grouper-users - RE: [grouper-users] AD groups and sAMAccountname, colons
Subject: Grouper Users - Open Discussion List
List archive
- From: "Bryan E. Wooten" <>
- To: "Michael R. Gettes" <>
- Cc: "" <>
- Subject: RE: [grouper-users] AD groups and sAMAccountname, colons
- Date: Mon, 11 Mar 2013 21:34:26 +0000
- Accept-language: en-US
- Authentication-results: sfpop-ironport05.merit.edu; dkim=neutral (message not signed) header.i=none
Thanks Mike, I am using bushy. Doesn’t seem to make any difference. As a quick work around I decide to set sAMAccountName to group descripton since I can control it in the UI. But now I get a new Error: DSID-03050C42 “This occured because the "cn" attribute did not match the
first part of the "distinguishedName" attribute. If we change this to:” http://clintboessen.blogspot.com/2011/06/0x2081-multiple-values-were-specified.html Thanks, Bryan From: Michael R. Gettes [mailto:]
keep in mind you have 64 character limit in most component names of a DN in AD. Thank you Microsoft and thank you PKI folks for coming up with arbitrary not-so-well-thought-out limitations. We break down each : separated name into an
OU and the leaf becomes a CN. I am told there is some config statement regarding "bushy" that makes all this happen.
i hope this helps. /mrg On Mar 11, 2013, at 4:41 PM, "Bryan E. Wooten" <> wrote:
When provisioning AD groups from the PSP the default example shows sAMAccountName being set to the CN. When the PSP provisions a group it seems to create 2 CNs. One like
FolderID:GroupID and another that is just GroupID. Well AD doesn’t allow colons in sAMAccountName. I found this discussion: This comment caught my eye: “ At Duke, we work around the colon issue and maintain uniqueness
by converting the colons into hyphens and not allowing hyphens in group/folder names in Grouper.” Is this something I can configure or do I have to dig into the source code to make the fix? -Bryan |
- [grouper-users] AD groups and sAMAccountname, colons, Bryan E. Wooten, 03/11/2013
- Re: [grouper-users] AD groups and sAMAccountname, colons, Michael R. Gettes, 03/11/2013
- RE: [grouper-users] AD groups and sAMAccountname, colons, Bryan E. Wooten, 03/11/2013
- Re: [grouper-users] AD groups and sAMAccountname, colons, Sebastien Gagne, 03/11/2013
- RE: [grouper-users] AD groups and sAMAccountname, colons, Bryan E. Wooten, 03/11/2013
- [grouper-users] RE: AD groups and sAMAccountname, colons, Chris Hyzer, 03/11/2013
- [grouper-users] RE: AD groups and sAMAccountname, colons, Bryan E. Wooten, 03/11/2013
- Re: [grouper-users] AD groups and sAMAccountname, colons, Michael R. Gettes, 03/11/2013
Archive powered by MHonArc 2.6.16.