grouper-users - RE: [grouper-users] PSPNG Group rename events....
Subject: Grouper Users - Open Discussion List
List archive
- From: "Hyzer, Chris" <>
- To: "Black, Carey M." <>, Jeffrey Williams <>
- Cc: "" <>
- Subject: RE: [grouper-users] PSPNG Group rename events....
- Date: Wed, 31 Jul 2019 14:04:20 +0000
- Arc-authentication-results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=isc.upenn.edu;dmarc=pass action=none header.from=isc.upenn.edu;dkim=pass header.d=isc.upenn.edu;arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=IgDYXtPF9nS9Rai8FNTHxf18AzmLeXe6RK8xIxBK/M0=; b=kFhEtTPW9XDjRoUh8MODiifaXxTQoLouux9cEtbmJ9bOBTQLH1F3iNU7nQI6y1raPxFFmsTnus4x0o/1s/UNX+b6rjmUxJZXdb8oVKHx8LOQsKBjX1gijHJrnibSAQJrwkWN2qyT7YaSsrrxA2eihqS4Bn/utOAbqQJCEg4MZnANyI5jKRtRy7At22xPJvXkeI9BkoN+Mu4jh0Yjh8830Hf/EwhIuy7vMHInxiLZW1dgQm855xo1GL1dARNSMENZwYu9kUHcv1lo7B1q5G1ljRm8i1eE4XhXaF/RgezAe3ukb6GVHIQe8O8dyaKwEcQ8xEAspR+P8VsMuAap9htuQw==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=FQi21au3718Zs6Q8LMFseAZUOUdTAvs+xXtPDr+OLNXJfYw76akVgKV9cX3Fw7xrFuysJjsl2MynuiUynZT7fdtvytRh72YjYfI07NGYRTSFVO4KOGxEP56h7E/AmR5qnqrC3RdSpB6rEQLHgC8yqd3c+HMKUE3yyWcL1tHNSFjsZyhW4Os+pG818vzbuCitzGm0BWydPgXHogRsqIt8b70yzBzbKs7OIEuw+P+Vj6f1VnJx/HlZSAjMNO2HulJtKZdWUUY1cjqVwhZ4FaXCRbbeDGhOJ6D54u61UGwm4VYqsyBlWyfnfvukRa3xTy0K+eq7lCGve77sbwFOD9gfow==
Cant pspng set the grouper group uuid to samaccountname and lookup by that?
I don’t think you can move or rename the AD group since grouper is the system of record and specifies the location of the group and could create a new one where it should be and delete the old to get the samaccountname?
Thanks Chris
From: <>
On Behalf Of Black, Carey M.
Jeffrey,
Thank you for the reply.
While I think your workaround would work, I also think that the integration technique of PSPNG should not depend on using the POSIX group id value (or some other “static value” from Grouper) to keep the integration “synced and stable”.
IMHO: PSPNG should automatically bring the AD GUID back and stuff it into a Grouper attribute. (Maybe an attribute specific to the provisioner?) That way the AD group could be moved, renamed, etc… and Grouper would still be able to find it and maintain it. ( including resetting the name/dn, etc…) AND/OR PSPNG should know how to process a “change event” that affects an attribute that is used in the DN or CN attributes of the groupCreationLdifTemplate config value. [ I know which of those solutions I think would be more stable and less prone to user error. :) ]
I just don’t see an option for either of those solutions in the current configs. So PSPNG seems fragile (under some data change conditions that break the matching rules) to me.
All,
Maybe there is a way to include the groups “previous name” into the search conditions? ( But I am just not clear how that could be 100% generically done. Maybe with “alternate name”, but that would only cover some group properties and not all of them. Not to mention attribute value changes….)
Is there any way to get PSPNG to bring attributes back (to Grouper attributes) when it creates the provisioned object?
-- Carey Matthew
From: Jeffrey Williams <>
Also, if this seems to work and stand up to scrutiny, I'll be happy to update the wiki as well.
On Sat, Jul 27, 2019 at 11:21 AM Jeffrey Williams <> wrote:
-- |
- [grouper-users] PSPNG Group rename events...., Black, Carey M., 07/27/2019
- Re: [grouper-users] PSPNG Group rename events...., Jeffrey Williams, 07/27/2019
- Re: [grouper-users] PSPNG Group rename events...., Jeffrey Williams, 07/27/2019
- RE: [grouper-users] PSPNG Group rename events...., Black, Carey M., 07/29/2019
- RE: [grouper-users] PSPNG Group rename events...., Hyzer, Chris, 07/31/2019
- RE: [grouper-users] PSPNG Group rename events...., Black, Carey M., 07/31/2019
- Re: [grouper-users] PSPNG Group rename events...., Jeffrey Williams, 07/31/2019
- RE: [grouper-users] PSPNG Group rename events...., Black, Carey M., 07/31/2019
- RE: [grouper-users] PSPNG Group rename events...., Hyzer, Chris, 07/31/2019
- RE: [grouper-users] PSPNG Group rename events...., Black, Carey M., 07/29/2019
- Re: [grouper-users] PSPNG Group rename events...., Jeffrey Williams, 07/27/2019
- Re: [grouper-users] PSPNG Group rename events...., Jeffrey Williams, 07/27/2019
Archive powered by MHonArc 2.6.19.