Skip to Content.
Sympa Menu

grouper-users - [grouper-users] RE: One group - multiple provisioners

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] RE: One group - multiple provisioners


Chronological Thread 
  • From: Ryan Rumbaugh <>
  • To: "" <>
  • Subject: [grouper-users] RE: One group - multiple provisioners
  • Date: Fri, 27 Jul 2018 17:56:36 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:fIk4YxFn6lmXpTtyDEL8G51GYnF86YWxBRYc798ds5kLTJ76p8y9bnLW6fgltlLVR4KTs6sC17KI9fi4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQpFiCa8bL9oMBm6sRjau9ULj4dlNqs/0AbCrGFSe+RRy2NoJFaTkAj568yt4pNt8Dletuw4+cJYXqr0Y6o3TbpDDDQ7KG81/9HktQPCTQSU+HQRVHgdnwdSDAjE6BH6WYrxsjf/u+Fg1iSWIdH6QLYpUjul8qlrVQToiD8ZODEl7GHZhMtwjKdBrxKgoRx03orYbY6ROfZ7eK7WYNEUSndbXstJVyJPHJ6yb5cBAeQCM+ZXrYj9qEcBohalHwagGP/jxyVUinPqw6E31fkqHwHc3AwnGtIDqGjardXvO6cUTOu70LTIzTDYYPxMxDf954jIeQ0mrPGWR7JwbM/RxlI1GAPYgVWQqZfoPzWL2esWqWiU9fFgVeG1hGI9tQ5+vyWvy94qh4LUiIwVzVXE+j94wIYzPdC3U0l7YNG+HJRMsCGaMo17Sd4hTWFwoCs21KcJtYKmcCUP1Zgr2gPTZvmJc4WH/h7vSOOcLDVmi39qeb+yghO//Va8xuD4TsW4zUhGoy5fntTIuH0BzRLe58idRvZz/0qtwTiP2B7Q5+1YJE05kLfUJp46zbEsk5ces1nPEyz3lUjzkqObckYp9+at5unkeLrrppyROolpgQ/kKKsugNawAeEgPwgOQWeb/eO82aX780DlR7tGkuM6nrDEvZ7cO8gXv6m5DBRL3Yo57Ba/Eium388fnXkaKlJKZQiLj5DzO1HJPPD3E+uwg0itkDdswfDKJLrhAojRLnjHl7fherV951RAxwo0yNBT/5NUCrcfL/LvQkL9qsbXAgMkPwGx3urrFchx24YQWW+AHqOVLKbfvF2W6e8gIuSBYYoYtCjhJ/Uh//LuiGU2mV4Zfamnx5sXb3W4E+x8I0WDfHrsh8wOHn0XvgoxTOznk1uCXiBIaHaoRa08/TI7B5i8AYjdW4+tnaSN3D2nEZ1OemBGFleMHG/nd4WeXPcMdTqSLdF7kjAdSLihUJEu1Qu1tALhz7pnL/HU+jEDtZ79ztR15uvTlQ0s+jxuCcSSzX2NQ39ukmwWWjA2wfM3nUsogFiZ1rVgjuYdCMde/ehhUwEmOITawvAgTd3+R0iJKtiTT0u+T8/jHCo8VMkZwtkSblx7Fsn4yB3Pwnz5LaUSkumxFZUyupjB2nL4Osl9gyLczrQkhVA7TctnM2CsnKdk9AGVCoLUxRbK3522fLgRiXaevFyIynCD6R0JClQiWLjZXX0ZekrdpMj44UWHVbK1FLA7KVUcm9WaJP5MbdvkxRVdSfHvNc6WQlr5mnz4RHPqjqiJcJKsfmwc2CvHD01RiRoO+HyPKAc+LiGsqXjXFz9nU1/jfhCk/A==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Not sure if I can attach images to this listserv or not, but I added a screenshot to Box here: https://nebraska.box.com/s/dt2q5atb0icxhtrboo1ffp61vcthae4c

 

Here are the configs for each:

 

changeLog.consumer.pspng_ad_lincoln.class = edu.internet2.middleware.grouper.pspng.PspChangelogConsumerShim

changeLog.consumer.pspng_ad_lincoln.type = edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner

changeLog.consumer.pspng_ad_lincoln.quartzCron = 0 * * * * ?

