Release Automation

 View Only
  • 1.  LDAP auto-sync

    Posted Aug 18, 2017 05:00 AM

    Whether LDAP is synched automatically with CA-RA? If i add or remove a user to LDAP, would it reflect in ability to log-in to CA-RA?



  • 2.  Re:  LDAP auto-sync
    Best Answer

    Posted Aug 18, 2017 05:21 AM

    there isn't a sync required as you're directly connecting your CA-RA instance with your LDAP

     

    what you need to do though is set permissions for the users/groups. everyone in the LDAP can log on, but they won't see any application as long as they don't have permissions for them.

     

    but if you're for example using an AD group to handle permissions for an application and later on a new user is added to this ad group, it will work immediately



  • 3.  Re:  LDAP auto-sync

    Broadcom Employee
    Posted Aug 18, 2017 09:52 AM

    Along the lines of what Michael has said... CA Release Automation doesn't specifically record anything in our database regarding that ldap user except: if it gets a request from an imported user then use <security context> to authenticate the user in ldap. If a user is imported from ldap and later delete that user id from ldap then you will need to remove it manually from CA Release Automation. The user will not be able to login into CA Release Automation because the <security context> for that user would no longer be valid and the ldap search would return an Object Not Found. So deleting the user id from CA Release Automation is optional but just good maintenance practice. 

     

    If you're using imported ldap groups and a user that used to be part of that group is deleted from ldap then there is nothing more to do in CA Release Automation. 

     

    Kind regards,

    Gregg