Skip to main content

LDAP Link and object re-parenting

  • August 3, 2018
  • 0 replies
  • 7 views

praveshbhardwaj
Forum|alt.badge.img+1

Hi Team,

We have a customer using LDAP Link to sync Vertica with their AD. They are planning to roll out some changes to the user's hierarchy and so LDAP DNs for all these users needs to be updated to reflect their new teams/hierarchy. We know LDAP Link as it works, drops and recreates LDAP users within Vertica when there is any change to the DNs. However, this should also mean we have to again (manually):

1. Re-parent Vertica tables and views with new users.
2. Grant authentications to the users.

The proposed changes at customer are large scale and potentially disruptive as it will involve re-parenting nearly all Vertica tables/views.

The proposed plan includes making use of config param GlobalHeirUserName to change ownership to dbadmin or some other user (so objects are not dropped by LDAP Link) and then probably writing a script to change ownership back to earlier respective owners. This script should utilize system table "REPARENTED_ON_DROP" to determine the older ownership.

Does this plan sounds reasonable? And more importantly, if anyone has any recommendations/BP from field experience. This should be a common scenario for customers using LDAP Link.

Customer is using Vertica 8.0.

Thanks in advance.
Pravesh