Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Re: PSP (Original) Provisioning to LDAP and AD woes

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Re: PSP (Original) Provisioning to LDAP and AD woes


Chronological Thread 
  • From: Jeffrey Crawford <>
  • To: "Hyzer, Chris" <>
  • Cc: "Bee-Lindgren, Bert" <>, Gouper Users List <>
  • Subject: Re: [grouper-users] Re: PSP (Original) Provisioning to LDAP and AD woes
  • Date: Tue, 21 Mar 2017 10:38:19 -0700
  • Ironport-phdr: 9a23:f2hhux273Or1CUXcsmDT+DRfVm0co7zxezQtwd8ZseIULPad9pjvdHbS+e9qxAeQG96KtrQa2qGP6/mocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDqwbalzIRiyogndq9UajZZ/Iast1xXFpWdFdf5Lzm1yP1KTmBj85sa0/JF99ilbpuws+c1dX6jkZqo0VbNXAigoPGAz/83rqALMTRCT6XsGU2UZiQRHDg7Y5xznRJjxsy/6tu1g2CmGOMD9UL45VSi+46ptVRTlkzkMOSIn/27Li8xwlKNbrwynpxxj2I7ffYWZOONjcq/BYd8WQGxMVdtTWSNcGIOxd4kAD+QBM+hWrIfzukUAogelCAa2GO/i0CVFimPq0aA41ekqDAHI3BYnH9ILqHnaqMv6NKkcUeCv0qbJzSjIYu1M2Tjn5onIfBchoeuRUrltdsfRy1cgFw3LjlWKt4PkPy+a2/8Qs2eH9OpvSfijhHA6pAFsuzWiwNonhIrRho8N1FzJ9Dl1zYQwKN22S0N0esKoHZ5fui2GK4d6X8YvTH10tCkhz7ALvIC3cDYUx5kh2hXRceaIc5KS7RLmTOuRISl3hHZieL+ngha960mgyunlWsm1zFZGsjNJk9bSunwTyRPf8MeHSvx6/keu3TaAyRrf5f1DIUAxjabbKpghzaAslpcLr0jOHzP6lUfzga+YdUgr4fSk5uHob7n6upOQKop5hR3iPqs1n8GyBPo0PhYQUGSD/OSzzrzj/Un3QLVQif02l7HUsJLEKsQVqK65GRFa04Y/5BukEjepzM8YkmUdIF1bZR2HkpDlO0vSL/DgEfe/n1OsnS9kx/DcOb3hH43NIWbZkLv4YLZ98FBTyBAozd1E45JUC6oBIO7oWkPvrtDYDxk5MxCqzOb9DtVyyJ8eVXyVDqCHLazSrAzA2uV6acmddoIP/H7WK+Ik/LSm2XoymU4PcLOB3IAcLm2gE/JgZUiVfCy/rM0GFDIoswQwVuH7wHaYWCFdYGy+F/Y+6z81Eo+3Bq/eTZumxrGNwXHoTdVtemlaBwXUQj/TfIKeVqJJMXrKLw==

The problem is that we don't seem to be ready for pspng yet, PSP is really stable and there is a couple of outstanding issues with PSPNG that I'm working with Bert on (Stopping if a subject isn't present, updating non group membership information like description). PSP is doing all that but it seems tied to one source.

Jeffrey E. Crawford
Enterprise Service Team

Both pilots and IT professionals require training and currency before charging into clouds!
---------------------------------------

On Tue, Mar 21, 2017 at 9:46 AM, Hyzer, Chris <> wrote:

Cant each configuration for the different pspng’s have different userSearchFilter configs to accommodate that?  Or use the guid somehow?  I would hope we don’t need a different subject source…

 

From: Jeffrey Crawford [mailto:]
Sent: Tuesday, March 21, 2017 12:43 PM
To: Hyzer, Chris <>
Cc: Bee-Lindgren, Bert <>; Gouper Users List <>


Subject: Re: [grouper-users] Re: PSP (Original) Provisioning to LDAP and AD woes

 

Easiest example of the differing DN's would be:

LDAP: uid=jeffreyc,ou=people,dc=ucsc,dc=edu

AD:   cn=jeffreyc,ou=autest,dc=test,dc=ucsc,dc=edu

 

We base the lookups on a custom attribute in both LDAP and AD called "guid" this is what is stored in Grouper and is used as the subject id.

