<div dir="ltr"><div dir="ltr"><div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">I've done this via the idp.authn.LDAP.userFilter (used uid and mail address to lookup users) then put the user's identity in a canonical form (conf/c14n/* files).</div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif">Mircea</div><div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div>--</div><div>Mircea Baciu, Senior Unix Systems Administrator<br></div><div><span style="font-size:12.8px">Simmons University | 300 The Fenway | Boston, MA 02115 | 617-521-2194</span><br></div></div></div></div></div></div></div></div><br></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, May 13, 2019 at 3:14 PM Joshua Brodie <<a href="mailto:josbrodie@gmail.com">josbrodie@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Is it possible to have failover password validations, by say email address and uid (same password)?<div><br></div><div>If uid/password combination fails, the email address/password combination will be tried (order not needed -- all attributes in the ldap).</div><div><br></div><div>Thanks.</div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>