#6983 [RFE] Dynamic automember and groups
Closed: fixed 4 years ago by frenaud. Opened 6 years ago by pvoborni.

As administrator I do not want to manually update membership of users based on some attribute, when this attribute changes - e.g. in user-mod operation. Or run a hacky cron-job based solution. I want the user to be automatically added to groups based on automember rules and removed from previous groups if they no longer match automember rules.

The general use-case is:

  • Automember groups are created to match manager, team name, cost center, etc.
  • Application access roles are then tied to the relevant automember groups
  • As people move around internally (which happens a lot), access is automatically updated-- adding and removing users as necessary
  • Group can be marked as managed exclusively by automember inclusions/exclusions

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1438144

6 years ago

Metadata Update from @pvoborni:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1438144

6 years ago

Metadata Update from @pvoborni:
- Issue set to the milestone: FreeIPA 4.8

6 years ago

Fixed upstream in 389-ds component, please see 389-ds ticket 50077. freeipa requires (on master and ipa-4-7 branches) 389-ds >= 1.4.0.21 or 1.4.1.1 (>=fedora 30) which contains the fix.

Metadata Update from @frenaud:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

4 years ago

Metadata Update from @frenaud:
- Issue set to the milestone: FreeIPA 4.7.3 (was: FreeIPA 4.8)

4 years ago

Login to comment on this ticket.

Metadata