Skip to Content.
Sympa Menu

grouper-users - RE: [grouper-users] PSPNG and groupSelectionExpression - still need etc:pspng:provision_to when using groupSelectionExpression ?

Subject: Grouper Users - Open Discussion List

List archive

RE: [grouper-users] PSPNG and groupSelectionExpression - still need etc:pspng:provision_to when using groupSelectionExpression ?

Chronological Thread 
  • From: "Black, Carey M." <>
  • To: "Pete St. Onge" <>, "" <>
  • Subject: RE: [grouper-users] PSPNG and groupSelectionExpression - still need etc:pspng:provision_to when using groupSelectionExpression ?
  • Date: Tue, 23 Jul 2019 19:37:08 +0000
  • Arc-authentication-results: i=1; 1;spf=pass;dmarc=pass action=none;dkim=pass;arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed;; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=cXt6JiLzkLSaRklhG+mQxGr9YgLBzMzIUzH9vacQtzM=; b=Pbjc9uuqr2/sUmlwWOOvX0GIm5nhZiF+OKA0x8+g/vyVOEWz/gHIxKKsdAjQqMBWzImLE6mznEuWBvnRTc7rHNL1i+I1ozN68Xikwo+BCQtd5T9mE25i69XtBD7LFUJ9Dr7S7PJFaGqOIK7s1FD9QcVTdzD0hPQzklME/qGTXI2hjJq1wguwuetmoHwSKUjnUD7Nk7ZY+thKnoY+8LRd7STAzqbld0UCdcehQMSr7+0hfC6zKW4Lt/Qgh7yx41hiROT3eMY2D9UExekFqbJj9rOtHI8VdhkuIfCG4fS3ORf7VaWF5RbujFKv1u6yBW3Asyntg2x/HbBc5ZT79zXpkA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901;; cv=none; b=H2kmA7IBgCSxehwERCq9+90cu/O7Ny8eZzLPnJHZiK6zCW1rrY0MI7xw+y70mEHYm1hy9xThaowYEpN1ZYqZ3gJ3Y4OnRoo1pOzzqBd4jXUR+cd4DQDnDQrJ/b8ejYCUUB5dnz1Em+3Idv193JxBF5kmgqHfMoIGKyQTL6PAZ9OjJYtAv9WKLkNyHdrB2Dsio46xmcQmqhNcNJO5ZhTj0hiYufD4ztRtLP0wiHQnyr3z3Cg08s0j31Zi8TJlNhmprfL7k+2/zKwca9Gua23sNq6jGHRfYHMHpY9Id2WjINudC+5+KwnRSt7ocWIiM1wnqj8qc0PqpdMFAVFuntaYFw==


I think the "docs" on "groupSelectionExpression" (
) may need some improvement.
Description: "Jexl expression that refers to stem_attributes,
group_attributes, or group"
I am really unclear on what the ",or group" means for that

However, I *think* that setting is limited to only grouper attributes. ( AKA:
Objects in Grouper called "attributes". Not "properties" of the group
themselves. Like the parent stem locations, their descriptions, their
extension values, etc....)

So I think what your config is trying to say is:
PSPNG find an attribute named "${name.startsWith("d:")}". If
the group (or stem) has that attribute on it, then provision it.
However, PSPNG would fail to find an attribute named
"${name.startsWith("d:")}" and *maybe* it falls back to the "default"
attribute? (And maybe it breaks the searching for parent objects with that

So maybe try to remove that config value and see if the system behavior

I can confirm that for me, I have the "etc:pspng:provision_to" on a parent
folder (and a parent's parent folder) with a value that matches the
provisioner's name. And the groups in the sub-sub folder are provisioned
without having the attribute directly assigned to the group.

And this is in my config:
changeLog.consumer.<provisioner's Name>.provisionerName =
<provisioner's Name>

Carey Matthew

-----Original Message-----
<> On Behalf Of Pete St. Onge
Sent: Monday, July 22, 2019 6:56 PM
Subject: [grouper-users] PSPNG and groupSelectionExpression - still need
etc:pspng:provision_to when using groupSelectionExpression ?


As a bit of a follow up on my previous email, we are successfully using
PSPNG to provision to our proof-of-concept environment, so long as all
of the groups and folders have the etc:pspng:provision_to attribute set
on all entities below our provisioning target (the "d:" stem in our

The goal, however, is to leverage specific stems to provision to
different provisioning targets (our OpenLDAP 'd' target for now, 'e' or
similar for AzureAD (and 'f' or similar for AD) in the near future ($foo
in the future etc) so that we don't have to add and manage the attributes.

From what I understand in my reading this far, the
groupSelectionExpression option should allow us to set out what stem for
the provisionner to provision. I've set this so far to this:

changeLog.consumer.pspng_groupOfNames.groupSelectionExpression =

I'm not seeing errors in the API logs during a full sync or subsequent
incrementals, but it seems like groups added below d: aren't being
provisioned unless they have the etc:pspng:provision_to attribute added,
with the value set to 'pspng_groupOfNames'

The (somewhat) redacted config is as follows:

changeLog.consumer.pspng_groupOfNames.class =
changeLog.consumer.pspng_groupOfNames.type =
changeLog.consumer.pspng_groupOfNames.quartzCron = 0 * * * * ?
changeLog.consumer.pspng_groupOfNames.ldapPoolName = d
changeLog.consumer.pspng_groupOfNames.supportsEmptyGroups = false
changeLog.consumer.pspng_groupOfNames.memberAttributeName = member
changeLog.consumer.pspng_groupOfNames.memberAttributeValueFormat =
changeLog.consumer.pspng_groupOfNames.groupSearchBaseDn =
changeLog.consumer.pspng_groupOfNames.allGroupsSearchFilter =
changeLog.consumer.pspng_groupOfNames.singleGroupSearchFilter =
changeLog.consumer.pspng_groupOfNames.groupSearchAttributes = cn,objectclass
changeLog.consumer.pspng_groupOfNames.groupCreationLdifTemplate = dn:
cn=${}||cn: ${}||objectclass: groupOfNames
changeLog.consumer.pspng_groupOfNames.userSearchBaseDn = dc=c,dc=b,dc=a
changeLog.consumer.pspng_groupOfNames.userSearchFilter =
changeLog.consumer.pspng_groupOfNames.userSearchAttributes =
changeLog.consumer.pspng_groupOfNames.grouperIsAuthoritative = true
changeLog.consumer.pspng_groupOfNames.groupCreationLdifTemplate = dn:
${utils.bushyDn("d:",""), "cn","ou")}||cn:
${grouperUtil.extensionFromName(name)}||objectclass: groupOfNames
changeLog.consumer.pspng_groupOfNames.groupSelectionExpression =

As before, any suggestions appreciated.

Thanks in advance, -- pete

Peter St. Onge
Information Security Architect (416)978-5030
Business Continuity and Communications
Information + Technology Services University of Toronto

Archive powered by MHonArc 2.6.19.

Top of Page