Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Query on Naming Conflicts - Grouper, ldappcng, AD

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Query on Naming Conflicts - Grouper, ldappcng, AD

Chronological Thread 
  • From: "RL 'Bob' Morgan" <>
  • To: Tom Zeller <>
  • Cc: "Mailvaganam, Hari" <>, "" <>
  • Subject: Re: [grouper-users] Query on Naming Conflicts - Grouper, ldappcng, AD
  • Date: Thu, 10 Mar 2011 10:24:19 -0800 (PST)

At UW we put group names into sAMAccountName of our campus-wide AD, hence had to create a group name space that is non-conflicting with our general username space, and also conforms to restrictions in sAMAccountName syntax. This led us to these designs:

which carves out subspaces of the greater NetID namespace for various purposes including groups.

Note that among other things sAMAccountNames can't have ":" in them. So we are obliged to work around the hard-coding of ":" as group-id
delimiter in Grouper by translating it to "_" in every external view, including our Groups Service UI.

See here for user documentation:

- RL "Bob"

On Thu, 10 Mar 2011, Tom Zeller wrote:

At Memphis, we make sure that our Active Directory RDNs are unique,
whether they be users, groups, contacts, etc., and these RDNs are
provisioned to sAMAccountName. Whenever a new person, group, or
contact is created, we check our namespace for uniqueness.

Silly, but, you might get away with adding a prefix to sAMAccountName
for groups.

On Wed, Mar 9, 2011 at 5:59 PM, Mailvaganam, Hari

We are looking at pushing groups from Grouper, via LDAPPCNG, to Active
Directory (AD).

In example scenario below, for group and person, there will be a clash in
sAMAccountName – would you have any suggestions on policies, or rules, to
avoid similar conflict?


Distinguished Name (DN):

sAMAccountName: science


Distinguished Name (DN):

sAMAccountName: science


Best regards,


Archive powered by MHonArc 2.6.16.

Top of Page