Providing ldap group names as an attribute revisited

Cantor, Scott cantor.2 at osu.edu
Fri Jun 14 13:49:04 EDT 2013


> If I were to change to use memberOf attribute to assign membership on
> the user entries, then would that attribute be somehow protected so that
> users cannot self-assign themselves to groups (like "admin", "superuser"
> etc.).

That is directory specific, most allow attribute-specific authorization rules.

> The approach I have now keeps group membership under the control of the
> group owner and not individual users. This seems more secure.

Then you need two connectors and the rest should be straightforward (as much as anything in LDAP is when you don't know it well, as I do not).

-- Scott




More information about the users mailing list