AEM and LDAP Group Mapping and permission management Best practices
Hi Everyone,
I would like to take some recommendations and best practices wrt AEM internal groups and LDAP groups mapping & permission management.
We have AEM and LDAP groups setup in our project, both internal and LDAP groups are named identical. We are on AEM 6.5 and using ACL Netcentric to maintain the permissions. Below is one of the sample config we have with the yaml file.
- aem-publishers-myapp-gb:
- name: MyApp Publishers GB
isMemberOf: aem-common-myapp
path: myapp/gb
externalId: "CN=aem-publishers-myapp-gb,OU=xxxx,OU=xxxx,OU=xxxx,OU=xxxx,DC=xxxx,DC=COM;XXXX"
- Is it recommended to both the internal and LDAP groups identical name?
- Are there any known limitation with this kind of setup?
- Would it be advised to have the unique names among AEM internal and LDAP?
We are currently facing some issues when a LDAP group details got updated and then users either lost permissions or unable to login to AEM, where the log throws this group already exists in AEM. The investigation for this issue is in progress but meanwhile we suspect this would be due to the group naming conventions followed.
It would be great to get any of your views on the above mentioned setup.
Thanks in Advance!
Mani