Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] grouper and openldap

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] grouper and openldap

Chronological Thread 
  • From: Michael R Gettes <>
  • To: Jorj Bauer <>
  • Cc:
  • Subject: Re: [grouper-users] grouper and openldap
  • Date: Mon, 30 Jan 2017 10:50:17 -0500
  • Ironport-phdr: 9a23:0fA1cxIoxOKEljElCtmcpTZWNBhigK39O0sv0rFitYgRI/3xwZ3uMQTl6Ol3ixeRBMOAuq4C1bGd7PCocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDWwbalzIRi4ognctMobipZ+J6gszRfEvmFGcPlMy2NyIlKTkRf85sOu85Nm7i9dpfEv+dNeXKvjZ6g3QqBWAzogM2Au+c3krgLDQheV5nsdSWoZjBxFCBXY4R7gX5fxtiz6tvdh2CSfIMb7Q6w4VSik4qx2UxLjljsJOCAl/2HWksxwjbxUoBS9pxxk3oXYZJiZOOdicq/BeN8XQ3dKUMRMWCxbGo6zc4QAAfcBM+laoYfzqFgArRWgCwerH+7v1iZIhnrq0a06z+gtDwfL1xEgEdIUt3TUqc34OqATUe+pzKnH1yvMb/dL0jnh9YPGcw4uoe2QXb1uasra1E4iFwbfjlWfp4HpIyiY1vwWs2iG9eZvS/+gi3M+pgx3vzOhxd8sh5HUio4LyV3I7zh1zJs2KNGiVUJ2bt+pHIFNuyyUNoZ6Wt4uT39rtSog17EKpJ22cDIXxJg62xLTcfOKfoaO7xn+TuieOy14i2hgeL+nhxa970ygyurkW8moylZGsDRJkt/RunwQzRPf8NKISuBj8Ue9wzqPzxvT6vxeLU8qiKXbNoYtwr82lpUNrUTOBjL6lFv1gaOMa0ko5+ul5/76brjpp5KQLZJ4hw//P6g2n8ywG+U4MgwAX2iB/uS80aXu/UjjQLVFgPA6jrLUsIjBJcQGvKK2HRJa0ps75xalEzimyMgYnWUALF9ddxKHlY/pO0zWIP/mF/ezmkmskCx1yPDcJb3sGZHNLnnYkLf9ZrZx9VRQyAs1zdBD+Z1UELcBL+zvWkPvrtDXEAI2MxHni9rgXfd6zIFWc2uSD7XRZKHVq12g+u8qO+2BIoIZpWCuBeIi4qvLjHQ5kFIZNZPh8pYLdH2jVqBjOUrCOVL0mcpHHGsX6FltBNf2gUGPBGYAL025WLgxs3RiUNqr

I received only a few replies. Others have run into this limitation of
openldap not being able to support large static group objects. The problem is
really large numbers of multi-valued attributes (not just group objects). My
observation is 5 seconds to update when the group object becomes greater than
35K-40K members. Apparently, openldap has to regenerate the
member/uniquemember attributes for the entire object each time. This appears
to be a known issue with openldap since at least October of 2003. People
have switched to using 389/sun-oracle (the iPlanet derivatives) or Active
Directory. There are probably other directory servers able to support large
group objects as well - but it would appear openldap and derivates have this

i hope this helps.


> On Jan 26, 2017, at 10:22 AM, Jorj Bauer
> <>
> wrote:
> I'd love to hear an anonymized roll-up of what you find. We're in early
> days of Grouper here and are picking a new LDAP back-end to replace our
> Oracle DSEE - perfect timing for us to find out what our future troubles
> are going to look like...
> -- Jorj
> On 01/26/2017 09:49 AM, Michael R Gettes wrote:
>> Hi All,
>> A few months ago there was discussion around large groups for grouper. I
>> believe someone from either UCLA or Oregon State (or maybe some place
>> else) indicated they had groups of 400K. Would those people kindly
>> contact me off list? I have a couple of questions for you - not about
>> grouper perf concerns, but about non-grouper perf concerns.
>> Thank you!
>> /mrg

Archive powered by MHonArc 2.6.19.

Top of Page