Under Accounts, we have Staff and Students also. Then sites, then departments… etc. And the above works fine.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">HTH,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Dave<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D">_________________________________________________<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D">Dave Perry<br>
eLearning Technologist, Hull College Group<br>
<br>
Room L34 - Queens Gardens Library<br>
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG<br>
Extension 2230 / Direct Dial 01482 381930<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D">* Need a fast reply? Try
<a href="mailto:elearning@hull-college.ac.uk"><span style="color:blue">elearning@hull-college.ac.uk</span></a> *<o:p></o:p></span></b></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-left:36.0pt"><b><span lang="EN-US" style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext">From:</span></b><span lang="EN-US" style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext">
 users [mailto:users-bounces@shibboleth.net] <b>On Behalf Of </b>Daniel McDonald<br>
<b>Sent:</b> 15 August 2016 22:53<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Shib v3 IDP with multiple OU's<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">Hi, <br>
<br>
Im trying to configure shibboleth IDP 3.2.1 and having some probs authenticating against our AD....<br>
<br>
We have multiple ou's with no account overlap:<br>
ou=Staff<br>
ou=Students<br>
ou=Faculty<br>
<br>
The doc for <a href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration">
LDAPAuthnConfiguration</a> says that you can have <span class="s1">idp.authn.LDAP.userFilter=</span><br>
<span style="color:#222222">(&(|(ou:dn:=people)(ou:dn:=guests))(uid={user})) and have it search multiple OU's.<br>
<br>
This works for me with just 1 ou in ldap.properties:<br>
idp.authn.LDAP.baseDN                         = ou=Staff,DC=umb,DC=edu<br>
idp.authn.LDAP.userFilter                      = (mail={user})<br>
<br>
But when I try to use what the docs suggest to use 2 OU's it doesnt work:</span><br>
<span style="color:#222222">idp.authn.LDAP.baseDN                         = DC=umb,DC=edu<br>
idp.authn.LDAP.userFilter                       = (&(|(ou:dn:=Staff)(ou:dn=Students))(mail={user}))<br>
<br>
I noticed it says "</span>Active Directory does not fully support extensible match rules" and im im assuming thats why it doesnt work.
<br>
<br>
Does someone have a config that they use to connect to 2 or more OU's in AD that they could share????
<br>
<br>
Thanks!!<br>
Dan<o:p></o:p></p>
</div>

    <div>
      <font color="#999999" size="2">
                <span style="font-family: Arial;"><a href="http://www.hull-college.ac.uk/about-us/stakeholders-newsletter">The Review Newsletter</a></span> </font></div><div><font color="#999999" size="2"><br />
        <font face="Arial">This message is sent in confidence for the addressee </font>
        <span style="font-family: Arial;">only.  It may contain confidential or sensitive </span>
        <span style="font-family: Arial;">information.  The contents are not to be disclosed </span>
        <span style="font-family: Arial;">to anyone other than the addressee.  Unauthorised </span>
        <span style="font-family: Arial;">recipients are requested to preserve this </span>
        <span style="font-family: Arial;">confidentiality and to advise us of any errors in </span>
        <span style="font-family: Arial;">transmission.  Any views expressed in this message </span>
        <span style="font-family: Arial;">are solely the views of the individual and do not </span>
        <span style="font-family: Arial;">represent the views of the College.  Nothing in this </span>
        <span style="font-family: Arial;">message should be construed as creating a contract.</span>
      </font>
    </div>
    <div>
      <font face="Arial" color="#999999" size="2">
        <br />
      </font>
    </div>
    <div>
      <font face="Arial" color="#999999" size="2">Hull College Group owns the email infrastructure, including the contents.</font>
    </div>
    <div>
      <font face="Arial" color="#999999" size="2">
        <br />
      </font>
    </div>
    <div>
      <font face="Arial" size="2" color="#00CC33">Hull College Group is committed to sustainability, please reflect before printing
      this email.</font>
    </div>
    <div>
      <hr />
    </div>



</body>
</html>