Child pages
  • Grouper Call 16-Dec-2015
Skip to end of metadata
Go to start of metadata

 

Notes: Grouper Call of  Dec 16, 2015

Attending: Chris, Shilen, Misagh, Emily,


New Action Items


[AI]  (All) on the Grouper-core team should review the proposed questions on the TIER Packaging survey


[AI] (Shilen) create a wiki documenting the Loader work


[AI] Chris will work on Security Configuration issue


[AI} (Emily) will tell Dean we’d like Grouper IAM Online in  July 2016


[AI] ( Emily ) submit request for a Grouper BOF at Global Summit


Action Items

 

[AI] (Jim)  Draft a more detailed process for security concern handling  - in progress

 

 [AI] (Jim) handle taking info on security advisories from the Shib wiki for the Grouper wiki  https://spaces.internet2.edu/display/Grouper/Grouper+Security+Issues

 

[AI] (Bert) follow up on bulk sync email.  

 

[AI] (Emily) Schedule IAM Online webinar on Grouper for June 2016 or later    - Emily will tell Dean we’d like Grouper IAM Online in   July 2016


DISCUSSION

 Current work tasks

 

Chris: Messaging changelog consumer

 

  https://spaces.internet2.edu/display/Grouper/Grouper+messaging+built+in


Shilen: Loader

 

was working on Quartz change,

 

needs to test that on various databases

 

Some of Grouper Misc projects need to be updated


[AI] (Shilen) create a wiki documenting the Loader work


Shilen updated Grouper to use latest hibernate but there are a few issues to work through.  Need to check if there are caching changes, exceptions when evicting, and some other api changes.


Bert: PSPNG - no report on this call

 

·

 

Misagh: Building and packaging

Misagh has most Grouper projects converted to Gradle. Some don’t want to compile yet.

 

Hope to wrap up by Friday Dec. 18


Everything (proof of concept) will go into  a Gradle branch.  

 

Misagh will let people know and ask for testing


looking at scripting logic in Gradle.  


Q: will we want to get rid of all Ant?

 

A: keep some Ant tasks where needed and have Gradle call those Ant tasks.


Q: what about making tarballs?

 

A: Gradle does that easily


1.       https://spaces.internet2.edu/pages/viewpage.action?pageId=87755940

 

·         Vivek: WS

 

 

 

TIER update


TIER Packaging WG has focused on Shib more than on Grouper.

 

Chris: they did discuss Grouper on one recent call

 

link is https://docs.google.com/document/d/1_jfdZpzCLxV2WTgCjMY3FZMuGGV67QvkLzkEtwLayGM/edit#

 

 

 

There will be a TIER survey of people who do not have Grouper and people who do.

 

[AI]  (All) on the Grouper-core team should review the proposed questions on the TIER Packaging survey



Security vulnerability submissions

 

            a. test the jira security


[AI] Chris will work on Security Configuration issue


            b. someone (not chris or shilen), create a secure test issue

 

            c. make sure no one can see the issue except submitter, chris, shilen

 

            d. chris (and shilen?) should get notified

 

e. chris or shilen update issue

 

f. make sure still no one else can see except submitter, chris, shilen

 

5. Discuss client and installer one jar - the client currently has an exploded version of a number of JARs. We are looking into using an uber/fat jar to take advantage of dependency management. This behavior depends on the how classloader functions, and it may be container specific (tomcat, etc) so we might not use this for now, and simply keep updating the inner jars.

 

maven shade plugin creates uber jar as an example

 

depends on container classloader, which is a showstopper since grouper doesnt always run in container

 

chris can upgrade the packages in client and installer as needed no problem

 

 

 

 Issue roundup

 

·         Iam online  will be scheduled for  July 2016

 

·         Encrypt and externalize passwords wiki

 

·         UTF-8, mysql, and connect string param

 

·         2.2.2 and legacy attributes

 

·         Permissions performance, test data, API changes - Shilen working on it

 

·         Subject problem patch (no response?)

 

·         Confluence chrome

 

·         One membership per folder

 

·         Member change subject runtime exception - Chris made  patch

 

·         “list” api methods (isStemListField())

 

·         Setting title in UI

 

·         Valid Grouper version (patch)

 

·         Tomcat 8 CSRF

 

·         useInClause… in sources.xml (master)

 

·         export partial registry

 

·         authn, shib, remote_user

 

·         findStems web service documentation issues

 

·         SIGSEGV on loader

 

·         Grouper BOF at Internet2 Global Summit in Chicago, May 15-18, 2016 ?

 

[AI] ( Emily ) submit request for a Grouper BOF at Global Summit


·         PSP ldap connection issues 2.1.5

 

·         PSP bulksync issues

 

 

 

 

 

No Grouper Call on Wed. Dec. 30.

 

Happy Holidays, Happy New Year!


Next Grouper call - Wed. Jan 13, 2016

 

 

 


 


 


 

  • No labels