grouper-users - Re: [grouper-users] PSPNG: Handling groups that require a member
Subject: Grouper Users - Open Discussion List
List archive
- From: "Michael R. Gettes" <>
- To: David Langenberg <>
- Cc: Warren Curry <>, "" <>, "" <>, Bert Lindgren <>, John Gasper <>
- Subject: Re: [grouper-users] PSPNG: Handling groups that require a member
- Date: Sun, 15 Jan 2017 11:47:56 -0500
- Ironport-phdr: 9a23:g3fY/h2gEtB72sWTsmDT+DRfVm0co7zxezQtwd8ZseISIvad9pjvdHbS+e9qxAeQG96Kt7Qf16GP7PCocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDWwbal8IRi5ogndq8sbjIh/Iast1xXFpWdFdf5Lzm1yP1KTmBj85sa0/JF99ilbpuws+c1dX6jkZqo0VbNXAigoPGAz/83rqALMTRCT6XsGU2UZiQRHDg7Y5xznRJjxsy/6tu1g2CmGOMD9UL45VSi+46ptVRTlkzkMOSIn/27Li8xwlKNbrwynpxxj2I7ffYWZOONjcq/BYd8WQGxMVdtTWSNcGIOxd4sBAekdMulXsofzqVkBowWwBQerH+7g0CNEhnrs0K06z+gsEwfL1xEgEdIUt3TUqc34OKkVX+C00KbIzS/MYO1S2Tzg9IbEaA0qr/CSUrJsbcre11IvGw3YhViXrIzlJTyV2+oRv2WA9+pgTv+vh3Q5pA5svzii38EhgZTHiIISz1DL7yR5wIAtKN2gUk57ZtmkEJVItyGdNot2RN8iT3t0tyY9z70KoZG7fDISyJg+2RLQduGLfoaK7x/iUuuaPDR2hGp9db6imRq/8lKsxvDhWsS3ylpGsyVIn9jWunwQ2RHe686KQeZn8Ei7wzaAzQXT5/lEIU8qkarbLIYswqIqlpYNr0jDGDL6lFjsg6OMbEok4fan6/j9brX+vZ+cKpV4hR/jPaQzgsC/AOI4PRYSX2WD5Oiwyr7u8VfkTLlXjfA6iLTVvZ/bKMgBu6K0DQ5Y3p4m6xmlDjem1NoYnWMALFJAYB+HipLpO17ALfzkFvq/m0+skCpxy//YI7LhH43BLmLfn7f5YbZ990lcxRI8zdBF4JJUF6kBL+zpWkPoqdzYFQE2Mxavw+v8DNV915geWX6UAqOHKq/SsFmI5v4xLOmWYo8apir9J+Y/6/HwkHA5hAxVQa788ZIJaXzwOv1gLEifa3f2jZ9VHW4Usw4WUefqiVaLXjkVanqvCfES/DY+XciDDIzDT42pyIbHlAi2AoFbfSoOXlWWHiywX52fRrEBZD/EcZwpqSANSbX0E9xp7hqprgKvjuM/duc=
+1 to Dave. (actually, +1000000000) now, even tho i disagree with Mr. Fox (and Curry) about the need to even solve this problem I would like to see if there is a way to address the requirements stated. What I “hear” is a desire to have the state of a grouper group properly reflected into LDAP (and other applications) even when the group is empty. If that is an effective description of the problem, then this problem must not be solved by PSPNG as it provisions a subset of what interacts with Grouper. I believe the proper solution would be to have an option (not the default) for grouper to detect the case where a group has no members and add to the group the “ghost” member. The “ghost” member should behave like any other member of a group (however, maybe you don’t want to allow it to be deleted?). When other members are added to the group, the “ghost” can be removed. We are implementing identity management services here - so the very notion of a “ghost” member should throw us all into a tizzy. I can’t support the notion of a “ghost” member - it’s just wrong. So, a “ghost" member is a subject - all subjects must be defined in a subject source for grouper - and most logically the person subject source which would be taken from your identity management system. This way, all applications in your identity eco-system will be able to properly reference the “ghost”. Now you won’t have LDAP based applications having groups different than non-LDAP apps. You won’t have LDAP based applications needing additional data from other identity services (your registry) having to deal with the special “ghost” situation. And, PSPNG wouldn’t have to change. I believe this would address the concerns/desires stated thus far and would be a more holistic approach and not one based on exception(s). Thoughts? /mrg
|
- [grouper-users] PSPNG: Handling groups that require a member, Bee-Lindgren, Bert, 01/11/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Jim Fox, 01/11/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Michael R Gettes, 01/11/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Bee-Lindgren, Bert, 01/11/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, John Gasper, 01/11/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Michael R. Gettes, 01/14/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, David Langenberg, 01/14/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Jim Fox, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Curry, Warren, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, David Langenberg, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Michael R. Gettes, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Michael R. Gettes, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Jim Fox, 01/16/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Curry, Warren, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Klingenstein, Nate, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Jim Fox, 01/15/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, David Langenberg, 01/14/2017
- Re: [grouper-users] PSPNG: Handling groups that require a member, Michael R. Gettes, 01/14/2017
Archive powered by MHonArc 2.6.19.