Skip to Content.
Sympa Menu

grouper-users - RE: [grouper-users] what is a group authorized to do ?

Subject: Grouper Users - Open Discussion List

List archive

RE: [grouper-users] what is a group authorized to do ?


Chronological Thread 
  • From: Dave Churchley <>
  • To: Julio Polo <>, Steven Carmody <>
  • Cc: Grouper-Users <>
  • Subject: RE: [grouper-users] what is a group authorized to do ?
  • Date: Thu, 2 Mar 2017 08:54:41 +0000
  • Accept-language: en-GB, en-US
  • Authentication-results: mailhub-mx3.ncl.ac.uk; spf=pass smtp.mailfrom=newcastle.ac.uk
  • Ironport-phdr: 9a23:SBx5dRRyjFApU8nFFtM0Pz2CGtpsv+yvbD5Q0YIujvd0So/mwa6zbRKN2/xhgRfzUJnB7Loc0qyN4v2mAjVLuMzQ+Fk5M7V0HycfjssXmwFySOWkMmbcaMDQUiohAc5ZX0Vk9XzoeWJcGcL5ekGA6ibqtW1aFRrwLxd6KfroEYDOkcu3y/qy+5rOaAlUmTaxe71/IRG2oAnLuMQanIRuJrsvxhbNv3BFZ/lYyWR0KFyJgh3y/N2w/Jlt8yRRv/Iu6ctNWrjkcqo7ULJVEi0oP3g668P3uxbDSxCP5mYHXWUNjhVIGQnF4wrkUZr3ryD3q/By2CiePc3xULA0RTGv5LplRRP0lCsKMSMy/XrJgcJskq1UvBOhpwR+w4HKZoGVKOF+db7Zcd8DWGZNQtpdWylHD4y7d4UPCOkPM+hFpIX5ulcCsR6yCA+xD+3t1zBInGf7060k3eo8DQHI0g4vH9MSv3vbotX4L70dXfypwKTS0TnPc/Fb1DHg44bIaBAhpvSMUKp+f8XL10kgCR7Og0uQqYz4JTOayuQNs2yF4OtgSOmijGAppBtvojex3MshlInJhp8Pyl/Y9SV5xJg6JN2jRU59f9GlHodfuDuBN4tqRsMtXXtktzwmxbEcpJ67fzEHxZI6zBDRbPyHdpKH4hPlVOuJJzd3mHZldKiliBmu60Sg1+78W8+p21hJtipIisTAum4O2hDJ9MSKRedx8l2/1TuB2A3f8OJJLE4smabGNZIswaQ8moQcvEjfBCP6hlv6ga+Mekgm++Wk8+Dqb7r8qpOCOIJ5ihvyPrkwlsCjG+g1MQoDUm6G8uqmzrLj51f2QLBSg/02jKbZtJfaKNwepqGjAg9V1oYj6wukADu/1dQZkncKIEhDeB2bi4jlIUvBL+ziAfeigFSgiDZrx/bYMb39GpjBM2bPnbT7cbpj5ENQ1BA/wc5R6p9bEL0MI/z+Vlf0tNPCDx85NwK0w/zgCNV4zo4QV3iAArGHP6/Ir1KI5v8vI/OQa48VvDbyNfgk6uXojXAnl14SYbOm3YALaHC8APtqOV+Wbmb2jtccEmcGphA+Q/DyiF2eTT5TYG6/X60m5jE8FYKmFZnMRpq0jLycxye0AIdWZntdB1CIEHfobJmEW+wSZC6II89hlCAEWqa7S48nyx6uqBH2x6B5IeXJ5y1L/a7kgfpo4+zU3Sk18Ts8W8aA12CKZ2F9gWoJRnk70L0p5QRG1lqd3K4wqPVCENtf9rsdSRs3K5Pa+OdzEdX1VhPpdM2OV1DgT9m7V2IfVNU0lvMHfUs1MNW/lBvD2ye7S+s5nqKGQrc077jX33z8Nu57xmnN3bI9i1RgS8AJKG7w1f03zBTaG4OcyxbRrK2tb6lJmX+V+Q==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Yes, this is the method we use. We only have one of our base stems provisioned to AD. Groups under that stem are (supposed to be) names uniquely according to their purpose. Department groups and the like can be included as members of these application groups. I think this works quite well. It is, in fact, one of my seven principles of Grouper group administration (https://blogs.ncl.ac.uk/integration/2016/02/19/make-applications-groups-specific/)!

 

Dave

 

From: [mailto:] On Behalf Of Julio Polo
Sent: 01 March 2017 21:09
To: Steven Carmody <>
Cc: Grouper-Users <>
Subject: Re: [grouper-users] what is a group authorized to do ?

 

I would advocate creating a group for each application/service (for each authz need).  Each of those application groups can include the same officially-sanctioned group for the desired department, but each group can have its own exceptions (inclusions and exclusions). To help track all such groups, you can create a special attribute to identify them or you could just put them all under one folder.

-julio

 

On Wed, Mar 1, 2017 at 9:41 AM, Steven Carmody <> wrote:

Hi,

We've got a growing community of dept-based people taking advantage of delegated management of group membership. And we've got a growing community of service owners managing the membership of their service eligibility groups. They sometimes include dept-based-groups in their eligibility groups.

We now have some dept-based group managers asking "before I add a person to group X, how can I find out the set of permissions and services are granted to that group?". A perfectly reasonable question.

I can see that using service management groups might help to develop an answer -- I'm wondering if other sites have yet encountered this question, and what tools they are providing to users who want an answer ?

thanks !

 




Archive powered by MHonArc 2.6.19.

Top of Page