From: Glen Holcomb Date: 2007-04-20T07:31:02+09:00 Subject: Re: ruby scripting on microsoft active directory plus exchange ------=_Part_47942_2417534.1177021860199 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 4/19/07, Francis Cianfrocca wrote: > > On 4/19/07, Glen Holcomb wrote: > > > > Francis, your Net::XACML proposition sounds very interesting. I would > > be > > happy to provide what help I can. I should forewarn you though, I'm new > > to > > ruby and haven't done any serious programming in a while. As for my > ideas > > with regards to Net::LDAP and A/D. I will collect them and post > something > > later today (work has been a bit hectic). > > > > With regard to XACML, it would be enough for interested people to suggest > applications and be wiling to try our code out. We're getting closer to a > beta drop of an authorization engine (no more than a few weeks away or > less) > and I'll announce it here. As I said, it's the fruit of years of labor, > but > it's only recently that people are getting interested in the idea of a > centralized authorization service. > I can actually only think of a couple of things right now. First, when attempting bind_as with non administrator level credentials and the :base set to the root of the tree I get an invalid credentials error message, It has to be the permissions on the tree. I'm not sure if this is the default A/D configuration or not but I have a feeling (after talking to the admin) that it is. It would be nice if there were a way for :bind_as or maybe a new method :bind_as_ad to automatically change the base to whatever normal user accounts try to authenticate against. I'm not sure what that is if such a thing exists though. A few simple wrappers for those not familiar with A/D that want to get "standard" info out of the directory might be nice too. For example a groups method so those unfamiliar with A/D don't have to dig through the directory structure to find memberof, also things like username to grab the cn value. Some might also find some sort of clean interface for grabbing machine account info to be useful as well. -- "Hey brother christian with your high and mighty errand, Your actions speak so loud, I can't hear a word you're saying." -Greg Graffin (Bad Religion) ------=_Part_47942_2417534.1177021860199--