> What's your ldap server software (just by curiosity) ?

OpenLDAP

> Do you think this method
> http://www.openldap.org/doc/admin23/overlays.html#Reverse%20Group%20Membership%20Maintenance
>
> Could do the trick ? Please, say yes :-)

That looks ideal to me.  I consulted with our OpenLDAP admin for a
second opinion, and he agreed.  We make heavy use of overlays to
simplify certain requirements, so I'm comfortable recommending a
solution like the above.

>> It's my opinion that yours is a use case that should be supported by
>> CAS out of the box and it's something that I hope we will pursue in a
>> future release of CAS.  I encourage you to open a Jira improvement
>> issue for your use case to put it on the development roadmap.
>>
>
> Hmm it depends if you think it's a lack of the user storage or a lack of cas
> server...

It's a limitation of CAS.  I think it's perfectly reasonable to search
a different branch for attributes, where it would be expected to
produce multiple search results.  I believe the single result
restriction is to prevent a search that produces multiple results when
querying for a principal, which could be a security concern if you
just grabbed the first one that might not necessarily be the "right"
one.  While that consideration is important, it shouldn't preclude a
use case like yours where multiple results are not only expected but
required.

I do hope you'll open the Jira issue and post the issue number to this thread.

M

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to