contiv/contiv.github.io

Add a note to `Manage Authorizations->Authorizing Users` page

yuva29 opened this issue · 3 comments

Please add this here http://contiv.github.io/documents/admin/manageAuthorizations.html under Authorizing Users

Active Directory(AD) users are authorized based on the authorizations defined on their AD groups in our system.
Single user can be associated with many AD groups (one of them being the primary group) and 
the authorizations can be defined on any of them expect the primary group.
Because, there is no straight-froward mechanism to retrieve user's primary group from AD. 

More details here: http://lists.freeradius.org/pipermail/freeradius-users/2012-August/062055.html

As mentioned, please write up a high level explanation for why this shouldn't be done in addition to linking to the relevant discussion

Updated it.