Print  
Gray star Gray star Gray star Gray star Gray star --Not rated--
219 Visits 8 Comments
Created
Daniel Clar Daniel Clar
Kablink Component
  • Teaming

I'm using LDAP to authenticate the users.

I've discovered that too many users were imported so I've decided to modify the filters using some LDAP attributes in our directory.

Strange thing none of tem are removed when I execute the synchronization.


Some idea ?

Thanks

Daniel

 

Workflow
Process State Action
Discussion workflow Active
This entry is currently active
Attachments(0)
Entry History
Tags
 
Replies
Thumbnail Image
Jong Kim Jong Kim

Did you check the "Delete Users That are not in LDAP" checkbox on the "Configure LDAP Synchronization" admin page?

Thumbnail Image
Daniel Clar Daniel Clar

No because I was afraid that it removes also local users.

The indications on LDAP configurations let me think that they will be removed too.

Am I wrong ?

Thanks,
Daniel

Thumbnail Image
Jong Kim Jong Kim

I'm glad you asked. I think you're right. I just tested it on my machine, and it deleted all my local users except for a few system accounts! So, do not use the option if you want to keep local users.

Personally, this does not feel right to me. I think we should have an option where it can purge LDAP-originated users only, without touching local users.

Thumbnail Image
Daniel Clar Daniel Clar

I agree. I sustain you in this new option.

If you modify something on this page you could perharps aloso modify the filter field to be a multiline field. We have more than 10 conditions and it's not readable.

Thanks.

Daniel

Thumbnail Image
Daniel Clar Daniel Clar

Just to know what happens if we delete the LDAP configuration ?

Are all LDAP users removed ?

It could be a workaround while this option is not present ?

Thanks

Daniel

Thumbnail Image
Daniel Clar Daniel Clar

I have perhaps already an answer : the users won't have the same internal id when they will be imported again so their newly created entries won't be theirs.

Am I right ?

Daniel

 

Thumbnail Image
Jong Kim Jong Kim

Deleting the LDAP configuration does not delete already imported users. Once you delete the configuration, however, you can't use LDAP for authentication (unless you have another LDAP configuration). The same configuration is used for both synchronization and login-time authentication.

Thumbnail Image
Jong Kim Jong Kim

I entered two bug reports.

Bug 587070 - Checking "Delete Users That are not in LDAP" option also purges local users

Bug(enhancement) 587077 - Make the LDAP Filter field to support multiline

Skip Footer Toolbar