Implemented in | 6.0 |
As of Spotfire 6.0 users can optionally be filtered so that only group members are retrieved from the LDAP servers during synchronization. Using this feature requires group synchronization to be enabled, otherwise the new option will be ignored. The new "filter users by groups" option is configured in the config-ldap-group-sync command line tool.
I don't think this is needed. We have an extremely large LDAP directory and our LDAP sync is very efficient. We actually sync every 30 minutes with 4 large LDAP directories on our Spotfire Servers. In 6.5 you can also now add wildcards (i.e. *) on the group names and even specify a partial group name and a full OU restricting the sync to specific groups. You can further trim the LDAP sync by specifying user OU contexts to search them on and setting filter-users-by-groups to true to only sync users which belong to a sync'ed LDAP group.