[Geoserver-devel] proposal: LDAP UserGroupService

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144--

Basically: There is no LDAP UserGroupService yet. Some people might want one. For example, to use the integrated geofence with ldap, because the integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels

Added my +1

Cheers

···

On Mon, May 2, 2016 at 10:46 AM, Niels Charlier <niels@anonymised.com> wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144–

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@anonymised.comsts.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

+1

The proposal is not _tremendously_ detailed but I think this is a
feature that is needed.
If you can just elaborate a little on the proposal itself that would be great.

As an instance, do you intend to put same caching in between GS and
LDAP to avoid LDAP sloweness slowing down request serving?

Regards,
Simone Giannecchini

GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Simone Giannecchini
@simogeo
Founder/Director

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 333 8128928

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

-------------------------------------------------------
AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate.
Il loro utilizzo è consentito esclusivamente al destinatario del
messaggio, per le finalità indicate nel messaggio stesso. Qualora
riceviate questo messaggio senza esserne il destinatario, Vi preghiamo
cortesemente di darcene notizia via e-mail e di procedere alla
distruzione del messaggio stesso, cancellandolo dal Vostro sistema.
Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal
D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely
for the attention and use of the named addressee(s) and may be
confidential or proprietary in nature or covered by the provisions of
privacy act (Legislative Decree June, 30 2003, no.196 - Italy's New
Data Protection Code).Any use not in accord with its purpose, any
disclosure, reproduction, copying, distribution, or either
dissemination, either whole or partial, is strictly forbidden except
previous formal approval of the named addressee(s). If you are not the
intended recipient, please contact immediately the sender by
telephone, fax or e-mail and delete the information in this message
that has been received in error. The sender does not give any warranty
or accept liability as the content, accuracy or completeness of sent
messages and accepts no responsibility for changes made after they
were sent or for other risks which arise as a result of e-mail
transmission, viruses, etc.

On Mon, May 2, 2016 at 12:20 PM, Christian Mueller
<christian.mueller@anonymised.com> wrote:

Added my +1

Cheers

On Mon, May 2, 2016 at 10:46 AM, Niels Charlier <niels@anonymised.com> wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144--

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications
Manager
Applications Manager provides deep performance insights into multiple
tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

--
DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers
of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Hi,

I tried the link below and it wound up on a "Create new wiki" page. Removing the -- at the end resulted in
https://github.com/geoserver/geoserver/wiki/GSIP-144

This page did open.

Chris Snider
Senior Software Engineer
Intelligent Software Solutions, Inc.

-----Original Message-----
From: Niels Charlier [mailto:niels@anonymised.com]
Sent: Monday, May 02, 2016 2:46 AM
To: Geoserver-devel <geoserver-devel@lists.sourceforge.net>
Subject: [Geoserver-devel] proposal: LDAP UserGroupService

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144--

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Hi

@Simone, GeoServer uses caching already. Its the same as if you are using a user group store based on JDBC. No need to implement a special LDAP cache for serving requests.

Cheers

···

On Mon, May 2, 2016 at 4:53 PM, Chris Snider <chris.snider@anonymised.com> wrote:

Hi,

I tried the link below and it wound up on a “Create new wiki” page. Removing the – at the end resulted in
https://github.com/geoserver/geoserver/wiki/GSIP-144

This page did open.

Chris Snider
Senior Software Engineer
Intelligent Software Solutions, Inc.

-----Original Message-----
From: Niels Charlier [mailto:niels@anonymised.com918…]
Sent: Monday, May 02, 2016 2:46 AM
To: Geoserver-devel <geoserver-devel@lists.sourceforge.net>
Subject: [Geoserver-devel] proposal: LDAP UserGroupService

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144–

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@anonymised.comsts.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@anonymised.comsts.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

Ciao Christian,
I did not know that :slight_smile:

Regards,
Simone Giannecchini

GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Simone Giannecchini
@simogeo
Founder/Director

