grouper-users - Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun)
Subject: Grouper Users - Open Discussion List
List archive
- From: Jeffrey Williams <>
- To: "Coleman, Erik C" <>
- Cc: "" <>
- Subject: Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun)
- Date: Thu, 7 Jun 2018 14:15:50 -0400
- Ironport-phdr: 9a23:fm5v5RxsLUuz2lzXCy+O+j09IxM/srCxBDY+r6Qd2+4TIJqq85mqBkHD//Il1AaPAd2Graocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze+/94HTbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDwULs6Wymt771zRRDqhicJNzA3/mLKhMJukK1WuwiuqwBlzoPOfI2ZKPhzc6XAdt0aX2pBWcNRWjRFDIyiYYsPAfABMvhYroLgp1QOrB++BQ2tBOz1zz9InWL90Ko40+QvHwDG3QggH9YPsHvOt9j1KaESXvy6zKXS0zrMcu5W1C775YPVfB4hpvSMUqhxccrX0UQvGBnFjlKNqYz9JT+V0P4Cs22F4OZ4SOKvjXIoqw5rrjip2MgslpHFhp8Tyl/Y+iV12pg6KsClSEN9fNWqE4NQujmEO4Z3Xs8vQWRluCg5x7IdpZK2eScHxIg7yxHDbvGIb5SE7xLmWeuUPzt1imxpdbSijBio60eg0PfzVsys3VZKsCVFlt7Mu2gI1xPJ68iHTuJx/lmi2TqTzgzS5f9ILE4qmabBJJ4hxbkwlpUXsUvdBCP5hEL2jKqOekUl/Oin9fjnb634qpKdK4N5iATzMqotl8OkHeg1NwcDU3SH9eug0bDs4VH1TbVPg/AzjKXUvo7WKdwepqGjAg9V1ogj6wy4DzejyNkYn3cHLVxEeBKDi4jpOkvBLevlDfe5n1usny1nyO7bMb38GpnNNGTMkK/9fbZh7E5R0AUzzcpY55JJErEOPujzVlbstNzDEBA5KRe0zv3jCNV8zYMeRXmPDrGDPKPTt1+I+vwgI/OKZIALpDbxNeIp6ODzgn8kyhchevzj9pwTZXWxGLAuDl+YYjLHyJ9VHGwBlgs6SO3sj1yZFzNfeiDhcbg742QZBYyoF4rSDr+shLiA1SKgVslUaH9HDlSNGF/1cY6LHfoAdXTBcYdajjUYWO35GMca3ha0uVqixg==
I am progressing with PSPNG running pretty smoothly now, so I’m moving on to prettying up the data, but encountered another snag… we are pushing most groups to a single flat OU, using the ${group.name} the group as the CN (i.e., “stem1:mygroup”). And by default, if you don’t specify samAccountName in groupCreationLDIFTemplate, that ends up getting assigned a random value by AD, which is rather ugly and unusable in some interfaces.
I’d like to set the samAccountName to something equally unique, but of course I cannot use “:” colon characters in AD group names so ${group.name} fails. Setting samAccountName to ${group.extension} is potentially not unique if I have two groups with the same extension (i.e., “stem1:mygroup” and “stem2:mygroup”).
So is there some clever JEXL trick that I can do to replace “:” with a hyphen “-“ in the ${group.name}? Or can I do something like “${group.parentStem}-${group.
extension}”? Does anyone have some LDIF templates they’d be willing to share? It is so hard to test JEXL!
Thanks!
-Erik
--
Erik Coleman <>
Identity and Acccess Management
Technology Services
University of Illinois at Urbana-Champaign
Identity Architecture, ITS
University of North Carolina at Greensboro
256-TECH (256-8324)
- [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun), Coleman, Erik C, 06/07/2018
- Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun), Jeffrey Williams, 06/07/2018
- Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun), Jeffrey Williams, 06/07/2018
- Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun), Julio Macavilca, 06/07/2018
- Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun), Jeffrey Williams, 06/07/2018
- Re: [grouper-users] PSPNG groupCreationLDIFTemplate (more JEXL fun), Jeffrey Williams, 06/07/2018
Archive powered by MHonArc 2.6.19.