<div dir="ltr">Using a new install of IdP 4.0.1, I am configuring an authenticator that can combine the results of multiple DN resolvers, following the documentation for <i>Single Directory with multiple branches</i> -> <i>Aggregate DN Resolver</i> at <a href="https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration#55804291ae05b98371814cefae58d3bb594a5067">https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration#55804291ae05b98371814cefae58d3bb594a5067</a>. Note, my directory does not support extensible matching.<div><br></div><div><i>I have got this working</i>, but in doing so found that I had to obtain a copy of conf/authn/ldap-authn-config.xml from IdP 3.4 and then create a new ldap-authn-config.xml that restores many of the beans that are now removed from the default 4.0 version of the file. The docs do suggest that this will be necessary, but the example I was following does not show this explicitly and I can't help wondering if I am missing a trick.</div><div><br></div><div>I've attached a copy of my ldap-authn-config.xml. The only changes that I have made to this from the default version are those that I have found necessary to implement my aggregate dn resolver.</div><div><br></div><div>Does this look like a sensible approach, or should I be able to use a simpler configuration?</div><div><br></div><div>Thanks,</div><div><br></div><div>Max Spicer<br>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="font-size:small">IT Services, University of York<br></div></div></div></div></div></div></div></div>