grouper-users - Re: [grouper-users] loading nested groups from an LDAP source
Subject: Grouper Users - Open Discussion List
List archive
- From: Rob Gorrell <>
- To: "Hyzer, Chris" <>
- Cc: "" <>
- Subject: Re: [grouper-users] loading nested groups from an LDAP source
- Date: Thu, 4 Aug 2016 11:50:59 -0400
Rob, my email got rejected due to attachment, but its attached to confluence and jira below
From: Hyzer, Chris
Sent: Wednesday, August 03, 2016 8:15 PM
To: 'Rob Gorrell' <>;
Subject: RE: [grouper-users] loading nested groups from an LDAP source
An example is done:
https://bugs.internet2.edu/
jira/browse/GRP-1354
There is a jar attached inside the zip in this email
Add the ldapGroupUserConverter.jar to the classpath (e.g. to lib/custom)
In the grouper-loader.properties, add the class
loader.ldap.el.classes = ldapGroupUserConverter.
LdapGroupUserConverter
Set the Grouper loader LDAP subject _expression_ attribute to ${ldapGroupUserConverter.
convertDntoSubjectIdOrIdentifi er(subjectId)}
Unset the subject source id
If the subjectId is a subjectId, then make sure Grouper loader LDAP subject ID type is "subjectIdOrIdentifier". If it is a subjectIdentifier (more common), then you can set it as subjectIdentifier.
Log the conversions with this in log4j.properties
log4j.logger.
ldapGroupUserConverter. LdapGroupUserConverter = DEBUG
Let me know how it goes! J
Thanks
Chris
From: [] On Behalf Of Rob Gorrell
Sent: Monday, July 25, 2016 9:46 AM
To:
Subject: [grouper-users] loading nested groups from an LDAP source
I currently have an LDAP_GROUP_LIST loader job pulling groups from an Active Directory source. In AD, we use a lot of group nesting (group of groups). When the loader job executes, it only loads those *user* objects with direct memberships to each group skipping over any *group* objects that are also direct members. What I would like it to do is resolve each group member in Grouper's internal source so that the group nesting copies over to grouper. Grouper has all these groups, but apparently the memberships aren't being resolved as it would seem the only subject source being used is my one that contains people (uncg-person).
-Rob
--Robert W. Gorrell
Systems Architect, Identity and Access ManagementUniversity of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
--
Systems Architect, Identity and Access Management
336-334-5954
PGP Key ID B36DB0CA
- RE: [grouper-users] loading nested groups from an LDAP source, Hyzer, Chris, 08/04/2016
- <Possible follow-up(s)>
- RE: [grouper-users] loading nested groups from an LDAP source, Hyzer, Chris, 08/04/2016
- Re: [grouper-users] loading nested groups from an LDAP source, Rob Gorrell, 08/04/2016
- RE: [grouper-users] loading nested groups from an LDAP source, Hyzer, Chris, 08/04/2016
- Re: [grouper-users] loading nested groups from an LDAP source, Rob Gorrell, 08/04/2016
Archive powered by MHonArc 2.6.19.