Roles & Groups

Daniel Hoffend dh at dotlan.net
Thu Sep 4 12:10:44 CEST 2014


Hmmm maybe my knowledge about this is outdated.

Cyrus supports Groups, you must prepend group: in the ACL
http://cyrusimap.org/docs/cyrus-imapd/2.4.7/overview.php#acluser

But you must have ldap configured. The current default config is
ldap_group_filter: 
(&(cn=%u)(objectclass=ldapsubentry)(objectclass=nsroledefinition))
ldap_member_attribute: nsrole
And this is where it is getting confusing again. Groups VS roles.

In my opinion roles would be flags or checkboxes like access rights 
someone has,
and groups are to organize groups, teams or org structures. But that's 
the joy of
having LDAP. Basically you're free to use and configure it the way you 
want and if you
prefer group instead of roles you're free to configure cyrus or any 
other application
the way you want.

It would be good to have an actual documentation section about what's 
the philosophy behind
groups and roles and what would be the best practices to use them. Sure 
everyone has an idea
or vision how they should be used or are limited to their current 
existing directory (for
migration) but some ideas about best practices would be helpful.

--
regards
Daniel


------ Originalnachricht ------
Von: "Torsten Grote" <torsten at kolab.org>
An: users at lists.kolab.org
Gesendet: 04.09.2014 10:06:23
Betreff: Re: Roles & Groups

>On Thursday 04 September 2014 07:16:13 Daniel Hoffend wrote:
>>  Cyrus can only manage per user ACLs on folders. Cyrus is not aware of 
>>groups
>>  afaik.
>
>Actually that is not true. With Kolab.org 3.3 you can even use groups 
>in the
>web client ACL settings. Just type group:nameofgroup
>
>Kind Regards,
>Torsten
>
>--
>Torsten Grote
>Kolab.org Community Manager
>
>e: torsten at kolab.org
>w: https://Kolab.org
>
>pgp: 0x2175A534A4F2EFA3
>_______________________________________________
>users mailing list
>users at lists.kolab.org
>https://lists.kolab.org/mailman/listinfo/users
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5714 bytes
Desc: not available
URL: <http://lists.kolab.org/pipermail/users/attachments/20140904/3413fc0a/attachment.bin>


More information about the users mailing list