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 333 8128928

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

-------------------------------------------------------
AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate.
Il loro utilizzo è consentito esclusivamente al destinatario del
messaggio, per le finalità indicate nel messaggio stesso. Qualora
riceviate questo messaggio senza esserne il destinatario, Vi preghiamo
cortesemente di darcene notizia via e-mail e di procedere alla
distruzione del messaggio stesso, cancellandolo dal Vostro sistema.
Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal
D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely
for the attention and use of the named addressee(s) and may be
confidential or proprietary in nature or covered by the provisions of
privacy act (Legislative Decree June, 30 2003, no.196 - Italy's New
Data Protection Code).Any use not in accord with its purpose, any
disclosure, reproduction, copying, distribution, or either
dissemination, either whole or partial, is strictly forbidden except
previous formal approval of the named addressee(s). If you are not the
intended recipient, please contact immediately the sender by
telephone, fax or e-mail and delete the information in this message
that has been received in error. The sender does not give any warranty
or accept liability as the content, accuracy or completeness of sent
messages and accepts no responsibility for changes made after they
were sent or for other risks which arise as a result of e-mail
transmission, viruses, etc.

On Mon, May 2, 2016 at 5:29 PM, Christian Mueller
<christian.mueller@anonymised.com> wrote:

Hi

@Simone, GeoServer uses caching already. Its the same as if you are using a
user group store based on JDBC. No need to implement a special LDAP cache
for serving requests.

Cheers

On Mon, May 2, 2016 at 4:53 PM, Chris Snider <chris.snider@anonymised.com>
wrote:

Hi,

I tried the link below and it wound up on a "Create new wiki" page.
Removing the -- at the end resulted in
https://github.com/geoserver/geoserver/wiki/GSIP-144

This page did open.

Chris Snider
Senior Software Engineer
Intelligent Software Solutions, Inc.

-----Original Message-----
From: Niels Charlier [mailto:niels@anonymised.com]
Sent: Monday, May 02, 2016 2:46 AM
To: Geoserver-devel <geoserver-devel@lists.sourceforge.net>
Subject: [Geoserver-devel] proposal: LDAP UserGroupService

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144--

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications
Manager
Applications Manager provides deep performance insights into multiple
tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications
Manager
Applications Manager provides deep performance insights into multiple
tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

--
DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers
of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Thanks, Simone.

Extra information:
It would be implemented in an analogue way to the RoleService. The different method implementations would execute LDAP search queries to retrieve the requested user information and translate the data to user/group objects. Configuration would also be similar to the RoleService and AuthenticationService but slightly more extended: users could choose between providing filters for retrieving all/specific users/groups or simply provide the necessary attribute names (where the filters are automatically created).

Regards
Niels

On 02-05-16 16:50, Simone Giannecchini wrote:

+1

The proposal is not _tremendously_ detailed but I think this is a
feature that is needed.
If you can just elaborate a little on the proposal itself that would be great.

As an instance, do you intend to put same caching in between GS and
LDAP to avoid LDAP sloweness slowing down request serving?

Regards,
Simone Giannecchini

GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Simone Giannecchini
@simogeo
Founder/Director

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 333 8128928

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

-------------------------------------------------------
AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate.
Il loro utilizzo è consentito esclusivamente al destinatario del
messaggio, per le finalità indicate nel messaggio stesso. Qualora
riceviate questo messaggio senza esserne il destinatario, Vi preghiamo
cortesemente di darcene notizia via e-mail e di procedere alla
distruzione del messaggio stesso, cancellandolo dal Vostro sistema.
Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal
D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely
for the attention and use of the named addressee(s) and may be
confidential or proprietary in nature or covered by the provisions of
privacy act (Legislative Decree June, 30 2003, no.196 - Italy's New
Data Protection Code).Any use not in accord with its purpose, any
disclosure, reproduction, copying, distribution, or either
dissemination, either whole or partial, is strictly forbidden except
previous formal approval of the named addressee(s). If you are not the
intended recipient, please contact immediately the sender by
telephone, fax or e-mail and delete the information in this message
that has been received in error. The sender does not give any warranty
or accept liability as the content, accuracy or completeness of sent
messages and accepts no responsibility for changes made after they
were sent or for other risks which arise as a result of e-mail
transmission, viruses, etc.

