Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute

Chronological Thread 
  • From: Arnaud Deman <>
  • To: "" <>
  • Subject: Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute
  • Date: Wed, 18 May 2011 09:21:24 +0200


I made an error and sent my question directly to Tom and not to the list
so I paste the initial mails below, sorry...

The difficulty will be to determine which subject ids have to be
synchronized. Is there a way to do that easily with Grouper ?

Best Regards,

>Right. If a subject is not a member of any groups, then the current
>ldappcng 1.x code will not include the subject for provisioning, so
>their memberships will not be deleted from the provisioning target.
>This is a bug.
>I have uncommitted code for 2.0 which will allow us to specify the
>objects for provisioning in a configurable way through the shibboleth
>attribute resolver.

>For now, one would have to run -ldappcng -calc|diff|sync <subjectid>.

>With ldappcng, for consistency, I tried to maintain the behavior of
>ldappc from previous versions, which itself was incorrect, so I persisted
>this bug.

>>On Tue, May 17, 2011 at 10:35 AM, Arnaud Deman
>> wrote:
>> Hello,
>> I have tested with the intervalFullSync argument and the subjects
>> removed
>> to all their groups are still not deprovisionned. It is also the case
>> when I launch ldappcns whithout the argument bulkSync alone.
>> Thanks,
>> Arnaud.

Le vendredi 08 avril 2011 à 01:42:26, Tom Zeller a écrit :
> I added a -intervalFullSync <seconds> option. See the updated bug.
> [1]

Arnaud Deman
04 91 28 85 25
DSI - Université Paul Cézanne Aix-Marseille III
Avenue Escadrille Normandie-Niemen

Archive powered by MHonArc 2.6.16.

Top of Page