Providing ldap group names as an attribute revisited
Cantor, Scott
cantor.2 at osu.edu
Fri Jun 14 13:49:04 EDT 2013
> If I were to change to use memberOf attribute to assign membership on
> the user entries, then would that attribute be somehow protected so that
> users cannot self-assign themselves to groups (like "admin", "superuser"
> etc.).
That is directory specific, most allow attribute-specific authorization rules.
> The approach I have now keeps group membership under the control of the
> group owner and not individual users. This seems more secure.
Then you need two connectors and the rest should be straightforward (as much as anything in LDAP is when you don't know it well, as I do not).
-- Scott
More information about the users
mailing list