cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
Re: [[cat-users]] Feature suggestion for managed IdP : being able to reset User Base.
Chronological Thread
- From: Stefan Winter <address@concealed>
- To: address@concealed
- Cc: Paul Gunn <address@concealed>
- Subject: Re: [[cat-users]] Feature suggestion for managed IdP : being able to reset User Base.
- Date: Mon, 20 May 2019 13:48:23 +0200
Hello,
> I've just helped one of our members set up the managed IdP. Over video
> conference.
>
> With us trying to get 1 of every type of device enrolled while I was
> online so they could see the process, me accidentally hitting the create
> user twice, and the general fun of remote support, their user list is
> looking a bit untidy.
>
> Right now, I'd love to hit a "Reset User Base" link, which would email
> the admin a link that they needed click on. Zap! Empty user list. Now
> they can import a clean CSV file and do a proper roll out now that
> they've done all the testing that they need to do.
I understand the use case.
The complication here though is that we keep logs of which account
authenticated when for the default period of six months. As soon as an
account was created and used to log into eduroam just once, we want to
have a trail starting at a client certificate, mapping to a username and
the associated Managed IdP institution.
If we were to allow actual deletion of previously used accounts, this
audit trail would become incomplete.
There is a shim to be argued about: created users which never actually
logged in. Yes, those we could delete right away, but those are also not
many - even in test scenarios as usage is one of the things you'd
typically want to test.
So:
> Or tabs with different lists for
>
> * new users
> * active users
> * deactivated users
Let's do this instead :-) That's a very useful suggestion for tidying up
the user overview.
Actually doing tabs involves more jQuery than I like (I like zero
jQuery) so I'll sit down together with Tomasz to work out how the code
needs to be changed to get organised in such tabs.
In the same go, I'll also default-hide expired and revoked certificates
as those are also not usually tremendously interesting.
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
[[cat-users]] Feature suggestion for managed IdP : being able to reset User Base.,
Paul Gunn, 05/06/2019
- Re: [[cat-users]] Feature suggestion for managed IdP : being able to reset User Base., Stefan Winter, 05/20/2019
Archive powered by MHonArc 2.6.19+.
