<html><body><div dir="ltr">
<br><br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On 08Apr2022 at 14:29:21, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" type="cite">
<div>
<div>
<blockquote type="cite"> Is this a common requirement?<br></blockquote><br>It's not safe, those names aren't unique. Consider two groups called CN=admin but with different OUs. Obvious problem there in the event if a mistake in configuration somewhere.<br>
</div>
</div>
</blockquote><br>
</div><div class="gmail_quote" dir="ltr">I made exactly that argument to the application admin, and provided a similar example. The claim back is that AD enforces global uniqueness on the CN of groups. An attempt to create just such a competing group with same CN in a different OU was denied with a message that the name already existed (i.e., in another OU). “AD is not, strictly, and LDAP directory.” A little surprising to me, and I wouldn’t want to stake my app’s security on AD always enforcing that uniqueness, but the current behavior of AD seems to insulate users against just this unsound practice. I’ll pull the CN’s only from the OU dedicated to that app in any case.</div><div class="gmail_quote" dir="ltr"><br></div><div class="gmail_quote" dir="ltr">David</div>
</div></body></html>