On Mon, May 2, 2016 at 12:20 PM, Christian Mueller
<christian.mueller@anonymised.com> wrote:

Added my +1

Cheers

On Mon, May 2, 2016 at 10:46 AM, Niels Charlier <niels@anonymised.com> wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144--

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications
Manager
Applications Manager provides deep performance insights into multiple
tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

--
DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers
of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Hi Niels

The jdbc implementation uses a propterty file for all sql statements

./main/resources/org/geoserver/security/jdbc/usersdml.xml

Do you plan something similar to the ldap implementation.

The nice thing is that users can adjust the queries to their environment.

Cheers

···

On Mon, May 2, 2016 at 6:08 PM, Niels Charlier <niels@anonymised.com> wrote:

Thanks, Simone.

Extra information:
It would be implemented in an analogue way to the RoleService. The different method implementations would execute LDAP search queries to retrieve the requested user information and translate the data to user/group objects. Configuration would also be similar to the RoleService and AuthenticationService but slightly more extended: users could choose between providing filters for retrieving all/specific users/groups or simply provide the necessary attribute names (where the filters are automatically created).

Regards
Niels

On 02-05-16 16:50, Simone Giannecchini wrote:

+1

The proposal is not tremendously detailed but I think this is a
feature that is needed.
If you can just elaborate a little on the proposal itself that would be great.

As an instance, do you intend to put same caching in between GS and
LDAP to avoid LDAP sloweness slowing down request serving?

Regards,
Simone Giannecchini

GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Simone Giannecchini
@simogeo
Founder/Director

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 333 8128928

http://www.geo-solutions.it
http://twitter.com/geosolutions_it


AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate.
Il loro utilizzo è consentito esclusivamente al destinatario del
messaggio, per le finalità indicate nel messaggio stesso. Qualora
riceviate questo messaggio senza esserne il destinatario, Vi preghiamo
cortesemente di darcene notizia via e-mail e di procedere alla
distruzione del messaggio stesso, cancellandolo dal Vostro sistema.
Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal
D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely
for the attention and use of the named addressee(s) and may be
confidential or proprietary in nature or covered by the provisions of
privacy act (Legislative Decree June, 30 2003, no.196 - Italy’s New
Data Protection Code).Any use not in accord with its purpose, any
disclosure, reproduction, copying, distribution, or either
dissemination, either whole or partial, is strictly forbidden except
previous formal approval of the named addressee(s). If you are not the
intended recipient, please contact immediately the sender by
telephone, fax or e-mail and delete the information in this message
that has been received in error. The sender does not give any warranty
or accept liability as the content, accuracy or completeness of sent
messages and accepts no responsibility for changes made after they
were sent or for other risks which arise as a result of e-mail
transmission, viruses, etc.

On Mon, May 2, 2016 at 12:20 PM, Christian Mueller
<christian.mueller@anonymised.com> wrote:

Added my +1

Cheers

On Mon, May 2, 2016 at 10:46 AM, Niels Charlier <niels@anonymised.com> wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144–

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels


Find and fix application performance issues faster with Applications
Manager
Applications Manager provides deep performance insights into multiple
tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel


DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers
of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

Hello Christian,

The appropriate queries will all be configurable, yes.

Regards
Niels

···

On 05/03/2016 06:30 AM, Christian Mueller wrote:

Hi Niels

The jdbc implementation uses a propterty file for all sql statements

./main/resources/org/geoserver/security/jdbc/usersdml.xml

Do you plan something similar to the ldap implementation.

The nice thing is that users can adjust the queries to their environment.

Cheers

On Mon, May 2, 2016 at 6:08 PM, Niels Charlier <niels@anonymised.com> wrote:

Thanks, Simone.

Extra information:
It would be implemented in an analogue way to the RoleService. The different method implementations would execute LDAP search queries to retrieve the requested user information and translate the data to user/group objects. Configuration would also be similar to the RoleService and AuthenticationService but slightly more extended: users could choose between providing filters for retrieving all/specific users/groups or simply provide the necessary attribute names (where the filters are automatically created).

Regards
Niels

On 02-05-16 16:50, Simone Giannecchini wrote:

+1

The proposal is not tremendously detailed but I think this is a
feature that is needed.
If you can just elaborate a little on the proposal itself that would be great.

As an instance, do you intend to put same caching in between GS and
LDAP to avoid LDAP sloweness slowing down request serving?

