Uploaded image for project: 'COmanage'
  1. COmanage
  2. CO-1741

Review LdapProvisioner Records On Various Statuses

    XMLWordPrintable

Details

    Description

      When a record is in non-Active status (eg: Suspended) certain attributes remain in the record. The idea is to maintain referential integrity for applications (so identifiers and biodem remain) but remove authorizations (so groups are removed). Currently

      1. eduPersonEntitlement is still populated. This is probably wrong.
      2. inMemberOf for "all" groups (eg: CO:members:all, CO:COU:mycou:members:all) is still populated. This might be "right", given that as far as Registry is concerned the person is still in these groups, but then documentation should be made clear not to rely on these groups for authz.

      Attachments

        Activity

          People

            benn.oshrin@at.internet2.edu Benn Oshrin (internet2.edu)
            benn.oshrin@at.internet2.edu Benn Oshrin (internet2.edu)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: