cancel
Showing results for 
Search instead for 
Did you mean: 

Multiple AD servers for failover

dhartford
Champ on-the-rise
Champ on-the-rise
Hi all,
What is the best approach to handle multiple AD servers in a cluster for failover (not different LDAP servers) for Alfresco 4.2.f? 

Attempting this with a DNS alias across all the AD nodes does not work as we get SSL renegotiation errors and can't find an 'approved' way around it (we have strict security requirements, so -Djdk.tls.allowUnsafeServerCertChange=true , -Dsun.security.ssl.allowUnsafeRenegotiation=true are not allowed).

Do not get the impression that mulitple ldap-ad1 / ldap-ad2 configuration files would work related to dual-synchronization challenges around duplicates, but looking for feedback.

-D
1 REPLY 1

gnyce
Champ in-the-making
Champ in-the-making
Perhaps I am not understanding the question completely, but - can't you just specify multiple AD servers for a passthru auth chain? This is what we do for CIFS auth, but - you don't say _what_ you are authenticating (e.g. web, webdav, cifs, ftp).
  passthru.authentication.servers=192.168.1.1,192.168.5.100,192.168.10.54
  #Offline server check interval in seconds
  passthru.authentication.offlineCheckInterval=300