Regards,
Simone Giannecchini

GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Simone Giannecchini
@simogeo
Founder/Director

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 333 8128928

http://www.geo-solutions.it
http://twitter.com/geosolutions_it


AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate.
Il loro utilizzo è consentito esclusivamente al destinatario del
messaggio, per le finalità indicate nel messaggio stesso. Qualora
riceviate questo messaggio senza esserne il destinatario, Vi preghiamo
cortesemente di darcene notizia via e-mail e di procedere alla
distruzione del messaggio stesso, cancellandolo dal Vostro sistema.
Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal
D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely
for the attention and use of the named addressee(s) and may be
confidential or proprietary in nature or covered by the provisions of
privacy act (Legislative Decree June, 30 2003, no.196 - Italy’s New
Data Protection Code).Any use not in accord with its purpose, any
disclosure, reproduction, copying, distribution, or either
dissemination, either whole or partial, is strictly forbidden except
previous formal approval of the named addressee(s). If you are not the
intended recipient, please contact immediately the sender by
telephone, fax or e-mail and delete the information in this message
that has been received in error. The sender does not give any warranty
or accept liability as the content, accuracy or completeness of sent
messages and accepts no responsibility for changes made after they
were sent or for other risks which arise as a result of e-mail
transmission, viruses, etc.

On Mon, May 2, 2016 at 12:20 PM, Christian Mueller
<christian.mueller@anonymised.com> wrote:

Added my +1

Cheers

On Mon, May 2, 2016 at 10:46 AM, Niels Charlier <niels@anonymised.com> wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144–

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels


Find and fix application performance issues faster with Applications
Manager
Applications Manager provides deep performance insights into multiple
tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel


DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers
of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

DI Christian Mueller MSc (GIS), MSc (IT-Security)
OSS Open Source Solutions GmbH

Hi Niels,
from a quick read:

  • Is it really targeted to 2.11, and not to 2.10? :slight_smile: Are you considering a backport to 2.9?
  • You are making a proposal for it, so it’s going to be part of core, with the UI in web/security/ldap? (no problems with it, but the proposal should say so)
  • The configurable portions should be mentioned in the proposal (your answer to Christian)

How about longer term maintainership? Core stuff is officially maintained by the PSC, so do you expect
to drop off after the proposal and have the PSC handle community fixes and bug reports?

Cheers
Andrea

···

On Mon, May 2, 2016 at 10:46 AM, Niels Charlier <niels@…2918…> wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144–

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@anonymised.comsts.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

==
GeoServer Professional Services from the experts! Visit
http://goo.gl/it488V for more information.

Ing. Andrea Aime

@geowolf
Technical Lead

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
phone: +39 0584 962313

fax: +39 0584 1660272
mob: +39 339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

AVVERTENZE AI SENSI DEL D.Lgs. 196/2003

Le informazioni contenute in questo messaggio di posta elettronica e/o nel/i file/s allegato/i sono da considerarsi strettamente riservate. Il loro utilizzo è consentito esclusivamente al destinatario del messaggio, per le finalità indicate nel messaggio stesso. Qualora riceviate questo messaggio senza esserne il destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro sistema. Conservare il messaggio stesso, divulgarlo anche in parte, distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità diverse, costituisce comportamento contrario ai principi dettati dal D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely for the attention and use of the named addressee(s) and may be confidential or proprietary in nature or covered by the provisions of privacy act (Legislative Decree June, 30 2003, no.196 - Italy’s New Data Protection Code).Any use not in accord with its purpose, any disclosure, reproduction, copying, distribution, or either dissemination, either whole or partial, is strictly forbidden except previous formal approval of the named addressee(s). If you are not the intended recipient, please contact immediately the sender by telephone, fax or e-mail and delete the information in this message that has been received in error. The sender does not give any warranty or accept liability as the content, accuracy or completeness of sent messages and accepts no responsibility for changes made after they were sent or for other risks which arise as a result of e-mail transmission, viruses, etc.


Andrea,

Answers inline.

On 03-05-16 09:52, Andrea Aime wrote:

- Is it really targeted to 2.11, and not to 2.10? :slight_smile:

Fixed

Are you considering a backport to 2.9?

This is not necessary for me.

