<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<br>
Ive been trying to use the example from the link you provided, the
one thats titled: "<span class=" code-title">Complete example with
DN resolvers and authentication handlers for bindSearch" but im
not sure if im adding it to the right place. <br>
<br>
I edited </span>ldap-authn-config.xml and replaced the section
"<!-- Bind Search Configuration -->" (lines 88-110) with the
code from the docs "Complete example...". I then edited
ldap.properties and changed idp.authn.LDAP.ldapURL to
idp.authn.LDAP.ldapURL1 and idp.authn.LDAP.ldapURL2, assigned them
values and did likewise with the rest of the properties. <br>
<br>
I got an LDAP error (Invalid connector configuration) as soon as
shib starts up when it tries to bind. <br>
<br>
I have idp.authn.LDAP.authenticator = bindSearchAuthenticator if
thats relevant.<br>
<br>
Am I editing the right place in ldap-authn-config.xml or should I be
putting the block of code somewhere else?<br>
<br>
Dan<br>
<br>
<div class="moz-cite-prefix">On 08/15/2016 06:06 PM, Raymond Gardner
wrote:<br>
</div>
<blockquote
cite="mid:B14E6ACCB76DE742A71A67C2FDF1C913595BDF73@ITWEGFCLST29000"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.s1
{mso-style-name:s1;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">></span>The
doc for <a moz-do-not-send="true"
href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration">LDAPAuthnConfiguration</a>
says that you can have <span class="s1">idp.authn.LDAP.userFilter=</span><br>
<span style="color:#1F497D">></span><span
style="color:#222222">(&(|(ou:dn:=people)(ou:dn:=guests))(uid={user}))
and have it search multiple OU's.</span><span
style="color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">[Raymond
Gardner] You are getting warm!<o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I
think you want a multiple directories configuration:<o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><a
moz-do-not-send="true"
href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories</a></a><o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">or<o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><a
moz-do-not-send="true"
href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-DNResolution"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-DNResolution">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-DNResolution</a></a><o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></i></b></p>
</div>
<p>****************************************************************
This
email message is intended for the use of the person to whom it
has been sent, and may contain information that is confidential
or legally protected. If you are not the intended recipient or
have received this message in error, you are not authorized to
copy, distribute, or otherwise use this message or its
attachments. Please notify the sender immediately by return
e-mail and permanently delete this message and any attachments.
NTT America makes no warranty that this email is error or virus
free. Thank you.
****************************************************************
</p>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
</body>
</html>