[p4] LDAP group sync questions
roadkills_r_us <[email protected]>
| Newsgroups | gmane.comp.version-control.perforce |
|---|---|
| Message-ID | <[email protected]> |
Posted on behalf of forum user 'roadkills_r_us'.
We are starting to sync our Helix groups to AD. We've been using AD
authentication with Helix for a couple of years.
- Is there a way to have a group sync against whatever servers are already
config'd? We have multiple AD servers configured, ordered nearest to
furthest. This makes sure authentications work so long as one server is up.
But group sync requires us to designate a single AD server per group. While
this is probably OK, this requires redundant configuration and is less robust.
Groups will be syncing far more frequently than users will be authenticating.
- The LdapSearchQuery that finally worked for us is:
(&(objectClass=user)(sAMAccountName=*)(memberof=CN=GROUPNAME,OU=klaatu,OU=groups,DC=barada,DC=nikto,DC=com))
At least for the forseeable future, the Helix and AD group names will be
identical. Is there a variable we can plug in for GROUPNAME (not its real
name)?
Thanks!
--
Please click here to see the post in its original format:
http://forums.perforce.com/index.php?/topic/5491-ldap-group-sync-questions
_______________________________________________
perforce-user mailing list - [email protected]
http://maillist.perforce.com/mailman/listinfo/perforce-user