Subject: Grouper Users - Open Discussion List
RE: [grouper-users] PSPNG Provisioned groups in AD
- From: "Black, Carey M." <>
- To: "Weston, Todd" <>, "" <>
- Subject: RE: [grouper-users] PSPNG Provisioned groups in AD
- Date: Wed, 26 Feb 2020 19:26:41 +0000
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=osu.edu; dmarc=pass action=none header.from=osu.edu; dkim=pass header.d=osu.edu; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kgYOzqqpRjIGFtquhxyszSsexjMOnWH9lS7fvkn4GHY=; b=br1CtPsAuJhEH4v4s5wkKJyc/m1L4oHZiioVtH+3uccAe/QE/W8lRnMGx78uXqTuMU9Eo1j80qZmP/3yazvu0RUVJytf369NW22/dgre1FCWKEBWrD9nGOrH58MC1d07ksFsvhy2SsqivHvUi9TIfGkBcapJDqopGdslwDahh70ZuOUTs5VrWjzX2P+kdd5iT/xkoOzPWUxk1r/mAgmk7n69VUzjC7GCClBNKpDNJa4dlLK2uhrlcgbpFrMTo+YSv3Np/u2aesutjIQKlV+6De4eiGISZWC7Q8s0a7mBprCS0xC7sNkRA5QEIcLCbcYXoqHvOsCLFC2th9sikOh1gg==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HuJOiF8dzudceGBVTaLcOboumWv1bhVCVpheRZsUbSCv/TP2E0Jc9wCawHw1ZmOwgG7v2lLmDCZisfqIiRU5jWq18kApdORVGABetsJ9YtuKEuRuDg+Uf+2NdQJp8gfLsA4yrckLZBp3vlN5uMJAhyskJkIiFJ2L6nBYIEiUhb2GyZU1GEgDEKaGqxfrM/6BPnRGrFMvTrrhZFLpKX4gaVYKQfAIddOdkJxWFNjh4Nj21F13K3BPuqr2GJ2eoQy8GYeXjeSW5r3t5pcWJI7qugNAr2HHP+NsnzdIulE+V4Y0Oboho8QiJ3acQad5o9s3YTD+xBdVZ1+Cl4iKUkMcLQ==
RE: Manual modifications
It depends on how you have it configured and when the “full provisioning runs”. When it runs it should correct the memberships (adds and/or removes) to match what is in Grouper.
NOTE: The grouper tooling does not “listen for changes”. Rather the jobs run on a “cron type”(time of day) schedule. So if you only correct the group “once a day” it will be right at least once a day. :)
It is best to help your AD admin know that the groups “in that OU” are not to be manually/directly altered. ( Use Policy instead of Technology. )
Check the grouper-loader.properties: for edu.internet2.middleware.grouper.pspng.FullSyncStarter and when it is scheduled to run.
RE: Large groups
I wonder if you see 1000 (or less) users in the groups in AD?
Maybe you did not configure the connection as “AD” ( …. .isActiveDirectory = true ) and/or if you do not have the paging set up properly on the LDAP connection? (ldap.<yourLDAPname>.pagedResultsSize = 1000 )
Hope that helps.
Oh and “Grouper 2.4.0” is a good ball park. However, there are 12 PSPNG patches that really matter too. So you might check which patch level you are using too.
Start gsh and it will output a line at the top Example: “pspng patches installed: 0, 1, 2, 3, 4,……” ( then enter 5 characters “ :exit ” and then press enter to exit gsh )
On Behalf Of Weston, Todd
I’m new here, so if these have already been covered, please point me in that direction:
I’m an old-school Windows guy, so please don’t assume a lot of Linux context is residing in me…
Grouper 2.4.0, MySQL 5.5
- [grouper-users] PSPNG Provisioned groups in AD, Weston, Todd, 02/26/2020
- RE: [grouper-users] PSPNG Provisioned groups in AD, Black, Carey M., 02/26/2020
- Re: [grouper-users] PSPNG Provisioned groups in AD, Jeffrey Williams, 02/26/2020
Archive powered by MHonArc 2.6.19.