grouper-users - Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute
Subject: Grouper Users - Open Discussion List
List archive
- From: Tom Zeller <>
- To: Arnaud Deman <>
- Cc: "" <>
- Subject: Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute
- Date: Fri, 20 May 2011 14:35:33 -0700
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:from:date :x-google-sender-auth:message-id:subject:to:cc:content-type :content-transfer-encoding; b=mUEXO5nyQRTXxwdl5Zfp0fuwX0+kmY88oBGGLQwW0pTKmkRxgCPKaHN2mbAfs2CnCy 88i7ii+Ne9Cv2YHjccnReK2imcuubCWMNfxw8pxMvc1LBQJ6ait6BCaMtByFyTo29i1R SUhjkus4bCY0aZSEuFRYevAMkaBxqJZ4gab6A=
> The difficulty will be to determine which subject ids have to be
> synchronized. Is there a way to do that easily with Grouper ?
As of now for 2.0, the subject ids for each provisioned object (e.g.
stem, group, member, etc.) are returned from a shibboleth attribute
resolver data connector, which is configurable as well as extensible.
So, yes, for 2.0 I would say it is easy enough.
TomZ
>>Right. If a subject is not a member of any groups, then the current
>>ldappcng 1.x code will not include the subject for provisioning, so
>>their memberships will not be deleted from the provisioning target.
>>This is a bug.
>>
>>I have uncommitted code for 2.0 which will allow us to specify the
>>objects for provisioning in a configurable way through the shibboleth
>>attribute resolver.
>
>>For now, one would have to run gsh.sh -ldappcng -calc|diff|sync <subjectid>.
>
>>With ldappcng, for consistency, I tried to maintain the behavior of
>>ldappc from previous versions, which itself was incorrect, so I persisted
>>this bug.
>
>>>On Tue, May 17, 2011 at 10:35 AM, Arnaud Deman
>>><>
>>> wrote:
>>> Hello,
>>>
>>> I have tested with the intervalFullSync argument and the subjects
>>> removed
>>> to all their groups are still not deprovisionned. It is also the case
>>> when I launch ldappcns whithout the argument bulkSync alone.
>>>
>>>
>>> Thanks,
>>> Arnaud.
>
>
>
> Le vendredi 08 avril 2011 à 01:42:26, Tom Zeller a écrit :
>> I added a -intervalFullSync <seconds> option. See the updated bug.
>>
>> [1] https://bugs.internet2.edu/jira/browse/GRP-595
>
> --
> Arnaud Deman
> 04 91 28 85 25
> DSI - Université Paul Cézanne Aix-Marseille III
> Avenue Escadrille Normandie-Niemen
> 13397 MARSEILLE CEDEX 20
>
>
- Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute, Arnaud Deman, 05/18/2011
- Re: [grouper-users] ldappc-ng and deprovisioning of isMemberOf attribute, Tom Zeller, 05/20/2011
Archive powered by MHonArc 2.6.16.