changeLog.consumer.pspng_ad_lincoln.ldapPoolName = ad_lincoln

changeLog.consumer.pspng_ad_lincoln.isActiveDirectory = true

changeLog.consumer.pspng_ad_lincoln.memberAttributeName = member

changeLog.consumer.pspng_ad_lincoln.memberAttributeValueFormat = ${ldapUser.getDn()}

changeLog.consumer.pspng_ad_lincoln.groupSearchBaseDn = OU=Grouper-ES,DC=adtest,DC=unl,DC=edu

changeLog.consumer.pspng_ad_lincoln.allGroupsSearchFilter = objectclass=group

changeLog.consumer.pspng_ad_lincoln.singleGroupSearchFilter = (&(objectclass=group)(cn=${group.name}))

changeLog.consumer.pspng_ad_lincoln.groupCreationLdifTemplate = dn: cn=${group.name}||cn: ${group.name}||objectclass: group

changeLog.consumer.pspng_ad_lincoln.userSearchBaseDn = OU=people,DC=adtest,DC=unl,DC=edu

changeLog.consumer.pspng_ad_lincoln.userSearchFilter = unlUNCWID=${subject.id}

changeLog.consumer.pspng_ad_lincoln.userSearchAttributes = dn,cn,mail,sAMAccountName,objectclass,unlUNCWID

changeLog.consumer.pspng_ad_lincoln.grouperIsAuthoritative = true

 

 

changeLog.consumer.pspng_ad_nebraska.class = edu.internet2.middleware.grouper.pspng.PspChangelogConsumerShim

changeLog.consumer.pspng_ad_nebraska.type = edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner

changeLog.consumer.pspng_ad_nebraska.quartzCron = 0 * * * * ?

changeLog.consumer.pspng_ad_nebraska.ldapPoolName = ad_nebraska

changeLog.consumer.pspng_ad_nebraska.isActiveDirectory = true

changeLog.consumer.pspng_ad_nebraska.memberAttributeName = member

changeLog.consumer.pspng_ad_nebraska.memberAttributeValueFormat = ${ldapUser.getDn()}

changeLog.consumer.pspng_ad_nebraska.groupSearchBaseDn = OU=Grouper,DC=neadtest,DC=nebraska,DC=edu

changeLog.consumer.pspng_ad_nebraska.allGroupsSearchFilter = objectClass=group

changeLog.consumer.pspng_ad_nebraska.singleGroupSearchFilter = (&(objectClass=group)(cn=${group.name}))

changeLog.consumer.pspng_ad_nebraska.groupCreationLdifTemplate = dn: cn=${group.name}||cn: ${group.name}||objectClass: group

changeLog.consumer.pspng_ad_nebraska.groupCreationBaseDn = OU=Grouper,DC=neadtest,DC=nebraska,DC=edu

changeLog.consumer.pspng_ad_nebraska.userSearchBaseDn = OU=People,DC=neadtest,DC=nebraska,DC=edu

changeLog.consumer.pspng_ad_nebraska.userSearchFilter = sAMAccountName=${subject.id}

changeLog.consumer.pspng_ad_nebraska.grouperIsAuthoritative = true

 

Thanks for your assistance!

 

--

Ryan Rumbaugh

Identity Management Specialist

Cybersecurity & Identity |ITS|

501 123.1, 68588-0203

University of Nebraska |nebraska.edu

Kearney|Lincoln|Omaha

402-472-0831 (o)

 

From: Bee-Lindgren, Bert <>
Sent: Thursday, July 26, 2018 3:42 PM
To: Ryan Rumbaugh <>;
Subject: Re: One group - multiple provisioners

 

Ryan,

 

Multiple provision_to assignments, indeed, mark a group/folder to be provisioned by the multiple pspng provisioners. As you noticed, pspng uses multi-assign, single-valued attributes for this.

 

Can you share the provisioner-config parts of grouper-loader.properties as well as gsh input for the attribute-setting or a gui view of the multiple assignments?

 


From: <> on behalf of Ryan Rumbaugh <>
Sent: Thursday, July 26, 2018 4:03 PM
To:
Subject: [grouper-users] One group - multiple provisioners

 

Hi all!

 

We have about five downstream pspng provisioners configured in our environment and the question came up about whether or not we could provision one Grouper group to multiple directories. Does anyone know if there is a method to do so?

 

We have experimented with setting multiple “provision_to” attributes with different configured grouper-loader.properties pspng assignment values, but that doesn’t seem to work. Additionally, we tried to set multiple assignment values, but received the following exception:

 

Error: Cannot add multiple values to a single valued attribute: AttributeDefName[name=etc:pspng:provision_to,uuid=fa0342415de04e52a87eddd913d049a4], Problem calling method assignAddValueSubmit on edu.internet2.middleware.grouper.grouperUi.serviceLogic.SimpleAttributeUpdate

 

Thanks!

--

Ryan Rumbaugh

Identity Management Specialist

Cybersecurity & Identity |ITS|

501 123.1, 68588-0203

University of Nebraska |nebraska.edu

Kearney|Lincoln|Omaha

402-472-0831 (o)

 




Archive powered by MHonArc 2.6.19.

Top of Page