Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Multiple searchSubjects in sources.xml

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Multiple searchSubjects in sources.xml

Chronological Thread 
  • From: Julio Polo <>
  • To: Philip Harle <>
  • Cc: "" <>
  • Subject: Re: [grouper-users] Multiple searchSubjects in sources.xml
  • Date: Fri, 4 Nov 2016 08:39:08 -1000
  • Ironport-phdr: 9a23:g191vBebHkS4XDcd+uOcLqJclGMj4u6mDksu8pMizoh2WeGdxc69YB7h7PlgxGXEQZ/co6odzbGH6eawCCdZuMjJmUtBWaQEbwUCh8QSkl5oK+++Imq/EsTXaTcnFt9JTl5v8iLzG0FUHMHjew+a+SXqvnYsExnyfTB4Ov7yUtaLyZ/mjabiqtaKOlsArQH+SIs6FA+xowTVu5teqqpZAYF19CH0pGBVcf9d32JiKAHbtR/94sCt4MwrqHwI6LoJvvRNWqTifqk+UacQTHF/azh0t4XXskz7TQqL52NUcmwMlhcAVxDF7RX7RtHxuzH+u8J71TaRNNbqSb1yUD/k8qQ9GzHyjyJSFSM98Wafsst0i+oPog+lphtXw4fLaYCUcvdyY/WOLpshWWNdU5MJBGR6CYSmYt5KVrJZMA==

If AD behaves like other LDAP servers, you could specify the base as 'DC=campus,DC=ncl,DC=ac,DC=uk' and change the ACI for the LDAP/AD account you configured Grouper with so that it only has access to the two branches you want (OU=Campus Users and OU=Other Users)

Julio Polo
Enterprise Middleware, Identity and Access Management
Information Technology Services
University of Hawaii

On Fri, Nov 4, 2016 at 1:33 AM, Philip Harle <> wrote:
Inside of sources.xml we specify the path to the base OU in Active Directory containing the majority of our user accounts. However, we have a scenario where our subject user accounts exist across two separate locations in AD.

We currently use the following:
            <param-value>OU=Campus Users,DC=campus,DC=ncl,DC=ac,DC=uk</param-value>

Is it possible to specify a secondary location, for example 'OU=Other Users,DC=campus,DC=ncl,DC=ac,DC=uk' in addition to the one specified above?

I've attempted to construct a search block in sources.xml using numParameters to allow us to query a second location if the subject is not found in the first, but I've not had much success.

I realise this could be achieved by specifying the base as 'DC=campus,DC=ncl,DC=ac,DC=uk', however our domain contains a number of other root OU's that we'd rather not have Grouper search through in order to maintain performance of the service.


Phil Harle
IT Service
Newcastle University

Archive powered by MHonArc 2.6.19.

Top of Page