grouper-users - Re: [grouper-users] Design question
Subject: Grouper Users - Open Discussion List
List archive
- From: Tom Barton <>
- To:
- Subject: Re: [grouper-users] Design question
- Date: Wed, 06 Mar 2013 17:17:25 -0600
- Authentication-results: sfpop-ironport04.merit.edu; dkim=neutral (message not signed) header.i=none
Legacy attributes, as we use, spring into existence with the
creation of a (legacy) group type. Group types are available to
anyone with ADMIN on a group to assign to that group. Once a type is
assigned, its attributes are available to be filled in by an ADMIN.
I would say this isn't a great model for delegation since there's no
constraint on it. We have probably gotten away with it for
provisioning purposes because only a few IT people know what to put
in there or would have the gumption to do so. New attributes have a much better security model, in particular, supporting constrained delegation. In a more perfect world I'd convert our existing practice to those (right after we upgrade our grouper to the current rev!). I don't know whether PSP currently could meet our LDAP and AD provisioning needs, but I'm hopeful that further development of that part of grouper will resume before long, and we'll be able to put our feature requests on the table with everyone else. Tom On 3/4/2013 1:05 PM, Earl Lewis wrote:
|
- [grouper-users] Design question, Earl Lewis, 03/01/2013
- Re: [grouper-users] Design question, Earl Lewis, 03/01/2013
- Re: [grouper-users] Design question, Tom Barton, 03/02/2013
- Re: [grouper-users] Design question, Earl Lewis, 03/04/2013
- Re: [grouper-users] Design question, Tom Barton, 03/06/2013
- Re: [grouper-users] Design question, Jeff McCullough, 03/06/2013
- Re: [grouper-users] Design question, David Langenberg, 03/06/2013
- Re: [grouper-users] Design question, Tom Zeller, 03/06/2013
- Re: [grouper-users] Design question, Tom Barton, 03/06/2013
- Re: [grouper-users] Design question, Michael R. Gettes, 03/06/2013
- Re: [grouper-users] Design question, David Langenberg, 03/06/2013
- Re: [grouper-users] Design question, Earl Lewis, 03/04/2013
- Re: [grouper-users] Design question, Tom Barton, 03/02/2013
- Re: [grouper-users] Design question, Jim Fox, 03/04/2013
- Re: [grouper-users] Design question, Earl Lewis, 03/01/2013
Archive powered by MHonArc 2.6.16.