On 22/02/2017 16:43, Nigel Jones wrote:

Will raise a JIRA....

I just came across RANGER-1211 ..... this talks about optimizing user sync through an incremental approach.

Can anyone help with a MS AD question

The document implies that the memberOf attribute on a user is *computed*, which would suggest it's ALWAYS possible to EFFICIENTLY retrieve the list of users that are member of a known role (member attribute against the group). Is this indeed the case? Only MD? How about OpenLDAP ?

If so my problem probably goes away.......

Thanks


Reply via email to