 

 


Jeffrey E. Crawford
Enterprise Service Team

 

Both pilots and IT professionals require training and currency before charging into clouds!

---------------------------------------

 

On Tue, Mar 21, 2017 at 6:10 AM, Hyzer, Chris <> wrote:

Can you explain what your subject id is composed of, what subject identifiers you have in your source, what your DN is made up of in AD, and if any attributes in that user object in AD exist as the subject ID or one of the identifiers?

 

From: [mailto:] On Behalf Of Bee-Lindgren, Bert
Sent: Tuesday, March 21, 2017 7:47 AM
To: Jeffrey Crawford <>; Gouper Users List <>
Subject: Re: [grouper-users] Re: PSP (Original) Provisioning to LDAP and AD woes

 

Jeffrey,

 

While I've asked Shilen and Chris to verify my theory, I thought I'd sketch it out here before they have a chance so it's not further delayed by my training this week....

 

I think your two daemons don't have enough information nor enough separation to work together properly. I think you need you need to set up your grouper daemons as follows:

1) The "Main" daemon

-Runs the default jobs (change_log_temp to changelog, loaders, etc)

-Has changelog.consumer entries for _all_ the changelog listeners (including pspad)

-Has the pspad changelog listener disabled, perhaps with a blank schedule or with a schedule that specifies year=2010

-Runs the default psp that you've been using

 

2) The "PSP-AD" daemon

-Disables the default jobs, probably with changeLog.changeLogTempToChangeLog.enable = false and perhaps other properties

-I don't know how to disable this daemon from becoming a loader-job node
-Has the changelog.consumer entry for pspad as well as an active quartz schedule for it.

 

Hoping this helps,

  Bert

 


From: <> on behalf of Jeffrey Crawford <>
Sent: Monday, March 20, 2017 1:05 PM
To: Gouper Users List
Subject: [grouper-users] Re: PSP (Original) Provisioning to LDAP and AD woes

 

bump :)


Jeffrey E. Crawford
Enterprise Service Team

 

Both pilots and IT professionals require training and currency before charging into clouds!

---------------------------------------

 

On Fri, Mar 17, 2017 at 12:38 PM, Jeffrey Crawford <> wrote:

I'll try and keep this as simple as possible. We are not yet ready to move to PSPNG but we have an active project of provisioning groups to AD and have an existing provisioner to a couple of LDAP instances.

 

The LDAP servers use the same DN naming convention so we are able to split up the servers based on the multiple ldap psp-example. Now however we need to provision groups to AD which has a different DN. The following are the things I've tried:

 

running a second daemon that shows the sources.xml as being the AD server, however it seems like the daemon that hits the changelog first wins even if one had a different name for the psp changelog string:

grouper-loader.properties (LDAP)

changeLog.consumer.pspidm.class = edu.internet2.middleware.psp.grouper.PspChangeLogConsumer

 

grouper-loader.prperties (AD)

changeLog.consumer.pspad.class = edu.internet2.middleware.psp.grouper.PspChangeLogConsumer

 

I tried using a different source id in sources.xml but then you would have to update groups twice one from each source or provisioners based on the AD source would be blank

 

Is there some method I'm missing here?

 

Jeffrey E. Crawford
Enterprise Service Team

 

Both pilots and IT professionals require training and currency before charging into clouds!

---------------------------------------

 

 





Archive powered by MHonArc 2.6.19.

Top of Page