grouper-users - [grouper-users] RE: One group - multiple provisioners
Subject: Grouper Users - Open Discussion List
List archive
- From: Ryan Rumbaugh <>
- To: "" <>
- Subject: [grouper-users] RE: One group - multiple provisioners
- Date: Fri, 27 Jul 2018 17:56:36 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:fIk4YxFn6lmXpTtyDEL8G51GYnF86YWxBRYc798ds5kLTJ76p8y9bnLW6fgltlLVR4KTs6sC17KI9fi4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQpFiCa8bL9oMBm6sRjau9ULj4dlNqs/0AbCrGFSe+RRy2NoJFaTkAj568yt4pNt8Dletuw4+cJYXqr0Y6o3TbpDDDQ7KG81/9HktQPCTQSU+HQRVHgdnwdSDAjE6BH6WYrxsjf/u+Fg1iSWIdH6QLYpUjul8qlrVQToiD8ZODEl7GHZhMtwjKdBrxKgoRx03orYbY6ROfZ7eK7WYNEUSndbXstJVyJPHJ6yb5cBAeQCM+ZXrYj9qEcBohalHwagGP/jxyVUinPqw6E31fkqHwHc3AwnGtIDqGjardXvO6cUTOu70LTIzTDYYPxMxDf954jIeQ0mrPGWR7JwbM/RxlI1GAPYgVWQqZfoPzWL2esWqWiU9fFgVeG1hGI9tQ5+vyWvy94qh4LUiIwVzVXE+j94wIYzPdC3U0l7YNG+HJRMsCGaMo17Sd4hTWFwoCs21KcJtYKmcCUP1Zgr2gPTZvmJc4WH/h7vSOOcLDVmi39qeb+yghO//Va8xuD4TsW4zUhGoy5fntTIuH0BzRLe58idRvZz/0qtwTiP2B7Q5+1YJE05kLfUJp46zbEsk5ces1nPEyz3lUjzkqObckYp9+at5unkeLrrppyROolpgQ/kKKsugNawAeEgPwgOQWeb/eO82aX780DlR7tGkuM6nrDEvZ7cO8gXv6m5DBRL3Yo57Ba/Eium388fnXkaKlJKZQiLj5DzO1HJPPD3E+uwg0itkDdswfDKJLrhAojRLnjHl7fherV951RAxwo0yNBT/5NUCrcfL/LvQkL9qsbXAgMkPwGx3urrFchx24YQWW+AHqOVLKbfvF2W6e8gIuSBYYoYtCjhJ/Uh//LuiGU2mV4Zfamnx5sXb3W4E+x8I0WDfHrsh8wOHn0XvgoxTOznk1uCXiBIaHaoRa08/TI7B5i8AYjdW4+tnaSN3D2nEZ1OemBGFleMHG/nd4WeXPcMdTqSLdF7kjAdSLihUJEu1Qu1tALhz7pnL/HU+jEDtZ79ztR15uvTlQ0s+jxuCcSSzX2NQ39ukmwWWjA2wfM3nUsogFiZ1rVgjuYdCMde/ehhUwEmOITawvAgTd3+R0iJKtiTT0u+T8/jHCo8VMkZwtkSblx7Fsn4yB3Pwnz5LaUSkumxFZUyupjB2nL4Osl9gyLczrQkhVA7TctnM2CsnKdk9AGVCoLUxRbK3522fLgRiXaevFyIynCD6R0JClQiWLjZXX0ZekrdpMj44UWHVbK1FLA7KVUcm9WaJP5MbdvkxRVdSfHvNc6WQlr5mnz4RHPqjqiJcJKsfmwc2CvHD01RiRoO+HyPKAc+LiGsqXjXFz9nU1/jfhCk/A==
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
Not sure if I can attach images to this listserv or not, but I added a screenshot to Box here:
https://nebraska.box.com/s/dt2q5atb0icxhtrboo1ffp61vcthae4c Here are the configs for each: changeLog.consumer.pspng_ad_lincoln.class = edu.internet2.middleware.grouper.pspng.PspChangelogConsumerShim changeLog.consumer.pspng_ad_lincoln.type = edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner changeLog.consumer.pspng_ad_lincoln.quartzCron = 0 * * * * ? changeLog.consumer.pspng_ad_lincoln.ldapPoolName = ad_lincoln changeLog.consumer.pspng_ad_lincoln.isActiveDirectory = true changeLog.consumer.pspng_ad_lincoln.memberAttributeName = member changeLog.consumer.pspng_ad_lincoln.memberAttributeValueFormat = ${ldapUser.getDn()} changeLog.consumer.pspng_ad_lincoln.groupSearchBaseDn = OU=Grouper-ES,DC=adtest,DC=unl,DC=edu changeLog.consumer.pspng_ad_lincoln.allGroupsSearchFilter = objectclass=group changeLog.consumer.pspng_ad_lincoln.singleGroupSearchFilter = (&(objectclass=group)(cn=${group.name})) changeLog.consumer.pspng_ad_lincoln.groupCreationLdifTemplate = dn: cn=${group.name}||cn: ${group.name}||objectclass: group changeLog.consumer.pspng_ad_lincoln.userSearchBaseDn = OU=people,DC=adtest,DC=unl,DC=edu changeLog.consumer.pspng_ad_lincoln.userSearchFilter = unlUNCWID=${subject.id} changeLog.consumer.pspng_ad_lincoln.userSearchAttributes = dn,cn,mail,sAMAccountName,objectclass,unlUNCWID changeLog.consumer.pspng_ad_lincoln.grouperIsAuthoritative = true changeLog.consumer.pspng_ad_nebraska.class = edu.internet2.middleware.grouper.pspng.PspChangelogConsumerShim changeLog.consumer.pspng_ad_nebraska.type = edu.internet2.middleware.grouper.pspng.LdapGroupProvisioner changeLog.consumer.pspng_ad_nebraska.quartzCron = 0 * * * * ? changeLog.consumer.pspng_ad_nebraska.ldapPoolName = ad_nebraska changeLog.consumer.pspng_ad_nebraska.isActiveDirectory = true changeLog.consumer.pspng_ad_nebraska.memberAttributeName = member changeLog.consumer.pspng_ad_nebraska.memberAttributeValueFormat = ${ldapUser.getDn()} changeLog.consumer.pspng_ad_nebraska.groupSearchBaseDn = OU=Grouper,DC=neadtest,DC=nebraska,DC=edu changeLog.consumer.pspng_ad_nebraska.allGroupsSearchFilter = objectClass=group changeLog.consumer.pspng_ad_nebraska.singleGroupSearchFilter = (&(objectClass=group)(cn=${group.name})) changeLog.consumer.pspng_ad_nebraska.groupCreationLdifTemplate = dn: cn=${group.name}||cn: ${group.name}||objectClass: group changeLog.consumer.pspng_ad_nebraska.groupCreationBaseDn = OU=Grouper,DC=neadtest,DC=nebraska,DC=edu changeLog.consumer.pspng_ad_nebraska.userSearchBaseDn = OU=People,DC=neadtest,DC=nebraska,DC=edu changeLog.consumer.pspng_ad_nebraska.userSearchFilter = sAMAccountName=${subject.id} changeLog.consumer.pspng_ad_nebraska.grouperIsAuthoritative = true Thanks for your assistance! -- Ryan Rumbaugh Identity Management Specialist Cybersecurity & Identity |ITS| 501 123.1, 68588-0203 University of Nebraska |nebraska.edu Kearney|Lincoln|Omaha 402-472-0831 (o) From: Bee-Lindgren, Bert <>
Ryan, Multiple provision_to assignments, indeed, mark a group/folder to be provisioned by the multiple pspng provisioners. As you noticed, pspng uses multi-assign, single-valued attributes for this. Can you share the provisioner-config parts of grouper-loader.properties as well as gsh input for the attribute-setting or a gui view of the multiple assignments? From:
<> on behalf of Ryan Rumbaugh <> Hi all! We have about five downstream pspng provisioners configured in our environment and the question came up about whether or not we could provision one Grouper group to multiple directories.
Does anyone know if there is a method to do so? We have experimented with setting multiple “provision_to” attributes with different configured grouper-loader.properties pspng assignment values, but that doesn’t seem to work.
Additionally, we tried to set multiple assignment values, but received the following exception: Error: Cannot add multiple values to a single valued attribute: AttributeDefName[name=etc:pspng:provision_to,uuid=fa0342415de04e52a87eddd913d049a4], Problem calling method assignAddValueSubmit
on edu.internet2.middleware.grouper.grouperUi.serviceLogic.SimpleAttributeUpdate Thanks! -- Ryan Rumbaugh Identity Management Specialist Cybersecurity & Identity |ITS| 501 123.1, 68588-0203 University of Nebraska |nebraska.edu Kearney|Lincoln|Omaha 402-472-0831 (o) |
- [grouper-users] One group - multiple provisioners, Ryan Rumbaugh, 07/26/2018
- [grouper-users] Re: One group - multiple provisioners, Bee-Lindgren, Bert, 07/26/2018
- [grouper-users] RE: One group - multiple provisioners, Ryan Rumbaugh, 07/27/2018
- Re: [grouper-users] One group - multiple provisioners, Gettes, Michael, 07/26/2018
- RE: [grouper-users] One group - multiple provisioners, Ryan Rumbaugh, 07/27/2018
- [grouper-users] Re: One group - multiple provisioners, Bee-Lindgren, Bert, 07/26/2018
Archive powered by MHonArc 2.6.19.