29 | | ldapURL="ldaps://edir.alaska.edu:636" baseDN="ou=people,dc=alaska,dc=edu" principal="uid=shibboleth03,ou=resource,dc=alaska,dc=edu" |
30 | | principalCredential="shibboleth+20090303"> |
| 31 | ldapURL="ldaps://edir.alaska.edu:636" baseDN="ou=people,dc=alaska,dc=edu" |
| 32 | principal="uid=shibboleth03,ou=resource,dc=alaska,dc=edu" |
| 33 | principalCredential="•••••••••"> |
39 | | The !FilterTemplate supports user login with their UA Username or their ID #. |
| 42 | The !FilterTemplate supports user login with their UA Username (in uasystemid) or their ID # (in bannerid) or their edir UID. |
| 43 | |
| 44 | The UA Domain AD as of 2013-04 is defined as a single node connection: |
| 45 | {{{ |
| 46 | <resolver:DataConnector id="uaADLDAP" xsi:type="LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc" |
| 47 | ldapURL="ldaps://fbk-adua02.ua.ad.alaska.edu:3269" baseDN="ou=useraccounts,dc=ua,dc=ad,dc=alaska,dc=edu" |
| 48 | principal="cn=uashib,ou=uaf_service,ou=uaf,dc=ua,dc=ad,dc=alaska,dc=edu" principalCredential="•••••••••"> |
| 49 | <FilterTemplate> |
| 50 | <![CDATA[ |
| 51 | (|(sAMAccountName=$requestContext.principalName)(uaIdentifier=$requestContext.principalName)) |
| 52 | ]]> |
| 53 | </FilterTemplate> |
| 54 | </resolver:DataConnector> |
| 55 | }}} |
| 56 | The !FilterTemplate supports user login with their UA Username (in sAMAcountName) or their UA ID# (in uaidentifier). |
| 57 | |
| 58 | In the future, a subset of the UA AD servers might be put into a equalizer cluster, providing redundancy similar to edir. |
| 59 | As a fall-back, this !DataConnector might be configured with failover (see below). |