grouper-users - Re: [grouper-users] Re: Grouper PSPNG
Subject: Grouper Users - Open Discussion List
List archive
- From: Akki Kumar <>
- To: "Bee-Lindgren, Bert" <>
- Cc: Dave Churchley <>, Jeffrey Crawford <>, mchyzerpenn <>, "" <>
- Subject: Re: [grouper-users] Re: Grouper PSPNG
- Date: Thu, 9 Feb 2017 15:43:22 -0500
- Ironport-phdr: 9a23:p8wrfxRZI20XEZyMSUQP+geVYdpsv+yvbD5Q0YIujvd0So/mwa6zYRWN2/xhgRfzUJnB7Loc0qyN4vymCTFLuM/c+Fk5M7V0HycfjssXmwFySOWkMmbcaMDQUiohAc5ZX0Vk9XzoeWJcGcL5ekGA6ibqtW1aFRrwLxd6KfroEYDOkcu3y/qy+5rOaAlUmTaxe71/IRG5oAnLtcQbgYRuJrssxhbJv3BFZ/lYyWR0KFyJgh3y/N2w/Jlt8yRRv/Iu6ctNWrjkcqo7ULJVEi0oP3g668P3uxbDSxCP5mYHXWUNjhVIGQnF4wrkUZr3ryD3q/By2CiePc3xULA0RTGv5LplRRP0lCsKMSMy/XrJgcJskq1UvBOhpwR+w4HKZoGVKOF+db7Zcd8DWGZNQtpdWylHD4ihbYUAEvABMP5aoInzp1UAoxiwCxSyCuzz0TJHnGP60Lcg3ug9DQ3L3gotFM8OvnTOq9X1Mb8fXPy2zKnLzDXIcvZY2Sr46IfSaBAqvPaBUqh1ccXLyEgvFgXFjlqJqYz4ITyVzfgNs2mc7+pmTuKjl3IrpgNqrzigw8cjkIjJhoYPxl/Y8iV5xZ84KNulQ0B1Zt6kFYFftyCcN4ZuQ8MiRX1otzggyr0Ap5G7YDYGxI45yBHCdvyLa5SI4hL5VOmPOzh3mWhpeKiihxa090Wr1+7yVtGs3VpUrydJjtvBu3UD1xHQ8ceLVv5w80i91TqT2Q3e7/1LLVw6lafeLpMt3KA8mYQVvE/eBCH5gl/2g7WTdkg8+uin9eDnYrL+q5+ZLYB0iwX+Pr0pmsyjHeg0KwcPU3aF9euizrHj8kr5QLJFjv0yjKbVqozVJcMepqKhAg9V1Jgs6wqnAju40dkUgXsKIVdLeB+ElIflJ1TDLf/kAfujjVmhlStky+zIPrDkB5jBMGbPn6n5cbZ48UFcyQ4zzd5F55JTD7EMOOj8Wkrru93ZDx85NQO0w//6CNpjzYMeRWOPAqifMKPJrVOE+uAiLvKDZI8Qojn9Kvwl6+Tygn8+nF8RZbOp0ocPaHCkAvRmJF2UYXX2gtcGDGcKphQxTPbzhF2fSj5ceWyyX7kn6zE/CYKmFpvDRpuzjLCb3Se7GIFWaX5cClCKD3joa5uIV+0SZy2PP88y2gADAPKLRoJk8RCouADgxrwjZsDZ4DFS/cbp2cJpoefemFQ29Dp4AN6Q1UmKTn0ykWoUSjQ2mq1zvBou5E2E1P1RgP9ZXf9O4vpTGlMzMJfOzup1Es3/QR7AedGSEA75atqjCDA1CNk2xoldMA5GB9y+g0WbjGKRCLgPmunOXcRs/w==
Yes, adding configuration flag seems to be a right way do it since it will give the flexibility to create groups with or without members based on the flag configuration.Thank you,AkkiOn Mon, Oct 3, 2016 at 6:30 AM, Bee-Lindgren, Bert <> wrote:I understand. This thread is about groups that require a member (groupOfNames) and, in particular, what to do with them when the group no longer has members.
My thought is to add a configuration flag memberIsRequired that would both combine group creation with the addition of the initial member as well as delete the group when the last member is removed.
Does this sound right?
Thanks very much,Bert
On Oct 3, 2016, at 4:07 AM, Dave Churchley <> wrote:
+1
Yes, this would definitely be the case for us.
From: [] On Behalf Of Jeffrey Crawford
Sent: 02 October 2016 03:37
To: Akki Kumar <>
Cc: Bee-Lindgren, Bert <>; mchyzerpenn <>;
Subject: Re: [grouper-users] Re: Grouper PSPNG
Would this be an option? I'm wondering if in a situation like AD where you delete a group it may break all permissions that may be assigned to that group. I don't think Windows uses group names in the background rather it uses some sort of SID which would not be re-used.
