All work

Select view

Select search mode

 

LDAP does not replace functionality of /etc/opennms/groups.xml

Description

When switching to LDAP authentication, even after you get it working, you still need to edit the file /etc/opennms/groups.xml by hand to put users into groups.

The LDAP users don't show up on "Admin / Users and Groups / Group List / Modify Group" under the list of "Available Users" so there is no way to assign the LDAP users into groups from there.

Ideally, the whole /etc/opennms/groups.xml file would be replaced by an LDAP query, but if that's too difficult at least make it easy to assign the users.

Environment

Ubuntu linux, with Sun JDK

Acceptance / Success Criteria

None

Lucidchart Diagrams

Details

Assignee

Reporter

Original estimate

Time tracking

No time logged5h remaining

Components

Affects versions

Priority

PagerDuty

Created September 27, 2011 at 10:59 PM
Updated July 26, 2023 at 2:19 PM

Activity

CarterNovember 14, 2013 at 12:31 PM

I would like to see this implemented also.

Ideally we would like to use LDAP logins to define the nodes the different operations teams/RACs (Regional Action Centers)/NOCs and engineering departments see based off their LDAP groups.

Eg. LDAP group "Server Operations" see nodes categorized as "server", LDAP group "Networks Operations" see devices categorized as "Network", Video-On-Demand engineering teams sees their VOD servers while Video Operations see all "video" and "satellite" devices etc.

Jeff GehlbachNovember 14, 2013 at 12:06 PM

This would be a great enhancement, though I would scope it even a bit larger to include pulling e-mail addresses and other contact info from the directory.