Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] PSPNG creates group in AD with random samaccountname

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] PSPNG creates group in AD with random samaccountname


Chronological Thread 
  • From: Julio Macavilca <>
  • To: "Sawyer, Mona Zarei" <>
  • Cc: "Coleman, Erik C" <>, "" <>
  • Subject: Re: [grouper-users] PSPNG creates group in AD with random samaccountname
  • Date: Mon, 23 Oct 2017 11:53:14 -0400
  • Ironport-phdr: 9a23:9e8pPxEzhsRRfGuaGnH/o51GYnF86YWxBRYc798ds5kLTJ7ypsWwAkXT6L1XgUPTWs2DsrQf2rqQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDmwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VC+85Kl3VhDnlCYHNyY48G7JjMxwkLlbqw+lqxBm3oLYfJ2ZOP94c6jAf90VWHBBU95TWCxPAo2yYYgBAfcfM+lEtIT9vUcCoAGkCAWwGO/iyDlFjWL2060g1OQhFBnL0gg9H9IKsXTUq8j+OqAIXu+p1qbI0zTDb/dK1jjn9YPFdRIhoeyIXbJxdsrc0k8vFgPYjlmKt4PqIi6V2/0LvmOG4eRgUuevhHQmqwF3ujWvycAsio7GhoIR1F/I7zl2wIEwJdGgVE57YcSkH4VKuC6HLYd2WN4iQ2dwtCY10L0GvoO7fDAQxJQh3RHfbuKIf5CM4hLkW+aRLil3hGh/dL2hmhmy7E6twfD/WMmsyFtGsCtInsXOu30I2Rze6dOIRud480quxTqDyx7f5+RYLkwolafWLpsszqA+m5cTt0nIAzX4l1/sjKCMc0Up4uio5PrjYrXhvpKcMpV7igD6Mqg3ms2+D/g0PhEBXmSF9+mx1Kfv/UL+QLVNgf02lrfWvIrGKsQco661Gw5V0oA95BajFzqqztUVkWUFIV9AdhKKjJPmN03LLf33Efuzn0qgnTJ3yPzaPrDsB5DAImbNnbrhZbp97lRTyAs3zdBR/ZJUDbQBLerxWk/0tNHVDx40PxCvzubhCNR9y5kSVnySDa+EKK/Sq0OH5vozI+mQY48YoDn9K+Ii5/7zlX82h0UdcbC03ZsMdn+4BO9mLl6dYXrtmdcBDXwKshQkQOzrjl2CTSBcZ2y0X60i+jE3FpiqApneSYCw0/S923LxJZRJd21cThipFnHhP7eNQfoNImrGJ8hnmy4sULmoTo5n2B2z4lzAxqJjP9bTry8FsZPk/N5k+qvemQxh2yZzCpG/zmWMSClRl2gBWT4y16k39U5gzlaE+a5pnrpVGcEFtKABaRszKZOJl78yMNv1QA+UO47REFs=

Hi Mona,

What Erik mentioned is correct, we set samAccountName in groupCreationLdifTemplate.  What do you have in your grouper-loader config for groupCreationLdifTemplate?  Also, if you have access to AD, what does the connection transactions logs say as grouper tries to provision?  Lastly, I would turn up pspng logging to debug while testing, add the following to your log4j.properties:

log4j.logger.edu.internet2.middleware.grouper.pspng=DEBUG
log4j.logger.edu.internet2.middleware.grouper.changeLog=DEBUG

thanks,
Julio

On Mon, Oct 23, 2017 at 11:34 AM, Sawyer, Mona Zarei <> wrote:

I tried to add the samaccountname to the configuration but I get an attribute conversion error. Please see below.

Any ideas how we can fix this issue?

 

2017-10-23 11:26:35,884: [pspng_activedirectory-FullSync-Thread] ERROR LdapGroupProvisioner.createGroup(346) -  - Problem while creating new group: dn:cn=testsamacc

objectclass: group

 samAccountName:cn=testsamacc

edu.internet2.middleware.grouper.pspng.PspException: LDAP problem creating object: javax.naming.directory.NoSuchAttributeException: [LDAP: error code 16 - 00000057: LdapErr: DSID-0C090DB1, comment: Error in attribute conversion operation, data 0, v2580 ]; remaining name 'cn=testsamacc ,CN=Users,DC=cgcent,DC=miami,DC=edu'

                at edu.internet2.middleware.grouper.pspng.LdapSystem.performLdapAdd(LdapSystem.java:338)

                at edu.internet2.middleware.grouper.pspng.LdapProvisioner.performLdapAdd(LdapProvisioner.java:725)

                at edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner.createGroup(LdapGroupProvisioner.java:340)

