cancel
Showing results for 
Search instead for 
Did you mean: 

LDAP Destination with two separate search paths

asif_rahmetulla
Participant
0 Kudos

Hello All,

We have two separate base DNs one for contractors "ou=tisubcon,ou=person,dc=ti,dc=com" and another one for employees "ou=tiemployee,ou=person,dc=ti,dc=com". Is there a way one LDAP destination can be define that would search both DNs for userid authentication.

The connection test works if we specify single search base "UID=$USERID,ou=tisubcon,ou=person,dc=ti,dc=com. However, the desire here is to make a single LDAP destination work for both contractors and employees authentication.

Please provide your feedback.

Regards,

Asif

asif_rahmetulla
Participant
0 Kudos

Hello all,

I would like to share how we addressed the situation with multiple LDAP search base DNs. We defined two different LDAP destinations one for each organizational unit. Then configured policy configuration with multiple LDAP login modules pointing to each LDAP destination.

This is also explained in the SAP Single Sign On implementation guide.

For example, you can now use the following search base DNs in the LDAP Server ID Mapping mode section of Destination Management .

LDAP destination for Prod01

Search Base DN OU=Prod01, DC=domain, DC=com

LDAP destination for Prod02

Search Base DN OU=Prod02, DC=domain, DC=com

Hope this helps!

Regards,

Asif

Accepted Solutions (0)

Answers (1)

Answers (1)

asif_rahmetulla
Participant
0 Kudos

Hello all,

I would like to share how we addressed the situation with multiple LDAP search base DNs. We defined two different LDAP destinations one for each organizational unit. Then configured policy configuration with multiple LDAP login modules pointing to each LDAP destination. This is also explained in the SAP Single Sign On implementation guide.

For example, you can now use the following search base DNs in the LDAP Server ID Mapping mode section of Destination Management .

LDAP destination for Prod01

Search Base DN OU=Prod01, DC=domain, DC=com

LDAP destination for Prod02

Search Base DN OU=Prod02, DC=domain, DC=com

Hope this helps!

Regards,

Asif