- You are making a proposal for it, so it's going to be part of core, with the UI in web/security/ldap? (no problems with it, but the proposal should say so)

Done

- The configurable portions should be mentioned in the proposal (your answer to Christian)

I had already added that.

How about longer term maintainership? Core stuff is officially maintained by the PSC, so do you expect
to drop off after the proposal and have the PSC handle community fixes and bug reports?

The implementation is very much in line with / integrated with the rest of the sec-ldap module. I know it quite well now and I am willing to assist with supporting the module in the longer term. Only recently I tested it thoroughly with openldap after the spring upgrade.

Kind Regards
Niels

Can I get a couple more +1 :slight_smile:

On 03-05-16 10:14, Niels Charlier wrote:

Andrea,

Answers inline.

On 03-05-16 09:52, Andrea Aime wrote:

- Is it really targeted to 2.11, and not to 2.10? :slight_smile:

Fixed

Are you considering a backport to 2.9?

This is not necessary for me.

- You are making a proposal for it, so it's going to be part of core,
with the UI in web/security/ldap? (no problems with it, but the
proposal should say so)

Done

- The configurable portions should be mentioned in the proposal (your
answer to Christian)

I had already added that.

How about longer term maintainership? Core stuff is officially
maintained by the PSC, so do you expect
to drop off after the proposal and have the PSC handle community fixes
and bug reports?

The implementation is very much in line with / integrated with the rest
of the sec-ldap module. I know it quite well now and I am willing to
assist with supporting the module in the longer term. Only recently I
tested it thoroughly with openldap after the spring upgrade.

Kind Regards
Niels

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Sorry for the delay … very busy days :frowning:

I’m interested on this proposal, here is my +1

···

On Thu, May 5, 2016 at 10:00 AM, Niels Charlier <niels@anonymised.com> wrote:

Can I get a couple more +1 :slight_smile:

On 03-05-16 10:14, Niels Charlier wrote:

Andrea,

Answers inline.

On 03-05-16 09:52, Andrea Aime wrote:

  • Is it really targeted to 2.11, and not to 2.10? :slight_smile:
    Fixed
    Are you considering a backport to 2.9?
    This is not necessary for me.
  • You are making a proposal for it, so it’s going to be part of core,
    with the UI in web/security/ldap? (no problems with it, but the
    proposal should say so)
    Done
  • The configurable portions should be mentioned in the proposal (your
    answer to Christian)
    I had already added that.
    How about longer term maintainership? Core stuff is officially
    maintained by the PSC, so do you expect
    to drop off after the proposal and have the PSC handle community fixes
    and bug reports?
    The implementation is very much in line with / integrated with the rest
    of the sec-ldap module. I know it quite well now and I am willing to
    assist with supporting the module in the longer term. Only recently I
    tested it thoroughly with openldap after the spring upgrade.

Kind Regards
Niels


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@anonymised.comsts.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Best Regards,
Alessio Fabiani.

==
GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Alessio Fabiani
@alfa7691
Founder/Technical Lead

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 331 6233686

http://www.geo-solutions.it
http://twitter.com/geosolutions_it


AVVERTENZE AI SENSI DEL D.Lgs. 196/2003

Le informazioni contenute in questo messaggio di posta elettronica e/o nel/i file/s allegato/i sono da considerarsi strettamente riservate. Il loro utilizzo è consentito esclusivamente al destinatario del messaggio, per le finalità indicate nel messaggio stesso. Qualora riceviate questo messaggio senza esserne il destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro sistema. Conservare il messaggio stesso, divulgarlo anche in parte, distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità diverse, costituisce comportamento contrario ai principi dettati dal D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely for the attention and use of the named addressee(s) and may be confidential or proprietary in nature or covered by the provisions of privacy act (Legislative Decree June, 30 2003, no.196 - Italy’s New Data Protection Code).Any use not in accord with its purpose, any disclosure, reproduction, copying, distribution, or either dissemination, either whole or partial, is strictly forbidden except previous formal approval of the named addressee(s). If you are not the intended recipient, please contact immediately the sender by telephone, fax or e-mail and delete the information in this message that has been received in error. The sender does not give any warranty or accept liability as the content, accuracy or completeness of sent messages and accepts no responsibility for changes made after they were sent or for other risks which arise as a result of e-mail transmission, viruses, etc.


