grouper-users - RE: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request
Subject: Grouper Users - Open Discussion List
List archive
RE: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request
Chronological Thread
- From: Shaun Koh <>
- To: "Hyzer, Chris" <>
- Cc: "" <>, "Blair Christensen" <>, "Black, Carey M." <>
- Subject: RE: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request
- Date: Wed, 8 Feb 2017 22:16:05 +0000
- Accept-language: en-US, en-NZ
- Ironport-phdr: 9a23:cqohBRDE7UIMCgh2Ml3hUyQJP3N1i/DPJgcQr6AfoPdwSPT8o8bcNUDSrc9gkEXOFd2CrakV16yG6eu5BDxIyK3CmUhKSIZLWR4BhJdetC0bK+nBN3fGKuX3ZTcxBsVIWQwt1Xi6NU9IBJS2PAWK8TW94jEIBxrwKxd+KPjrFY7OlcS30P2594HObwlSijewZbx/IA+1oAnPucUanItvJ6UswRbVv3VEfPhby3l1LlyJhRb84cmw/J9n8ytOvv8q6tBNX6bncakmVLJUFDspPXw7683trhnDUBCA5mAAXWUMkxpHGBbK4RfnVZrsqCT6t+592C6HPc3qSL0/RDqv47t3RBLulSwKLCAy/n3JhcNsjaJbuBOhqAJ5w47Ie4GeKf5ycrrAcd8GWWZNW8BcXDFDDIyhdYsCF+oPM/hFoYnhqVUArhW+CgutBOzzxTBFnWX50bEm3+k7DQ3KwBIsEtQTu3rUttX1M6ISXPiowqnI1zrDcvVW0ir45ojPchAqvPaBXalwccXL1EkvERnJjlaXqYzlJD6azPkNvHSY7+pkT+2vjXMopxtrrTez3MssjIjIi5sTx1vZ+yt5x4M1Kse5SE59edOkEZ1Qtz2EOItsRMMtXX1otDggxrIYpJG7YS4Hw4kkyR7Hc/GLboaF7g75WOqPPDt1hWhpdK+hixuy60Ss1OLxW8qs3FpXoCdJjsPAum4Q2xHS8MSLV/tw80S71TuA0Q3Y9/tKLloulaXBLp4s2r4wmYQXsUTEBiL2nUr3gaCMeko+5+in9+fnYrH8qZ+aKoB4kBvxPbg0lsy5AOU0KgkOX26F9uSgzLDv4EP0TKlQgvEoj6XUsYrWKdkFqqO5GQNZzIku5hWnAzejytsYnH0HLFxfeBKAiojkI0rOIPDiAveihVSgijRrx/fGPrD6GJrNM2TMkLTlfbln7U5T1RA/wspD6J5ODLEAIer/WlXtu9zAEh85Lwu0zv7oCNVn0YMeRHqPDbGDMK/LrF+I/fwgI/OXZIIOvDb9KuMl5+L1jXMng1MdfK+p3YcJZ3CiGPRpPVmZbWT2jtgfDGgKo1l2cOu/wn2TQzNJIz6ZX7g9/XtzXIetDZbRS5qFgaeKmjqjE5tQIG1KFwbfP23vctC/W/4RbmqxJc8pxicEXKWnDYwm1TmnqQT5z7NhIqzd8Wsep8Swh5BO++TPmERqpnRPBMOH3jTIFjkskw==
Hi Chris, That is awesome and yes, it meets our requirements. – our Security team and the Grouper PM are delighted, thanks ! Best Regards, Shaun K. From: Hyzer, Chris [mailto:]
Does this capture what people had in mind? https://spaces.internet2.edu/display/Grouper/Grouper+attestation Thanks, Chris From: Black, Carey M. <> Another approach to “email till validated” would be to treat the group as “expired” at a “date”.
Like a user’s membership in a group can expire, maybe the whole group could be expired? ( So any query of membership for the expired group would return an empty set.) I would not want to “drop”(delete) the group or the members memberships, but rather, just have the group “not able to be used” until it is certified
again. Sometimes sending email is not enough… Sometimes, you actually need to “turn it off”. Might also be a good way to “time lock” multiple memberships. (expire a group-C that is a members of another group-B, instead of setting the expiration
date on all the “right” Members of group-B.) That way you could set it in one place and effect all of group-C being in group-B. To make extensions/early retirement easier. --
Carey Matthew
Office of the Chief Information Officer (OCIO) Identity and Access Management – Security Engineer-Lead 614-292-6079 Office From:
[]
On Behalf Of Shaun Koh Hi Chris, What you’ve outlined seem to work for us though we would prefer the emailing to be an optional flag. Also, a secondary filter would probably be handy to filter grouping of groups with the recertification flag set. – e.g. to view the recertification status for all groups
within a specific stem or group Let me know if the above made sense. Best Regards, Shaun K. From: Blair Christensen []
We've had a couple of requests @ uchicago for that precise workflow. On Mon, Jan 23, 2017 at 7:33 PM, Hyzer, Chris <> wrote: How would that work? -
Configure a group or stem with a number of days that groups need to be recertified -
When that time elapses email the admins of the group or a specified list every day until it is done -
Have a button in the UI to mark the group as recertified Thanks, Chris From:
[mailto:]
On Behalf Of Shaun Koh Hi there, I am wondering if there was any thought of having an audit trail for group verification/recertification ?
In particular, we currently have some high risk/value groups that we would like to know when the owners have last reviewed or updated (and perhaps send them a friendly reminder
when required). Is this something that you may be interested to implement ? – or does this feature exists and that I am just not aware of Best Regards, Shaun K. |
- Re: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request, Hyzer, Chris, 02/08/2017
- RE: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request, Shaun Koh, 02/08/2017
- RE: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request, Black, Carey M., 02/10/2017
- RE: [grouper-users] RE: Group Verification/Recertification Audit Trail -- Feature Request, Shaun Koh, 02/08/2017
Archive powered by MHonArc 2.6.19.