Grouper Call of August 3, 2022 

Attending 

  • Chris Hyzer, Penn, Chair
  •  Shilen Patel, Duke
  • JJ, Unicon
  • Carey Matt Black, Purdue
  • Drew Aschenbrener, Internet2
  • Emily Eisbruch, Internet2

DISCUSSION

 Administrivia

MIsc items


Plan for next Grouper release

  • Users being able to see provisioning
  • Hierarchies for groups and entities

  • Debug object logs, currently people can’t check
  • Chris added another column to grouper loader log

Work Items

Vivek

  • Azure and google provisioning
  • Grouper Entra ID Provisioner (Current) Azure O365
  • Grouper Google GCP provisioner
  • Leveraged work from NYU
  • Concept of priv list on a group for admins or managers
  •    At first only full sync
  •     Ideally list column in sync membership table
  •  Users being able to see provisioning config and make assignments 
  • Also ability  to view provisioning config, but not able to assign   
  • If a person has View-only priv for a group, that person should not be able to make the group provisionable.
  • If you are a provisioning admin, you should only have access to the groups you can read?
  • Azure and LDAP are  different cases, 
  • AI Vivek make JIRA for another priv on provisioning, Read, Assign, Admin, Manage  
  • Right now only sys admins can do re calcs

  • Diagnostics, making it simpler


Shilen

  • Subject change daemon, real time USDU
  • https://spaces.at.internet2.edu/x/DgAPDg
  •  
  • It issues entity recalcs, not working properly, Chris is looking at that
  •   JIRA for recalc issue GRP-4251 entity recalc by message not working
  • Issues found at University of Michigan, primary issue is resolved 
  • Web services not compiling. CI tests also failing, 
  •       AI Chris will help fix this web services no compiling
  • Want to Upgrade hibernate, but some needed functionality was removed 
  • Would eventually like to remove hibernate altogether
  • Could be a task for Shilen
  • Go to Hibernate 6? NO, has Java dependency
  • Want to remove vulnerabilities in 3rd party jars
  • Should we roll back into Grouper 2.5? To be decided
  • Some ability to view what groups you are in and respect privacy of other members
  •  Drew had reasonable proposal
  • There are cases where you don’t want someone to know they are a group
  • What about trace membership?
  • Want to have ability to show to a subject groups they are in without showing then other members of the group
  • Shilen will implement Drew’s suggestion
  • Keep Drew posted on how this develops

Chris

  • See Jiras 


JJ 

  • working with U Wisconsin on provisioning.
  • Updating to Grouper 2.6 will solve some of their issues
  • For Another client,  not  U Wisc: 
    •  AI Chris will look at issue JJ reported : LDAP provisioner , running thru “starts with”, name is flat reverse, name limit 64,   the config it fails, because LDAP DN is not being generated.  The CN is translated properly, but DN comes back as null. 


Issue Roundup 


Jiras in past two weeks




Grouper Emails in past two weeks

      none


Grouper wiki updates in past two weeks


Next Grouper Call : Wed. Aug 17, 2022 

  • No labels