+1

Jukka Rahkonen


Lähettäjä: Niels Charlier
Lähetetty: ‎5.‎5.‎2016 11:03
Vastaanottaja: geoserver-devel@lists.sourceforge.net
Aihe: Re: [Geoserver-devel] proposal: LDAP UserGroupService

Can I get a couple more +1 :slight_smile:

On 03-05-16 10:14, Niels Charlier wrote:

Andrea,

Answers inline.

On 03-05-16 09:52, Andrea Aime wrote:

  • Is it really targeted to 2.11, and not to 2.10? :slight_smile:
    Fixed
    Are you considering a backport to 2.9?
    This is not necessary for me.
  • You are making a proposal for it, so it’s going to be part of core,
    with the UI in web/security/ldap? (no problems with it, but the
    proposal should say so)
    Done
  • The configurable portions should be mentioned in the proposal (your
    answer to Christian)
    I had already added that.
    How about longer term maintainership? Core stuff is officially
    maintained by the PSC, so do you expect
    to drop off after the proposal and have the PSC handle community fixes
    and bug reports?
    The implementation is very much in line with / integrated with the rest
    of the sec-ldap module. I know it quite well now and I am willing to
    assist with supporting the module in the longer term. Only recently I
    tested it thoroughly with openldap after the spring upgrade.

Kind Regards
Niels


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel


Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z


Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Can I get a couple more +1 :slight_smile:

+1, though I would like to see recognition that this will need documentation
(ideally a tutorial) on application and limitations.

Brad

Drea Brad,
good point, I was kind of assuming that a brief section in the
documentation will be produced as part of this work since it
introduces new functionality.

Not sure this should be made explicit in the proposal.
Regards,
Simone Giannecchini

GeoServer Professional Services from the experts!
Visit http://goo.gl/it488V for more information.

Ing. Simone Giannecchini
@simogeo
Founder/Director

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 333 8128928

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

-------------------------------------------------------
AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate.
Il loro utilizzo è consentito esclusivamente al destinatario del
messaggio, per le finalità indicate nel messaggio stesso. Qualora
riceviate questo messaggio senza esserne il destinatario, Vi preghiamo
cortesemente di darcene notizia via e-mail e di procedere alla
distruzione del messaggio stesso, cancellandolo dal Vostro sistema.
Conservare il messaggio stesso, divulgarlo anche in parte,
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità
diverse, costituisce comportamento contrario ai principi dettati dal
D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely
for the attention and use of the named addressee(s) and may be
confidential or proprietary in nature or covered by the provisions of
privacy act (Legislative Decree June, 30 2003, no.196 - Italy's New
Data Protection Code).Any use not in accord with its purpose, any
disclosure, reproduction, copying, distribution, or either
dissemination, either whole or partial, is strictly forbidden except
previous formal approval of the named addressee(s). If you are not the
intended recipient, please contact immediately the sender by
telephone, fax or e-mail and delete the information in this message
that has been received in error. The sender does not give any warranty
or accept liability as the content, accuracy or completeness of sent
messages and accepts no responsibility for changes made after they
were sent or for other risks which arise as a result of e-mail
transmission, viruses, etc.

On Thu, May 5, 2016 at 12:00 PM, Brad Hards <bradh@anonymised.com> wrote:

Can I get a couple more +1 :slight_smile:

+1, though I would like to see recognition that this will need documentation
(ideally a tutorial) on application and limitations.

Brad

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

On Thu, May 5, 2016 at 12:10 PM, Simone Giannecchini <
simone.giannecchini@anonymised.com> wrote:

Drea Brad,
good point, I was kind of assuming that a brief section in the
documentation will be produced as part of this work since it
introduces new functionality.

Not sure this should be made explicit in the proposal.

Does not hurt to be explicit about it though... tests have been mandatory
for a long time,
documentation is kind of implied but not always requested for new core
functionality so far...
Maybe we should make a proposal in this direction to clarify it?

Anyways, +1 on this proposal under the condition there are also docs
(reference ones for a minimum, a tutorial would be great but not required)

Cheers
Andrea

--

GeoServer Professional Services from the experts! Visit
http://goo.gl/it488V for more information.

Ing. Andrea Aime
@geowolf
Technical Lead

GeoSolutions S.A.S.
Via di Montramito 3/A
55054 Massarosa (LU)
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39 339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

*AVVERTENZE AI SENSI DEL D.Lgs. 196/2003*

Le informazioni contenute in questo messaggio di posta elettronica e/o
nel/i file/s allegato/i sono da considerarsi strettamente riservate. Il
loro utilizzo è consentito esclusivamente al destinatario del messaggio,
per le finalità indicate nel messaggio stesso. Qualora riceviate questo
messaggio senza esserne il destinatario, Vi preghiamo cortesemente di
darcene notizia via e-mail e di procedere alla distruzione del messaggio
stesso, cancellandolo dal Vostro sistema. Conservare il messaggio stesso,
divulgarlo anche in parte, distribuirlo ad altri soggetti, copiarlo, od
utilizzarlo per finalità diverse, costituisce comportamento contrario ai
principi dettati dal D.Lgs. 196/2003.

The information in this message and/or attachments, is intended solely for
the attention and use of the named addressee(s) and may be confidential or
proprietary in nature or covered by the provisions of privacy act
(Legislative Decree June, 30 2003, no.196 - Italy's New Data Protection
Code).Any use not in accord with its purpose, any disclosure, reproduction,
copying, distribution, or either dissemination, either whole or partial, is
strictly forbidden except previous formal approval of the named
addressee(s). If you are not the intended recipient, please contact
immediately the sender by telephone, fax or e-mail and delete the
information in this message that has been received in error. The sender
does not give any warranty or accept liability as the content, accuracy or
completeness of sent messages and accepts no responsibility for changes
made after they were sent or for other risks which arise as a result of
e-mail transmission, viruses, etc.

-------------------------------------------------------

+1.

Please fix the links at the bottom of the GSIP page. They are still boilerplate.

Kind regards,
Ben.

On 02/05/16 20:46, Niels Charlier wrote:

Hello,

I was waiting to make this proposal for after the release:

https://github.com/geoserver/geoserver/wiki/GSIP-144--

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Please vote / provide feedback.

Thanks
Niels

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

--
Ben Caradoc-Davies <ben@anonymised.com>
Director
Transient Software Limited <http://transient.nz/&gt;
New Zealand

Hi Niels,

···

Basically: There is no LDAP UserGroupService yet. Some people might want
one. For example, to use the integrated geofence with ldap, because the
integrated geofence relies on a UserGroupService.

Since we funded this feature, I would of course +1 this (if this is allowed, I don’t know if the vote is open to everyone).

We are already using the service on a 2.8.x instance successfully.

Kind regards,

Pierre Mauduit

Ingénieur développement

Camptocamp France SAS

Savoie Technolac, BP 352

73377 Le Bourget du Lac, Cedex

Tel (France) : +33 4 58 48 20 24

Fax : +33 4 58 48 20 10

Mail : pierre.mauduit@anonymised.com757…

http://www.camptocamp.com

The proposal has been accepted.
The PR is ready to be reviewed at https://github.com/geoserver/geoserver/pull/1540 by someone with the authority to approve it at their earliest convenience.

Kind Regards
Niels

On 09-05-16 15:07, Pierre Mauduit wrote:

Hi Niels,

    Basically: There is no LDAP UserGroupService yet. Some people
    might want
    one. For example, to use the integrated geofence with ldap,
    because the
    integrated geofence relies on a UserGroupService.

Since we funded this feature, I would of course +1 this (if this is allowed, I don't know if the vote is open to everyone).

We are already using the service on a 2.8.x instance successfully.

Kind regards,

--

Pierre Mauduit

Ingénieur développement

Camptocamp France SAS

Savoie Technolac, BP 352

73377 Le Bourget du Lac, Cedex

Tel (France) : +33 4 58 48 20 24

Fax : +33 4 58 48 20 10

Mail : pierre.mauduit@anonymised.com <mailto:pierre.mauduit@anonymised.com>

http://www.camptocamp.com/&gt;

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z

_______________________________________________
Geoserver-devel mailing list
Geoserver-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-devel