<div dir="ltr">Those of you who support FIM4R and have run into the case of a local LDAP separate from the enterprise directory, how are you handling authentication? <br><br>A use case we have is access to several research CI webapps using an LDAP that contains both external collaborators and internal users, plus attributes specific to research services. The internal users also exist in the enterprise LDAP but without the attributes. There is no person registry at present, so this RCI LDAP is effectively authoritative for the attributes and the external collaborators. Our IdP is running v4.3.1.<br><br>I'm trying to avoid having RCI set up their own IdP and proxying to it from the central IdP and instead looking at configuring a second LDAP connector on our central IdP to return the research-specific attributes and authenticate the external users.<br><br>The solution I'm looking at is <a href="https://tinyurl.com/authUsersDifferentLDAPs" target="_blank">https://tinyurl.com/authUsersDifferentLDAPs</a>. The one unknown is how this configuration would behave for non-research service authentication. Only RCI apps should auth against the RCI LDAP.<div><br></div><div>We view this use case as the first phase of bringing RCI into the central IAM fold, so we want to get it right and are interested in best practice.</div><div><div><div><br>If you've encountered a similar use case, what solution did you implement?</div></div></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><b><span style="color:rgb(11,83,148)"><span style="background-color:rgb(255,255,255)"><span style="font-family:monospace"><img src="https://ci3.googleusercontent.com/mail-sig/AIorK4zpRbtQKEfumFa024uUvgVX6y-TmDvn0IU1RsgcUZgQdNxzrpusMRfxo-LMo1knzn-fSC7LFRE"><br></span></span></span></b></div><div><font size="2"><span style="color:rgb(11,83,148)"><b><b><span style="font-size:11.5pt;line-height:105%;font-family:"Arial",sans-serif;color:rgb(0,83,159)">Janemarie Duh</span></b></b></span></font></div><div><font color="#888888"><font size="2"><span style="color:rgb(11,83,148)"><span style="font-size:11.5pt;line-height:105%;font-family:"Arial",sans-serif;color:rgb(0,83,159)"><span style="font-size:10pt;line-height:105%;color:rgb(10,10,10)">UD Information Technologies</span></span></span></font></font></div><div><span style="color:rgb(11,83,148)"><i><span style="color:rgb(0,0,0)">Identity and Access Management Specialist</span></i><b><br></b></span></div><div><span style="color:rgb(11,83,148)"><a href="mailto:duhj@udel.edu" target="_blank"><span style="color:rgb(0,0,0)">duhj@udel.edu</span></a><b><br></b></span></div></div></div></div>