grouper-users - Re: [grouper-users] grouper posix gidNumber
Subject: Grouper Users - Open Discussion List
List archive
- From: Keith Hazelton <>
- To: "" <>
- Subject: Re: [grouper-users] grouper posix gidNumber
- Date: Fri, 20 Jan 2017 22:09:00 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:M1WKNxGCI2PgMmxqMj/P751GYnF86YWxBRYc798ds5kLTJ7yocywAkXT6L1XgUPTWs2DsrQf2raQ7/urADFbqb+681k6OKRWUBEEjchE1ycBO+WiTXPBEfjxciYhF95DXlI2t1uyMExSBdqsLwaK+i764jEdAAjwOhRoLerpBIHSk9631+ev8JHPfglEnjSwbLd9IRmsogjcuMYajZZiJ6s/1xDEvmZGd+NKyG1yOFmdhQz85sC+/J5i9yRfpfcs/NNeXKv5Yqo1U6VWACwpPG4p6sLrswLDTRaU6XsHTmoWiBtIDBPb4xz8Q5z8rzH1tut52CmdIM32UbU5Uims4qt3VBPljjoMOjgk+2/Vl8NwlrpWrhK/qRJi347aboKbNPR8caPcct0XXnZBUd1UVyBdHo+wc4kCAuwcNuhYtYn9oF4OoAO7CwayBePv1j9IjWL006Ig0uUuDwXG3BAnH9IIrX/Zq9b1O7kTUeCpzKnE1zXDYOlX2Djj7IjIbhchofeXULN+cMrR0lUgGxnbgVqNtIzoJjWY3fkDvWic6upvT+Ovi2g/pgFwpDiv2tkjipPPho0L1lDI6z91z5goKt2lUEJ6b9+kEIBMuC2AKYR5X94iTmd1syg50r0LoYO3cScFxZg9wxPTdeaLf5WM7x/hTuqdPyl0iGx9dL6hhhu+7Uqtx+jyVsS601tHrS9IncfJu3wR0hHc98uKR/t980qkwjmAzQ7T5v1BLE0wiaXWKpssz70umZcdq0vPBjH6lFn0gaOMeUgp+/Kk5/nmb7jovJOQKot5hwfjOao0gMO/G/43Mg0WUmib5+u80Lrj8FXiQLVPkv02irPWsI3GJcQbuKK1GQFU0oc46xmjCjepytUYnX0dIFNLeRKHlJTmN0vQL//lEPezm1WskDF1yPDaJrDtH5rAI3fZnLrlY7px8VNQxQ4xwNxF+Z5YFK8NLOr2WkDrtdzYChE5Mxazw+biENh91Z0RWWOTAq+ZKq/SsUWH5+MxLOmIeI8VvzD9JuMr5v7vln82hUURcre00psKcHy4BOhpI12FYXrwhdcMCWgKvhA5TOz3kF2NTyRTa2+vX6In+D47EpmmAJzHRoCsm7yBwDy7EoNMamBHDFCMDWnnd5+CW/gSdCKePNVtnSIZWri8GMcd0kTkuxX91qJqNK/J4SACrrri0sR4/eveiUt0+DBpRYzJ3HuKUnl5hCYVXDIsx4h+p1Bw0FGOzfI+jvBFQ499/fRMByQ3NILch8xzGd32RgXHNoOKRVe6QpOmCCM8Ss42xfcRYl12Xdiuk0aQjGKRH7YJmunTV9QP+aXG0i2pKg==
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
Yes.
___________________________________
email & jabber:
calendar: http://go.wisc.edu/i6zxx0
On 2017-01-20, 15:48 , "Michael R Gettes"
<>
wrote:
How would that support the use of Grouper as the locus for group
management? Peter’s answer for Brown I would think is what TIER would want
from an architectural perspective, yes?
/mrg
> On Jan 20, 2017, at 4:35 PM, Keith Hazelton
<>
wrote:
>
> Just as a side note, midPoint, an open source product that TIER is
evaluating has the ability to assign and manage gids and other aspects of
POSIX user accounts by provisioning to LDAP.
> ___________________________________
> email & jabber:
> calendar: http://go.wisc.edu/i6zxx0
>
> On 2017-01-20, 15:01 ,
"
on behalf of Michael R Gettes"
<
on behalf of
>
wrote:
>
> thank you Peter.
>
> i feel like there are bits of doc spread throughout but nothing that
brings together “this is how to get posix groups to work”. doc that is more
task oriented - follow these steps and this is how to manage posix groups and
gidNumber and so on. am i missing something?
>
> /mrg
>
>> On Jan 20, 2017, at 3:48 PM, Peter DiCamillo
<>
wrote:
>>
>> For gidNumber, we've been using the idIndex that Grouper generates for
group (and other objects):
https://spaces.internet2.edu/display/Grouper/Integer+IDs+on+Grouper+objects
For us, Grouper is the authoritative source for the GIDs.
>>
>> Peter
>>
>> On 1/20/17 3:38 PM, Michael R Gettes wrote:
>>> Has anyone done work to manage posix gidNumber within grouper and
would you care to share your work?
>>>
>>> I believe it should be possible to create a global attribute keeping
the next gidNumber and then to assign a gidNumber attribute with the current
global gidNumber to a group and then increment the global.
>>>
>>> This should be documented some place so others can leverage.
>>>
>>> I also don’t understand how to specify which groups should pushed to
LDAP (and how to exclude subsets). If anyone has done this and has examples
- please share.
>>>
>>> I am concerned the current PSPng implementation presumes 2 group
objects in LDAP, one for the normal group and a separate group for the Posix
version. This doesn’t seem right to me, we should be able to include posix
attributes within any group object. I have private email out to Bert these
questions as well.
>>>
>>> If I can get these problems resolved then I am halfway to eliminating
the need for the CMU GAP code.
>>>
>>> /mrg
>>>
>>
>
>
>
- [grouper-users] grouper posix gidNumber, Michael R Gettes, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Peter DiCamillo, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Michael R Gettes, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Keith Hazelton, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Michael R Gettes, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Keith Hazelton, 01/20/2017
- Message not available
- Re: [grouper-users] grouper posix gidNumber, Keith Hazelton, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Michael R Gettes, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Keith Hazelton, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Michael R Gettes, 01/20/2017
- Re: [grouper-users] grouper posix gidNumber, Peter DiCamillo, 01/20/2017
Archive powered by MHonArc 2.6.19.