NCEAS / morpho

Morpho metadata editor
GNU General Public License v2.0
3 stars 1 forks source link

access list does not show all dns in the LTER LDAP tree #909

Closed mbjones closed 6 years ago

mbjones commented 6 years ago

Author Name: Margaret O'Brien (Margaret O'Brien) Original Redmine Issue: 5128, https://projects.ecoinformatics.org/ecoinfo/issues/5128 Original Date: 2010-08-04 Original Assignee: Jing Tao


When adding access rules for individuals, not all the people in the LTER tree are available. It appears that missing folks are the relatively recent additions, eg, since about 2008, but I cannot be sure of that. this might be related to bug 3596.

mbjones commented 6 years ago

Original Redmine Comment Author Name: ben leinfelder (ben leinfelder) Original Date: 2010-08-12T17:16:04Z


see related bug for probable solution on the LTER ldap server: http://bugzilla.ecoinformatics.org/show_bug.cgi?id=3360

mbjones commented 6 years ago

Original Redmine Comment Author Name: Margaret O'Brien (Margaret O'Brien) Original Date: 2010-08-31T00:02:04Z


The LTER network has increased the number of entries its LDAP returns, per Ben's suggestion. However, they had an additional request, which might represent a better long-term solution:

From: http://rt.lternet.edu/Ticket/Display.html?id=13676 I want a IP# or space from which the knb referrals will come as a temporary solution - and I want a metacat to support authenticated queries from LDAP as the real solution. I don't want to keep streaming our records out across the planet to spammers.

mbjones commented 6 years ago

Original Redmine Comment Author Name: ben leinfelder (ben leinfelder) Original Date: 2013-01-17T19:52:28Z


Link the the ticket is dead. We can't really provide a complete list of all the IP addresses that might follow the ldap referral to LTER. Sure, the KNB is one Metacat that utilizes this feature, but so is my laptop where I have a test instance of Metacat.

We are in the process of changing how we do user authentication (to use certificates and InCommon/CILogon) so I think of this as a low priority. Moreover, Morpho 2.0.0 pulls it's users from the CN account listing rather than from the MN so this will not be a Morpho issue for much longer. (We do, however, want Metacat to continue to retrieve the full list of usernames from the LTER referral as we support moth the Metacat and DataONE MN apis during this transition time.)

mbjones commented 6 years ago

Original Redmine Comment Author Name: ben leinfelder (ben leinfelder) Original Date: 2013-01-19T00:13:58Z


This is a symptom of a server-side issue -- defer to that bug.

mbjones commented 6 years ago

Original Redmine Comment Author Name: Redmine Admin (Redmine Admin) Original Date: 2013-03-27T21:29:19Z


Original Bugzilla ID was 5128