Print  
Gray star Gray star Gray star Gray star Gray star --Not rated--
141 Visits    8 Comments
Users not removed when LDAP filters are modified
Created
Daniel Clar Daniel Clar
Mar 9, 2010 3:01 PM
Kablink Component
  • Teaming

I'm using LDAP to authenticate the users.

I've discovered that too many users were imported so I've decided to modify the filters using some LDAP attributes in our directory.

Strange thing none of tem are removed when I execute the synchronization.


Some idea ?

Thanks

Daniel

 

Workflow
Process State Action
Discussion workflow Active
This entry is currently active
Attachments (0)
Entry History
 
Replies
Thumbnail Image
Jong Kim Jong Kim
Mar 9, 2010 4:24 PM
Re: Users not removed when LDAP filters are modified

Did you check the "Delete Users That are not in LDAP" checkbox on the "Configure LDAP Synchronization" admin page?

Thumbnail Image
Daniel Clar Daniel Clar
Mar 9, 2010 4:32 PM
Re : Users not removed when LDAP filters are modified

No because I was afraid that it removes also local users.

The indications on LDAP configurations let me think that they will be removed too.

Am I wrong ?

Thanks,
Daniel

Thumbnail Image
Jong Kim Jong Kim
Mar 10, 2010 1:50 PM
Re: Users not removed when LDAP filters are modified

I'm glad you asked. I think you're right. I just tested it on my machine, and it deleted all my local users except for a few system accounts! So, do not use the option if you want to keep local users.

Personally, this does not feel right to me. I think we should have an option where it can purge LDAP-originated users only, without touching local users.

Thumbnail Image
Daniel Clar Daniel Clar
Mar 10, 2010 2:02 PM
Re : Re: Users not removed when LDAP filters are modified

I agree. I sustain you in this new option.

If you modify something on this page you could perharps aloso modify the filter field to be a multiline field. We have more than 10 conditions and it's not readable.

Thanks.

Daniel

Thumbnail Image
Daniel Clar Daniel Clar
Mar 10, 2010 2:08 PM
Re : Users not removed when LDAP filters are modified

Just to know what happens if we delete the LDAP configuration ?

Are all LDAP users removed ?

It could be a workaround while this option is not present ?

Thanks

Daniel

Thumbnail Image
Daniel Clar Daniel Clar
Mar 10, 2010 2:36 PM
Re : Re : Users not removed when LDAP filters are modified

I have perhaps already an answer : the users won't have the same internal id when they will be imported again so their newly created entries won't be theirs.

Am I right ?

Daniel

 

Thumbnail Image
Jong Kim Jong Kim
Mar 10, 2010 4:09 PM
Re: Re : Users not removed when LDAP filters are modified

Deleting the LDAP configuration does not delete already imported users. Once you delete the configuration, however, you can't use LDAP for authentication (unless you have another LDAP configuration). The same configuration is used for both synchronization and login-time authentication.

Thumbnail Image
Jong Kim Jong Kim
Mar 10, 2010 3:55 PM
Re: Users not removed when LDAP filters are modified

I entered two bug reports.

Bug 587070 - Checking "Delete Users That are not in LDAP" option also purges local users

Bug(enhancement) 587077 - Make the LDAP Filter field to support multiline

Add/Delete Tags
Personal Tags
--none--
Add
Community Tags
--none--
Add
Close
Skip Footer Toolbar