Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Grouper/LDAPPCNG Questions

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Grouper/LDAPPCNG Questions

Chronological Thread 
  • From: Tom Zeller <>
  • To: Joshua Brodie <>
  • Cc:
  • Subject: Re: [grouper-users] Grouper/LDAPPCNG Questions
  • Date: Mon, 7 Feb 2011 12:37:02 -0600
  • Domainkey-signature: a=rsa-sha1; c=nofws;; s=gamma; h=mime-version:sender:in-reply-to:references:from:date :x-google-sender-auth:message-id:subject:to:cc:content-type; b=VCKDVHMp+anl45KzfJPo8O78lPnIpxkh6hkXMxxdcmDnLNwNUglDPBfVEzw/DJQmK+ XneCaepvbLiv609/dtyS25ffkpXGK5oygRjnVGQ8oM/ADqmo2avh0x8BFPgoW/kCH63I kvZ0Rzthgc+x4UUkzlreFcelWFV63JLiAF3nQ=

To answer the question you did not ask, no, the configuration file
names are not intuitive. This should be improved.

Ldappcng (1.6+) requires the Shibboleth Attribute Resolver, while for
ldappc (1.5+) the Shibboleth Attribute Resolver is optional. Since
ldappc (1.5+) was first, some filenames retain ldappc. Perhaps each
version (1.5+ or 1.6+) should have separate configuration directories
in future releases.

For ldappcng (and ldappc), the following configuration filenames are
not configurable :


The names of the remaining configuration files are defined in
ldappc-services.xml, and by default are :


Each configuration file accepts a macro substitution file, by default,

The ldappcng configuration is, by default, ldappcng.xml :

<!-- the provisioning service provider is required for ldappcng, not
ldappc -->
<Service id="ldappc" ...
<ConfigurationResource file="/ldappcng.xml" ...
<ResourceFilter propertyFile="/" ...

The Shibboleth Attribute Resolver configuration is, by default,
ldappc-resolver.xml :

<!-- the attribute resolver id must be grouper.AttributeResolver -->
<Service id="grouper.AttributeResolver" ...
<ConfigurationResource file="/ldappc-resolver.xml" ...
<ResourceFilter propertyFile="/" ...

LDAP connection configuration provided by vt-ldap is, by default,
ldappc-ldap.xml :

<!-- the ldap provider is required for ldappcng, not ldappc -->
<Service id="ldap-provider" ...
<ConfigurationResource file="/ldappc-ldap.xml"
<ResourceFilter propertyFile="/" ...

> I'm planning on implementing ldappcng with an active directory (using with
> Grouper 1.6.3).
> A couple of questions:
> 1) According to,
> there is a 'ldappcng.xml' properties file - I could not find it: is it the
> '' file?

The macro substitution properties file,, is supplied

> 2) Are my understanding of the following property files correct?
> - not needed for ldappcng implementation

Correct. This is for ldappc (1.5+)

> - is this the 'ldapcng.xml' file mentioned in

Yes, rename to ldappcng.xml.

> - not needed for ldadpcng or is this the
> 'ldappcng.xml' file mentioned at

Rename to See (1).

> ldappc-internal.example.xml - not sure yet what this is for; please see Q3
> below
> ldappc-resolver.example.xml - not sure yet what this is for; please see Q3
> below
> ldappc-services.example.xml - not sure yet what this is for; please see Q3
> below
> 3) Why are the following three configuration files listed as 'Shibboleth
> Attribute Resolver' at
> Are they to be only
> used in conjunction with Shibboleth and can otherwise be ignored?
> ldappc-internal.xml Shibboleth Attribute Resolver
> ldappc-services.xml Shibboleth Attribute Resolver
> ldappc-resolver.xml Shibboleth Attribute Resolver

These are all required by ldappcng.

Apologies for the confusion,

Archive powered by MHonArc 2.6.16.

Top of Page