I was having quite a difficult time with this setup a few years ago. Ideally I would have liked to do RSA as the primary and AD as the secondary. However, if AD is secondary I cannot pull back group memberships to do proper mapping (AD is our central book of records). Having AD as a primary would work, however putting AD up for the world to try and lock out seemed like a pretty bad idea... In the end I came up with this solution (due to a multi-domain environment and the need for a single web site sign-in for all users): RSA as primary sign in RADIUS as secondary sign in, which does LDAP lookups, authentication and returns group memberships via custom scripts. P
... View more