                at edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner.createGroup(LdapGroupProvisioner.java:47)

                at edu.internet2.middleware.grouper.pspng.Provisioner.prepareGroupCache(Provisioner.java:749)

                at edu.internet2.middleware.grouper.pspng.Provisioner.startProvisioningBatch(Provisioner.java:475)

                at edu.internet2.middleware.grouper.pspng.FullSyncProvisioner.processGroup(FullSyncProvisioner.java:598)

                at edu.internet2.middleware.grouper.pspng.FullSyncProvisioner.thread_manageFullSyncProcessing(FullSyncProvisioner.java:256)

                at edu.internet2.middleware.grouper.pspng.FullSyncProvisioner$1.run(FullSyncProvisioner.java:188)

                at java.lang.Thread.run(Thread.java:745)

2017-10-23 11:26:35,885: [pspng_activedirectory-FullSync-Thread] ERROR FullSyncProvisioner.processGroup(609) -  - pspng_activedirectory-FullSync: Problem doing full sync. Requeuing group UM_External_Groups:testsamacc

edu.internet2.middleware.grouper.pspng.PspException: LDAP problem creating object: javax.naming.directory.NoSuchAttributeException: [LDAP: error code 16 - 00000057: LdapErr: DSID-0C090DB1, comment: Error in attribute conversion operation, data 0, v2580 ]; remaining name 'cn=testsamacc ,CN=Users,DC=cgcent,DC=miami,DC=edu'

                at edu.internet2.middleware.grouper.pspng.LdapSystem.performLdapAdd(LdapSystem.java:338)

                at edu.internet2.middleware.grouper.pspng.LdapProvisioner.performLdapAdd(LdapProvisioner.java:725)

                at edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner.createGroup(LdapGroupProvisioner.java:340)

                at edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner.createGroup(LdapGroupProvisioner.java:47)

                at edu.internet2.middleware.grouper.pspng.Provisioner.prepareGroupCache(Provisioner.java:749)

                at edu.internet2.middleware.grouper.pspng.Provisioner.startProvisioningBatch(Provisioner.java:475)

                at edu.internet2.middleware.grouper.pspng.FullSyncProvisioner.processGroup(FullSyncProvisioner.java:598)

                at edu.internet2.middleware.grouper.pspng.FullSyncProvisioner.thread_manageFullSyncProcessing(FullSyncProvisioner.java:256)

                at edu.internet2.middleware.grouper.pspng.FullSyncProvisioner$1.run(FullSyncProvisioner.java:188)

                at java.lang.Thread.run(Thread.java:745)

 

Thank you so much,

Best Reagrds,

 

Mona Z Sawyer M.Sc.

Programmer Intermediate

Middleware and Identity Services

Information Technology | University of Miami

1320 S. Dixie Hwy | Suite 1000.49

Coral Gables, Fl 33146

305-284-2214

 

"At the U, we transform lives through teaching, research and service."

UMIT Logo -
            Email Signature

 

From: [mailto:] On Behalf Of Coleman, Erik C
Sent: Friday, October 20, 2017 3:23 PM
To:
Subject: RE: [grouper-users] PSPNG creates group in AD with random samaccountname

 

We are seeing the same issue, and it is on our list of things to track down, just hasn’t bubbled up to the top yet. We are using PSP-NG to sync to Active Directory.  It looks like you can possibly set samAccountName explicitly using the “groupCreationLdifTemplate” property of the connector, perhaps by just appending:  “||samAccountName: ${group.name}”

 

Has anyone else successfully done this?

 

Thanks!

 

-Erik

 

 

--

Erik Coleman

Senior Manager, Enterprise Systems

Technology Services at Illinois

University of Illinois at Urbana-Champaign

 

 

 

From: [] On Behalf Of Sawyer, Mona Zarei
Sent: Friday, October 20, 2017 11:05
To:
Subject: [grouper-users] PSPNG creates group in AD with random samaccountname

 

Hello,

 

We are having PSPNG working to provision new groups into AD. The groups get created in AD with the same name as the group name in grouper, However, the samaccountname is a random character.

(groups name : “TestGroup”; group samaccountname : “$CK8Q00-M7J9243J15RK”)

For consistency, we need to have the group’s samaccountname the same as the name in AD.

Please kindly let me know how we can fix this.

 

Thank you so much.

 

Mona Z Sawyer M.Sc.

Programmer Intermediate

Middleware and Identity Services

Information Technology

University of Miami

1320 S. Dixie Hwy

Suite 1000.49

Coral Gables, Fl 33146

305-284-2214

 

"At the U, we transform lives through teaching, research and service."

UMIT Logo -
            Email Signature

 

 





Archive powered by MHonArc 2.6.19.

Top of Page