<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
There are docs on setting up multiple directories using aggregate dn resolver.  Maybe that's what you're looking for?</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<a href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories</a><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0; margin-bottom:0"></p>
<div><br>
</div>
<div><br>
</div>
<div>-------------------------------</div>
<div>Craig Pluchinsky</div>
<div>IT Services</div>
<div>Indiana University of Pennsylvania</div>
<div>724-357-3327</div>
<p style="margin-top: 0px; margin-bottom: 0px;"></p>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Adriano <Adriano.Dalessio@avasad.ch><br>
<b>Sent:</b> Friday, October 25, 2019 8:37 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Multiple LDAP domains on the same IDP</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">Peter Schober wrote<br>
> The main criterion should be (and I'm not sure your above liste was<br>
> intended to specify this or not) whether userids are either guaranteed<br>
> to be mutually exclusive to each domain, or -- where the same userid<br>
> may exist in both domains -- that at least it represents the same<br>
> person (though that may still cause issues with differing passwords<br>
> for the two accounts).<br>
<br>
Both domains are completly separated. Users from one domain can't be in the<br>
second one (as in, they can't be the same "physical" person). As for the<br>
actual value of the nameid, the domains have different naming conventions<br>
which makes it impossible to have the same value from one domain to another.<br>
<br>
<br>
Peter Schober wrote<br>
> There's also the question of multiple MS-AD domains in a "forest" (?) <br>
> where you can authenticate accounts in multiple domains using a single <br>
> LDAP configuration. But I know nothing about MS. <br>
<br>
Both domains are built the same: one forest with a unique domain. So<br>
different LDAP configuration required, I suppose.<br>
<br>
We tried to find documentations about configuration for multiple domains but<br>
had no luck so far. From the infos we could gather, we need to:<br>
<br>
-duplicate the ldap.properties file and reference them in the idp.properties<br>
file (done)<br>
-Change value according the domains informations (ldap1.properties and<br>
ldap2.properties) (done)<br>
<br>
The rest of the configuration seems to be in the ldap-authn-config.xml file,<br>
but i haven't seen anything precise for this part... So far ldap2.properties<br>
seems to be processed by Shibboleth (and ldap1.properties is ignored or<br>
overriden).<br>
<br>
<br>
<br>
<br>
<br>
--<br>
Sent from: <a href="https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">
https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</div>
</body>
</html>