<div dir="ltr">As we retire our legacy SSO, we will need to try to authenticate both against our KDC and a SQL backend (based on whether the principle has an @ in it).<div><br></div><div>Defining multiple backends in a single configuration using "sufficient" is not doing what I expect.  (In fact, "sufficient" just seems to let people into our QA id regardless of whether the password they provide is correct or not).</div><div><br></div><div>I found this thread, with Scott's suggestion to use chained JAAS modules. </div><div><br></div><div><a href="https://marc.info/?l=shibboleth-users&m=146211861020340&w=2">https://marc.info/?l=shibboleth-users&m=146211861020340&w=2</a><br></div><div><br></div><div>Anyone have an example of the "advance usage" as described at <a href="https://wiki.shibboleth.net/confluence/display/IDP30/JAASAuthnConfiguration#JAASAuthnConfiguration-AdvancedJAASUsage3.3">https://wiki.shibboleth.net/confluence/display/IDP30/JAASAuthnConfiguration#JAASAuthnConfiguration-AdvancedJAASUsage3.3</a></div><div><br></div><div>Liam</div><div><br></div></div>