Re: [p4] groups sync'd from LDAP - membership exceptions

Matt Janulewicz <[email protected]> Mon, 23 Apr 2018 11:30:01 -0700
Newsgroups gmane.comp.version-control.perforce
Message-ID <[email protected]>
Posted on behalf of forum user 'Matt Janulewicz'.

I'm not sure if this answers your question either, as 'not allowed'
can be interpreted in a few ways. If it means 'not allowed to log in',
then you want to look at the GroupSearchFilter setting on the LDAP
configuration. Setting this to an LDAP group would disallow login by anyone not
in that group. Then, the actual LDAP groups you put in the protections table
won't be affected by any extra users that are not in the GroupSearchFilter
group, they'll just be benign entries of users that can't log in in the
first place.

We're not quite yet switched to LDAP, because reasons, but this is how we
plan on managing the master user list. Adding and deleting users would then be
an LDAP function and we won't have to do that manually within Perforce.
Beyond that we can import any LDAP groups we want and not have to worry about
people in, say, an 'all' group suddenly gaining access to Perforce.



--
Please click here to see the post in its original format:
  http://forums.perforce.com/index.php?/topic/5696-groups-syncd-from-ldap-membership-exceptions
_______________________________________________
perforce-user mailing list  -  [email protected]
http://maillist.perforce.com/mailman/listinfo/perforce-user