<div dir="ltr">Is there a way to base the LDAP authN source (this AD/LDAP directory or that one) based on the service making the request? Preferably using jaas.config in v3.<div><br></div><div>(FWIW, the use case is for AD accounts that are set as expired or locked by the AD team, but who still should have access to a limited range of services. For these accounts a proxy authenticator is provided with the API of AD but which delivers a "success" even for these expired or locked accounts. I don't want to list this authN proxy as the first LDAP for all cases in a jaas.config, because it's a single point of failure and is only needed in ~1% of cases; I can't put it after the primary sources because they will (correctly) report failure before the proxy has its chance. A bad conflation of authN and authZ perhaps, but there it is.)<div><br></div><div>David Bantz</div></div><div>UA OIT IAM</div></div>