grouper-users - RE: [grouper-users] Update on my AD PSP issue, Trying to debug
Subject: Grouper Users - Open Discussion List
List archive
- From: "Bryan E. Wooten" <>
- To: "Bryan E. Wooten" <>, Shilen Patel <>, "" <>
- Subject: RE: [grouper-users] Update on my AD PSP issue, Trying to debug
- Date: Mon, 24 Jun 2013 13:37:48 +0000
- Accept-language: en-US
- Authentication-results: sfpop-ironport01.merit.edu; dkim=neutral (message not signed) header.i=none
I have wired up grouper to my IDE debugger and stop on a break point when I run the PSP change consumer after adding a group. My initial break point was set in LdapSpmlTarget.java line 937: /** * Handle provisioning add requests with no references to a target which requires references to not be empty, such * as OpenLDAP. * * @param addRequest the add request * @throws PspException if a psp error occurs * @throws DSMLProfileException if a dsml error occurs */ protected void handleEmptyReferences(AddRequest addRequest) throws PspException, DSMLProfileException { After a few steps I found myself in psp.java line 451: public void execute(AddRequest addRequest, AddResponse addResponse). Anyway I can’t seem to find where during the process the CN is set for the add request. Can you point me to the correct place in the source? Thanks, Bryan From: [mailto:]
On Behalf Of Bryan E. Wooten Ok, so I configured my sources.xml and ldap.properties to use AD instead of LDAP (I left all the psp*.xml files alone) and am able to provision a group to AD. Checking the wireshark trace I see that the cn equals the group name. This confirms my speculation below. So for some reason when the subject source is ldap the cn gets set to uofu:bryan22:groupname but when the subject source is AD the cn is set to just groupname. If someone can point me to the code that sets cn when the ldap addrequest is made I’ll try and debug the cause. This will be a show stopper for me if I can’t find a work around. If I can’t get the PSP to provision
groups to AD with an LDAP source I’ll probably be force to write my own change log consumer or something. I am sure I will run into similar issues when I try and add members to a group. But I’ll save that hurdle for another day. Thanks, Bryan From: Bryan E. Wooten
With the help of a colleague we noticed that the cn was passed as uofu:bryan22:group1 while the dn was cn=group1,ou=bryan22,ou=uofu,ou=groups,ou=grouper,dc=testad,dc=utah,dc=edu. We think the cn value is the problem. I am going to reconfigure back to my known good AD provisioning (with AD subject source) and capture a group add request and do a comparison of the cn value
passed. I'll do the test tomorrow and get back with an update. Thanks, Bryan From: Shilen Patel <> From the logs, what does the <addRequest> look like? Thanks! -- Shilen From: "Bryan E. Wooten" <>
|
- RE: [grouper-users] Update on my AD PSP issue, Trying to debug, Bryan E. Wooten, 06/24/2013
- Re: [grouper-users] Update on my AD PSP issue, Trying to debug, Shilen Patel, 06/25/2013
- RE: [grouper-users] Update on my AD PSP issue, Trying to debug, Bryan E. Wooten, 06/25/2013
- Re: [grouper-users] Update on my AD PSP issue, Trying to debug, Shilen Patel, 06/25/2013
- RE: [grouper-users] Update on my AD PSP issue, Trying to debug, Bryan E. Wooten, 06/25/2013
- RE: [grouper-users] Update on my AD PSP issue, Trying to debug, Gagné Sébastien, 06/25/2013
- RE: [grouper-users] Update on my AD PSP issue, Trying to debug, Bryan E. Wooten, 06/25/2013
- Re: [grouper-users] Update on my AD PSP issue, Trying to debug, Shilen Patel, 06/25/2013
- RE: [grouper-users] Update on my AD PSP issue, Trying to debug, Bryan E. Wooten, 06/25/2013
- Re: [grouper-users] Update on my AD PSP issue, Trying to debug, Shilen Patel, 06/25/2013
Archive powered by MHonArc 2.6.16.