Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6958259
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 27, 20262026-05-27T15:06:59+00:00 2026-05-27T15:06:59+00:00

This is something that has popped up our organization and I am looking for

  • 0

This is something that has popped up our organization and I am looking for a word of advice on it. We all used windows active directory and there were no issues until few application groups have figured out they either get too little support from the organization’s IT infra team or they don’t feel they are able to solve their needs within given infra environment. This all ended up having a few applications that use domain’s active directory, a couple that use active directory but they as well use their own LDAP for settings access permissions to their applicaions and another application (that’s quite outstanding here – Ciebel CRM) that uses their very own authentication model because they require external users in their application and local policy doesn’t allow creating them within the AD domain.

It has worked out until now that we have to hook them into some sort of integration. We can’t move all of them to organization’s active directory (this option would be the one I prefer), and there are a few very strong reasons why this is not possible.

So I was thinking if there is a authentication server (or whatever this may be called) that’s able to authenticate a user against multiple user sources? Say, company’s AD (for all apps that only use that are their source or user data and so on) and another LDAP server (or something else) that could be used for applications that need both “external” and internal users to be able to authenticate with them?

Couple more bits of information on this if helpful at all – the apps are a mixture of C++, Java, .NET and web applications. The integration I’ve mentioned is typically something like: appliction A sends a message or pulls a service to application B and attaches user token to it and I’m expecting application B to be able to talk to the auth server and understand if that’s a valid user token and what that user’s group/attributes are.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-27T15:07:00+00:00Added an answer on May 27, 2026 at 3:07 pm

    This seems to be a case for using a security token service (sts) where you can present a given credential (e.g. user@domain1), and this sts gives back to you the token designed for the desired target service.

    I’m not aware of any STS that is exactly what you want, but you could try to implement one yourself using some framework (e.g. apache axis2 with rampart). The STS itself is just a web-service, you still have to glue all this stuff together (i.e. write the code that will handle the different backend authentication directories), the advantage is that you hide all this ugly stuff behind a well defined web service.

    I guess you can implement a conformant STS using JAX-WS, or Jboss’ PicketLink STS.

    Best regards

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I saw this same question for VIM and it has been something that I
I can see that this is something that has been troubling a lot of
This is something that has always bothered me about PHP and I have never
This is something that has frustrated me for a long time (dozens of hours)
This is something that has always bothered me. Wouldnt it make more sense to
This is something that has been driving me mad over the past few days.
I know this is something that has been discussed over and over, and I
I have three models that look something like this: class Bucket < ActiveRecord::Base has_many
This is something that I think would be very useful. Basically, I'd like there
This is something that I always find a bit hard to explain to others:

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.