grouper-users - Re: [grouper-users] Re: PSP Question
Subject: Grouper Users - Open Discussion List
List archive
- From: David Langenberg <>
- To: "Bee-Lindgren, Bert A" <>, Jared Hoffman <>
- Cc: "" <>, "Kasa, Nubli" <>
- Subject: Re: [grouper-users] Re: PSP Question
- Date: Mon, 4 Apr 2016 23:02:52 +0000
- Accept-language: en-US
At the end of the day, the PSP needs to translate what it gets from Grouper (SubjectID) into the DN of the individual in AD. If it can easily do this via the subject API, then everything works like magic. If, however, it doesn't, then your job is to mangle
the attribute-resolver such that what pops out is the user's DN in AD. At some places I've assisted, this requirement has resulted in having to create intermediate attributes/dataconnectors whose function is to perform searches by subjectID against various
databases ( sometimes LDAP, sometimes something completely different) in order to yank out something like the value stored in sAMAccountName which can then be fed to the appropriate resolvers to get back the DN. It's definitely not fun and will take awhile
to get right, but that's the mark you're shooting for -- translating SubjectID into DN.
Hope this helps.
Dave
--
David Langenberg Identity & Access Management Architect University of Chicago
On April 4, 2016 at 3:05:52 PM, Jared Hoffman () wrote:
|
- Re: [grouper-users] Re: PSP Question, Jared Hoffman, 04/04/2016
- Re: [grouper-users] Re: PSP Question, David Langenberg, 04/04/2016
Archive powered by MHonArc 2.6.16.