Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

LDAP Group under different trees

Our JazzUsers/JazzAdmins group is under a different ldap tree then the JazzGuests group. It appears that the 'base group dn' has to be direct parent, ie: it doesn't do a subtree search. Is there any way to enable a subtree search for groups? It is unlikely that we will be able to change the ldap structure to conform to this apparent restriction.

Example (where we have allEmployees mapped to jazzGuests):

CN=jazzUsers,OU=Applications,OU=Corporate Groups, DC=ad,DC=xxx,DC=com

CN=jazzAdmins,OU=Applications,OU=Corporate Groups, DC=ad,DC=xxx,DC=com

CN=allEmployees,OU=Corporate Groups, DC=ad, DC=xxx,DC=com

Tried settings base group dn to OU=Corporate Groups,... but that fails, I'm assuming because it can't find jazzUsers/jazzAdmins which are deeper under OU=Applications.

0 votes



One answer

Permanent link
jason.kissinger@bsci-dot-com.no-spam.invalid (jasonkissinger) wrote in
news:gp3jkk$d2e$1@localhost.localdomain:

CN=allEmployees,OU=Corporate Groups, DC=ad, DC=xxx,DC=com

Tried settings base group dn to OU=Corporate Groups,... but that
fails, I'm assuming because it can't find jazzUsers/jazzAdmins which
are deeper under OU=Applications.

would BaseDN -> dc=com work if we keep the cn different enough ?
if not, I think this is a good enhancement and you should open a Work Item
:)

--
Christophe Elek
Serviceability Architect
IBM Software Group - Rational

0 votes

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Mar 09 '09, 1:26 p.m.

Question was seen: 4,104 times

Last updated: Mar 09 '09, 1:26 p.m.

Confirmation Cancel Confirm