[midPoint] Recompute all users is not working for me

Ivan Noris ivan.noris at evolveum.com
Mon Jun 22 13:29:37 CEST 2020


Hi Gus,

I don't know if you are referring to a specific sample, e.g. for the
metarole.

Sharing it would be helpful.

So far my only idea is to check if the (2nd order) mapping for
association has strong strength.

Best regards,

Ivan

On 22. 6. 2020 1:18, Gus Lou wrote:
> Hi Guys
> I need the permissions of users assigned to a Role (Rbac role named
> "Sec - SOC") to be updated after adding a new group (gs_spo_sec_soc)
> to this Role.
> After adding the group to the role, I ran a recompute task, I expected
> the new group to be added to users but it didn't. If I add a new user
> to the role he receives all groups.
>
> Did I do something wrong, did any steps miss?
>
> I followed the instructions on the wiki:
> https://wiki.evolveum.com/display/midPoint/Recompute+Task
>
> And also in this thread:
> https://lists.evolveum.com/pipermail/midpoint/2014-November/000639.html
>
> *My Lab*
> 01 Midpoint 4.1
> 01 Active Directory (Connector Ldap / AD 3.0) Resource
> 01 Metarole: "Metarole for groups - AD" (inducement to Active
> Directory (LDAP) Resource
> 03 Groups (gs_snow_sec_soc, gs_jira_sec_soc, gs_spo_sec_soc) assigned
> to Metarole
> 01 Rbac Role "Sec - SOC" inducements (gs_snow_sec_soc,
> gs_jira_sec_soc, gs_spo_sec_soc)
>
>
> Best Regards
> Gus
>
>
> _______________________________________________
> midPoint mailing list
> midPoint at lists.evolveum.com
> https://lists.evolveum.com/mailman/listinfo/midpoint

-- 
Ivan Noris
Senior Identity Engineer
evolveum.com

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20200622/370f4095/attachment.htm>


More information about the midPoint mailing list