Add new attribute to IPA user info (Linux)

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP





.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty margin-bottom:0;







up vote
1
down vote

favorite












I am not sure its so straightforward on the Linux side.
I want to add a new attribute to identify users as Contractor or Government.
Is this recommended or possible within LDAP?







share|improve this question



















  • It is certainly possible to modify the LDAP schema to add an attribute, assuming that a suitable attribute in a class does not already exist. For example, inetOrgPerson already has "employee type" which might be suitable. However, you could also model the domain differently (using a different/additional OU for example), or perhaps just using groups. I think providing a few scenarios about how you want to filter/search, etc. would help.
    – KevinO
    Jul 18 at 14:43










  • Thank you. For example: ipa user-show jdoe -all would show a field of Status: Contractor or Status: Government.
    – Mervyn Clarke
    Jul 18 at 14:49
















up vote
1
down vote

favorite












I am not sure its so straightforward on the Linux side.
I want to add a new attribute to identify users as Contractor or Government.
Is this recommended or possible within LDAP?







share|improve this question



















  • It is certainly possible to modify the LDAP schema to add an attribute, assuming that a suitable attribute in a class does not already exist. For example, inetOrgPerson already has "employee type" which might be suitable. However, you could also model the domain differently (using a different/additional OU for example), or perhaps just using groups. I think providing a few scenarios about how you want to filter/search, etc. would help.
    – KevinO
    Jul 18 at 14:43










  • Thank you. For example: ipa user-show jdoe -all would show a field of Status: Contractor or Status: Government.
    – Mervyn Clarke
    Jul 18 at 14:49












up vote
1
down vote

favorite









up vote
1
down vote

favorite











I am not sure its so straightforward on the Linux side.
I want to add a new attribute to identify users as Contractor or Government.
Is this recommended or possible within LDAP?







share|improve this question











I am not sure its so straightforward on the Linux side.
I want to add a new attribute to identify users as Contractor or Government.
Is this recommended or possible within LDAP?









share|improve this question










share|improve this question




share|improve this question









asked Jul 18 at 14:13









Mervyn Clarke

184




184











  • It is certainly possible to modify the LDAP schema to add an attribute, assuming that a suitable attribute in a class does not already exist. For example, inetOrgPerson already has "employee type" which might be suitable. However, you could also model the domain differently (using a different/additional OU for example), or perhaps just using groups. I think providing a few scenarios about how you want to filter/search, etc. would help.
    – KevinO
    Jul 18 at 14:43










  • Thank you. For example: ipa user-show jdoe -all would show a field of Status: Contractor or Status: Government.
    – Mervyn Clarke
    Jul 18 at 14:49
















  • It is certainly possible to modify the LDAP schema to add an attribute, assuming that a suitable attribute in a class does not already exist. For example, inetOrgPerson already has "employee type" which might be suitable. However, you could also model the domain differently (using a different/additional OU for example), or perhaps just using groups. I think providing a few scenarios about how you want to filter/search, etc. would help.
    – KevinO
    Jul 18 at 14:43










  • Thank you. For example: ipa user-show jdoe -all would show a field of Status: Contractor or Status: Government.
    – Mervyn Clarke
    Jul 18 at 14:49















It is certainly possible to modify the LDAP schema to add an attribute, assuming that a suitable attribute in a class does not already exist. For example, inetOrgPerson already has "employee type" which might be suitable. However, you could also model the domain differently (using a different/additional OU for example), or perhaps just using groups. I think providing a few scenarios about how you want to filter/search, etc. would help.
– KevinO
Jul 18 at 14:43




It is certainly possible to modify the LDAP schema to add an attribute, assuming that a suitable attribute in a class does not already exist. For example, inetOrgPerson already has "employee type" which might be suitable. However, you could also model the domain differently (using a different/additional OU for example), or perhaps just using groups. I think providing a few scenarios about how you want to filter/search, etc. would help.
– KevinO
Jul 18 at 14:43












Thank you. For example: ipa user-show jdoe -all would show a field of Status: Contractor or Status: Government.
– Mervyn Clarke
Jul 18 at 14:49




Thank you. For example: ipa user-show jdoe -all would show a field of Status: Contractor or Status: Government.
– Mervyn Clarke
Jul 18 at 14:49















active

oldest

votes











Your Answer







StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: false,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);








 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f457008%2fadd-new-attribute-to-ipa-user-info-linux%23new-answer', 'question_page');

);

Post as a guest



































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes










 

draft saved


draft discarded


























 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f457008%2fadd-new-attribute-to-ipa-user-info-linux%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

How to check contact read email or not when send email to Individual?

Bahrain

Postfix configuration issue with fips on centos 7; mailgun relay