Hello,
You can absolutely do this.
If you return an external user header, groups header and extra attributes headers, WebSEAL will build a credential for that user (and populate the specified groups) for a user thy doesn't exist in ISAM LDAP.
You can do the same from AAC Authentication Service or Federation Runtime by setting the POC mode to External User.
To authenticate against a database you'll probably have to write a full EAI App since those capabilities are not build into the JavaScript extensions. A hybrid approach would be to have AAC Authentication Mechanisn call to an external REST service which Does the DB work.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------