Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-2851

LDAP connector using Incremental Sync still syncs all memberships

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Medium
    • 2.4.4, 2.5
    • 2.3.2
    • Directory - LDAP
    • None

    Description

      When syncing an LDAP directory with Active Directory using incremental sync, user and group checks on periodic sync will properly respect the uSNChanged attribute and only make needed changes. However, even if AbstractCacheRefresher.synchroniseMemberships() returns an empty list, the connector will still query LDAP for all of the groups and check memberships as per a full sync, which can be very expensive in large ADs that depend on incremental syncs for performance.

      Attachments

        Issue Links

          Activity

            People

              jwalton joe
              alaskowski Adam Laskowski (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: