Univention Bugzilla – Bug 41680
AD Connector: Make global_ignore_subtree configurable via UCR
Last modified: 2018-05-15 10:30:24 CEST
The AD Connector mapping file uses 'global_ignore_subtree' to ignore a bunch of LDAP subtrees so they do NOT get synchronized. Unfortunately this is a hard coded list and not configurable. In some scenarios this ignore list must be extended so we should make this possible, just as other objects can be ignored via UCR, too (groups, users, containers ...)
* Make the global_ignore_subtree configuration option configurable via the UCR variable connector/ad/mapping/ignoresubtree/* (Bug #41680) 4.1-3: r72540 4.2: r72541 YAML: r72542
OK - connector/ad/mapping/ignoresubtree UCS 4.1-3 with ad connector + windows server 2012 (1) # container ignore with two users ignore1 and ignore2 @ucs-> univention-ldapsearch -LLL -b "cn=ignore,$(ucr get ldap/base)" dn dn: cn=ignore,dc=four,dc=test dn: uid=ignore1,cn=ignore,dc=four,dc=test dn: uid=ignore2,cn=ignore,dc=four,dc=test (2) # disabled sync of ignore container @ucs-> ucr set connector/ad/mapping/ignoresubtree/ignore="cn=ignore,dc=four,dc=test" (3) configured/started ad connector (bidirectional) (4) # container and users NOT synced to ad @ucs-> nivention-adsearch 'cn=ignore1' @ucs-> nivention-adsearch 'cn=ignore2' @ucs-> nivention-adsearch 'cn=ignore' @ucs-> nivention-adsearch 'cn=ignore*' OK - merged to 4.2-0 OK - yaml
<http://errata.software-univention.de/ucs/4.1/267.html>