Skip to Content.
Sympa Menu

grouper-users - [grouper-users] Question about LDAP to Grouper provisioning

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] Question about LDAP to Grouper provisioning


Chronological Thread 
  • From: "Bryan E. Wooten" <>
  • To: "" <>
  • Subject: [grouper-users] Question about LDAP to Grouper provisioning
  • Date: Thu, 28 Mar 2013 20:11:26 +0000
  • Accept-language: en-US
  • Authentication-results: sfpop-ironport01.merit.edu; dkim=neutral (message not signed) header.i=none

Hi all,

 

There is the psp-example-ldap-to-grouper but the documentation is rather sparse here: https://spaces.internet2.edu/display/Grouper/Grouper+Provisioning#GrouperProvisioning-ConfigurationExample%3ALDAPtoGrouper so I have several questions.

 

I have Grouper configured using the psp-example-grouper-to-active-directory. This is working great.

 

I now want import all the existing AD groups into Grouper (we potentially have thousands), recreating this by hand in Grouper would be impossible.

 

Looking at the differences between the psp.xml from grouper-to-ad and ldap-to-grouper, the first thing I notice is that both have a pso with the id of “stem”. There does not appear to be anyway to combine the settings into one pso with and id of “stem”.

 

Would it be appropriate to create a pso with an id of “ADToGrouperStem” and continue with the ad-to-grouper example? And doing the same type of thing for the pso with id of “group”?

 

Of course this assumes that the PSP can in fact both provision to and from AD. Is this true?

 

And last question. Provision from Grouper to AD is kicked off either at the gsh command prompt (loaderRunOneJob, gsh –psp –sync <id>) or using the Quartz timer in the Grouper loader. What command or setting kicks off ad-to-grouper provisioning? There is no change log to run against for AD changes.

 

Thanks,

 

Bryan




Archive powered by MHonArc 2.6.16.

Top of Page