cancel
Showing results for 
Search instead for 
Did you mean: 

Does Afaria 7.x support multivalued LDAP attribute based groups ?

Former Member
0 Kudos

Does Afaria 7.x support multivalued LDAP attribute based groups ?

Accepted Solutions (0)

Answers (2)

Answers (2)

keith_nunn
Active Participant
0 Kudos

Karan,

Afaria 7.0 uses the attribute specified on the Server > Configuration > Server \ Security page of the Afaria Administrator when authenticating a user.  A query is made against LDAP for an object that matches the value entered by the end-user as their user name.  Once we've confirmed that the user is proper, that value is stored in the device record in the database as the AssignmentsUserName. 

When user group assignments are handled we query the LDAP server using the AssignmentsUserName and request a list of every group to which that user object is a member.  We then check the Distinguished Name for each group against our list of user group definitions to see if that user is a member.

So an LDAP group based on multi-valued attributes is not likely to have any affect on this process one way or the other.  We're merely comparing the DN of the groups to which the user is a member against the DNs of the LDAP groups stored when the user group was created.  The attributes used to form those groups isn't considered.

Note that Active Directory in SP5 has a different behaviour than LDAP but SP4 and earlier are the same as above.

Hope that helps.  If I misunderstood the question, please clarify and we'll be happy to refine the details you need.

Thanks,

Keith Nunn
SAP Active Global Support

ercin_nurol
Explorer
0 Kudos

Hello Khan,

Can you please give us any example? What do you mean with multi valued? Do you get an error message, and if yes where do you get the error message? Can you please also provide  screenshots? Thank you.

Regards

Ercin Nurol

SAP Active Global Support