Re: [Freeipa-devel] group inactivation question

On Tue, 2007-11-06 at 14:29 -0500, Rob Crittenden wrote:
> Ticket https://hosted.fedoraproject.org/projects/freeipa/ticket/54 calls 
> for an option to inactivate all users in a group.
> I've got this mostly done on the GUI side. I added a similar option to 
> mark a group as active/inactive and it too updates nsAccountLock.
> So in XML-RPC when a group is updated I can see if this is "true" and 
> mark all the members as inactive. But this opens a real can of works.
> Groups can be members of groups. Should I follow all paths and 
> recursively mark everything inactive?

I say no - I think this behavior would be surprising, but who knows.

> And does the reverse hold true as well? If a group is inactive and it is 
> marked active does that cause everything to become active again? I 
> assume so but I hate assuming.

I assume so as well.

BTW - are you fixing the whole deluser is actually inactivation issue so
that we can both delete users and inactivate them?


