grouper-users - RE: [grouper-users] creating an initial admin user :confused:
Subject: Grouper Users - Open Discussion List
List archive
- From: Chris Hyzer <>
- To: Rob Gorrell <>
- Cc: "" <>
- Subject: RE: [grouper-users] creating an initial admin user :confused:
- Date: Wed, 22 May 2013 20:15:30 +0000
- Accept-language: en-US
- Authentication-results: sfpop-ironport04.merit.edu; dkim=neutral (message not signed) header.i=none
The UI (or the WS) is self contained in a webapp. To build it you need the API, but to run it you don’t (well, its in there) Thanks, Chris From: Rob Gorrell [mailto:]
bingo, that was it! I was running gsh from a separate API installation on my UI server, not from within the UI WEB-INF/bin and as such, that grouper.properties wasn't configured to use the wheel group. as soon
as I turned that on, I'm now seeing the admin options after logging into the UI. Thanks. On Wed, May 22, 2013 at 3:37 PM, Chris Hyzer <> wrote: No, shouldn’t matter. So you can confirm you are running the GSH from the UI WEB-INF/bin, and not
somewhere else, right? J Maybe bounce the UI and try again? If nothing else works, I can suggest some debug stuff you could add into Grouper, rebuild, and try
again. Remind me which version you are using. Also, send me a sanitized version of your grouper.properties from the UI’s WEB-INF/classes dir Thanks, Chris From:
[mailto:]
On Behalf Of Rob Gorrell Does removing all the <security-contraint> tags from the web.xml in order to shibbolize the UI (as directed here:
https://spaces.internet2.edu/display/Grouper/Newcastle+University+-+Protecting+UI+With+Shib) factor into potentially why i'm seeing admin functionality in the UI but grouper is reporting the privleges on my subject appear to be there? On Wed, May 22, 2013 at 12:11 PM, Rob Gorrell <> wrote: even more confused... yes, that checks out....
edu.internet2.middleware.grouper.GrouperSession: 3c2b8e6df1c24d24a92691b826a0817d,'GrouperSystem','application' On Wed, May 22, 2013 at 11:52 AM, Chris Hyzer <> wrote: Start GSH from your UI WEB-INF/bin, try to resolve the subject by id or identifier as whatever comes
from shib, and see if that specific subject is an admin… J could be the config in the UI isn’t
the same as another place? [appadmin@lorenzo appadmin]$ locate gsh.sh /opt/appserv/tomcat_2v/webapps/grouper/WEB-INF/bin/gsh.sh /opt/appserv/tomcat_3b/webapps/grouperWs/WEB-INF/bin/gsh.sh /opt/appserv/tomcat_3c/webapps/fastGrouperProdDaemon/WEB-INF/bin/gsh.sh [appadmin@lorenzo bin]$ cd /opt/appserv/tomcat_2v/webapps/grouper/WEB-INF/bin [appadmin@lorenzo bin]$ ./gsh -bash: ./gsh: Permission denied [appadmin@lorenzo bin]$ chmod +x gsh [appadmin@lorenzo bin]$ dos2unix gsh dos2unix: converting file gsh to UNIX format ... [appadmin@lorenzo bin]$ ./gsh Type help() for instructions gsh 0% grouperSession = GrouperSession.startRootSession(); edu.internet2.middleware.grouper.GrouperSession: 32e27397920f480f88bd38938114cc32,'GrouperSystem','application' gsh 1% subject = SubjectFinder.findByIdOrIdentifier("",
true); subject: id='10021368' type='person' source='pennperson' name='Michael Christopher Hyzer'
gsh 2% PrivilegeHelper.isWheelOrRoot(subject); true gsh 3% exit From:
[mailto:]
On Behalf Of Gagné Sébastien AFAIK you only need to be a member of the etc:sysadmingroup, maybe the problem is your
shib authentication ? Could there be a subject source mismatch between the subject in the Group and the subject that’s logged in (doubtful) ?
The logged-in user in linux that is running Grouper doesn’t have any impact here De :
[]
De la part de Rob Gorrell No, i'm not seeing that I guess furthur confirming I've not been successful in setting myself up as an admin. I guess what I'm confused about, beyond making myself
a subject and putting myself into a etc:sysadmin group, how do I tell Grouper the sysadmin group (and thus its members) be granted admin access? -Rob On Wed, May 22, 2013 at 10:42 AM, Earl Lewis <> wrote:
Robert W. Gorrell University of NC at Greensboro
Robert W. Gorrell University of NC at Greensboro
Robert W. Gorrell University of NC at Greensboro
Robert W. Gorrell University of NC at Greensboro |
- [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Earl Lewis, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- RE: [grouper-users] creating an initial admin user :confused:, Gagné Sébastien, 05/22/2013
- RE: [grouper-users] creating an initial admin user :confused:, Chris Hyzer, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- RE: [grouper-users] creating an initial admin user :confused:, Chris Hyzer, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- RE: [grouper-users] creating an initial admin user :confused:, Chris Hyzer, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- RE: [grouper-users] creating an initial admin user :confused:, Chris Hyzer, 05/22/2013
- RE: [grouper-users] creating an initial admin user :confused:, Gagné Sébastien, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Peter DiCamillo, 05/23/2013
- Re: [grouper-users] creating an initial admin user :confused:, Rob Gorrell, 05/22/2013
- Re: [grouper-users] creating an initial admin user :confused:, Earl Lewis, 05/22/2013
Archive powered by MHonArc 2.6.16.