Re: [p4] groups sync'd from LDAP - membership exceptions

P4Nick <[email protected]> Fri, 20 Apr 2018 08:35:01 -0700
Newsgroups gmane.comp.version-control.perforce
Message-ID <[email protected]>
Posted on behalf of forum user 'P4Nick'.

Hi Miles,

I'm not totally sure I understand what you mean by "designate users
that are not allowed from the LDAP group".

My normal recommendation for mixing LDAP sync'ed groups with additional
users is to use 2 groups and make one a subgroup of the other: this should solve
the users from 2 sources issue.

Excluding particular LDAP users is probably best achieved in the LDAP query, or
in the LDAP server itself depending on the scale of the problem.
If you're excluding half the users in an LDAP group,should there be a
separate LDAP group?
If there's just a couple of specific users you need to exclude, then
modifying the query might be better.

This IBM documentation for LDAP filtering has an example of a similar search
exclusion:
https://www.ibm.com/support/knowledgecenter/en/SSYJ99_8.5.0/admin-system/rbug_ldapfltrxprns.html



--
Please click here to see the post in its original format:
  http://forums.perforce.com/index.php?/topic/5696-groups-syncd-from-ldap-membership-exceptions
_______________________________________________
perforce-user mailing list  -  [email protected]
http://maillist.perforce.com/mailman/listinfo/perforce-user