  From: Paul Engle
  Date: Mon, 20 Feb 2017 11:16:04 -0600
I understand how to make Grouper authoritative for prefixed values of an
LDAP attribute using the LdapAttributeProvisioner and setting a value
for the grouperIsAuthoritative & allProvisionedAttributePrefix
properties. But how can I do so for _all_ values of an attribute,
without a prefix?

Up to now, we've had isMemberOf populated from the group name, so they
don't all share a common prefix. Introducing a prefix at this stage
would break several applications that are already using the existing
values. I thought I could be clever and put in a string like '*:',
making the resultant LDAP filter be (isMemberOf=*:*). But apparently
later on during the reconciliation, the prefix is made part of a regex,
so the asterisk blows it up.

Is there any way to specify an empty string for the property? If not,
can that be a feature request? If I can get this one issue solved, then
I think I will have a fully functional pspng equivalent of our existing
psp config.


Paul Engle
Office of Information Technology