I may be wrong but we may want pspng to have this "feature" be an option just in case some implementations don't use names as the main identifier. In short some people may want to be able to have empty groups.
just my $0.02 :)
Jeffrey E. Crawford
Enterprise Service Team
Both pilots and IT professionals require training and currency before charging into clouds!
------------------------------
---------
On Fri, Sep 30, 2016 at 9:58 AM, Akki Kumar <
> wrote: Hi Bert,
Thank you for creating Jira ticket.
Yes, grouper should delete group when the last member or all members of the group are deleted.
Thank you,
Akki
On Mon, Sep 26, 2016 at 6:51 AM, Bee-Lindgren, Bert <> wrote:
Akki,
PSPNG does not currently support combining group creation with the addition of the group's initial member. I've created a Jira for adding this.
https://bugs.internet2.edu/jir
a/browse/GRP-1376
Are there any concerns about removing the last member?... does the group need to be deleted?
Sincerely,
Bert
From: Akki Kumar <
>
Sent: Wednesday, September 21, 2016 11:29 AM
To: mchyzerpenn; Bee-Lindgren, Bert
Cc:
Subject: Re: Grouper PSPNG
Hello,
Does PSPNG support member addition while creating a group in LDAP? Our LDAP system requires adding members during group creation and I couldn't find a way do it through PSPNG.
changeLog.consumer.pspng_testO
ne.groupCreationLdifTemplate = dn: cn=${grouperUtil.extensionFrom Name(name)}||cn: ${grouperUtil.extensionFromNam e(name)}||objectclass: groupOfNames||member: <CONFIGURATION_TO_ADD_MEMBER>
Thank you,
Akki
On Tue, Sep 20, 2016 at 10:57 AM, Akki Kumar <
> wrote: Hello,
I am trying to integrate PSPNG with our LDAP system and its erroring out. I followed configuration “Group of Unique Names”: https://spaces.internet2.edu/d
isplay/Grouper/Grouper+Provisi oning%3A+PSPNG
When I run loader with “Group of Unique Names” configuration, it shows below error:
Problem while creating new object: [dn=cn=testGroup,ou=test,ou=te
stgrouper,dc=umd,dc=edu[[cn[te stGroup]], [objectclass[groupOfNames]]]] [org.ldaptive.LdapException@97
9158603::resultCode=OBJECT_CLA SS_VIOLATION, matchedDn=null, responseControls=null, referralURLs=[], messageId=-1, message=LDAPException(resultCo de=65 (object class violation), errorMessage='object class violation'), providerException=LDAPExceptio n(resultCode=65 (object class violation), errorMessage='object class violation')] at org.ldaptive.provider.Provider
Utils.throwOperationException( ProviderUtils.java:55) at org.ldaptive.provider.unboundi
d.UnboundIDConnection.processL DAPException(UnboundIDConnecti on.java:543) at org.ldaptive.provider.unboundi
d.UnboundIDConnection.add( UnboundIDConnection.java:317) at edu.internet2.middleware.group
er.pspng.LdapProvisioner.perfo rmLdapAdd(LdapProvisioner. java:253) at edu.internet2.middleware.group
er.pspng.LdapGroupProvisioner. createGroup(LdapGroupProvision er.java:226) at edu.internet2.middleware.group
er.pspng.LdapGroupProvisioner. createGroup(LdapGroupProvision er.java:54) at edu.internet2.middleware.group
er.pspng.Provisioner.prepareGr oupCache(Provisioner.java:678) at edu.internet2.middleware.group
er.pspng.Provisioner.startProv isioningBatch(Provisioner. java:453) at edu.internet2.middleware.group
er.pspng.FullSyncProvisioner.p rocessGroup(FullSyncProvisione r.java:314) at edu.internet2.middleware.group
er.pspng.FullSyncProvisioner. thread_manageFullSyncProcessin g(FullSyncProvisioner.java: 175) at edu.internet2.middleware.group
er.pspng.FullSyncProvisioner$ 1.run(FullSyncProvisioner. java:133) at java.lang.Thread.run(Thread.ja
va:745) Caused by: LDAPException(resultCode=65 (object class violation), errorMessage='object class violation')
at com.unboundid.ldap.sdk.LDAPCon
nection.add(LDAPConnection. java:1969) at org.ldaptive.provider.unboundi
d.UnboundIDConnection.add( UnboundIDConnection.java:311) ... 9 more
Questions:
· * What configuration are needed to add members during group creation by Grouper?
changeLog.consumer.pspng_testO
ne.groupCreationLdifTemplate = dn: cn=${grouperUtil.extensionFrom Name(name)}||cn: ${grouperUtil.extensionFromNam e(name)}||objectclass: groupOfNames||member: <CONFIGURATION_TO_ADD_MEMBER> · * Also when I set attribute supportsEmptyGroups = false, it still throws above error. Does PSPSNG supportsEmptyGroups attribute works when set to false?
Thank you,
Akki
- Re: [grouper-users] Re: Grouper PSPNG, Akki Kumar, 02/09/2017
- Re: [grouper-users] Re: Grouper PSPNG, Akki Kumar, 02/21/2017
Archive powered by MHonArc 2.6.19.