Group synchronization
Group synchronization makes the user directory mirror the group hierarchies in the LDAP directory.
When you set the
group-sync-enabled
option (in the
config-ldap-group-sync
command), the user directory synchronizes groups from the LDAP directory. By
synchronizing groups you can avoid needing to manage group memberships in
Spotfire. You will still assign licenses and privileges to groups from the
License and features tab for the group in the
Spotfire Server administration pages (or from the Administrator Manager in the
installed Spotfire client).
When configuring the groups to be synchronized, specify either the group account names or the distinguished names. The account names and the distinguished names can contain an asterisk (*) as a wildcard character. This wildcard behaves just like the asterisk wildcard in standard LDAP search filters.
Group synchronization enabled
configuration property
is set and no groups or group context names are configured, the user directory
synchronizes all groups that it can find in the configured context names.
The synchronized groups can also be used to filter the set of users that
are synchronized with the user directory. By enabling the
filter-users-by-groups
option, only users that are
members of at least one of the synchronized groups are synchronized with the
user directory.