<div dir="ltr"><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverScriptAttributeDefinitionExamples">https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverScriptAttributeDefinitionExamples</a><br><div><br></div><div>David Bantz</div><div>U Alaska</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Aug 24, 2017 at 11:05 AM, Wessel, Keith <span dir="ltr"><<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi, all,<br>
<br>
We've recently started receiving more requests to be able to not only expose our users' direct group memberships in AD groups through attributes in our IdP, but also indirect group memberships.<br>
<br>
I've so far resisted, not having the time to write a custom data connector that would query tokenGroups, decode each SID returned, then query each decoded SID to retrieven the group's DN. It's not a lot of work, but it hasn't been a priority.<br>
<br>
Does anyone have a data connector they've written to do this that they might want to contribute to the community? Or other suggestions on how to do this? I've considered Grouper's data connector, but since we don't ever plan to have all AD groups in Grouper, that won't be a complete list.<br>
<br>
Thanks,<br>
Keith<br>
<span class="HOEnZb"><font color="#888888"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>