Register users with same name

I’m wondering if there is any workaround to register people with same First and Lastname with same certifier-id?

Regards,

Erik

Subject: Everyone is going to tell you the same thing…

use a middle initial or nickname for one or both of them.

Subject: RE: Everyone is going to tell you the same thing…

can’t, i’ve 12 000 users waiting to be registered, so i can’t just rename or add initialname…

Subject: RE: Everyone is going to tell you the same thing…

I will be more direct (and I have never been accused of that;-) ):

You are goong to cause yourself more problems and headaches than it is worth if you do NOT do this, starting with mail routing from the outside.

I am going to suggest that you create a database to store an imported spreadsheet or CSV file that you will be using to create the users (I hope this is the approach you are taking). Make a sorted lookup view on the Common Name.

Then write an agent to register the users through the back end. For each user, check for duplicate names. If there is a duplicate, flag this document and all the duplicates found so they do not get processed. Run the agent and deal with duplications after the initial run.

Otherwise, you are going to come running and screaming back in here about your problems routing mail, etc.!

Subject: RE: Everyone is going to tell you the same thing…

Everyone except me; I’ll tell you to use a user-unique organizational unit which identifies one or (preferably) both of the users with the same name.

Subject: RE: Everyone is going to tell you the same thing…

hehe, someone who did not the skip boring paragraphs in the big Lotus book.Indeed that’s why they were invented in the first place :0. But you have to admit it would be easier if you can identify users with their Middle Initials.

Subject: RE: Everyone is going to tell you the same thing…

It doesn’t tend to be easier for the users.

Subject: RE: Everyone is going to tell you the same thing…

What, we were goimg to state the obvious?:slight_smile:

But seriously, this is only a valid alternative if you never have employee moves or reofanizations. If so, you risk the same problems. Bettr off heading this issue off up front and be done with it.

Subject: RE: Everyone is going to tell you the same thing…

I disagree – but then it’s not the first time we’ve disagreed.

Subject: RE: Everyone is going to tell you the same thing…

Nothing wrong with disagreement…it lends itself to self enlightenment (on both sides hopefully) and discussion.

Lets take what is happening here a step further. Suppose web-based authentication is brought into the picture (for iNotes or other web-based applications).

12,000 people are registered and somehow, theoretically speaking of course, the users no longer have distinctive short names. What happens when they try to log in using the short name? Instant conflict, no?

In addition, this has the potential of becoming a material control vulnerability that can be exploited.

Another example: I have seen too many cases where people have done type-ahead of names in addressing e-mail that are the same and guess what? They pick the wrong one. Of course, this also happens when they do not know if they want John A Smith or John B Smith. There is no real way to control for this, but with the introduction of a tie-breaker up front you have at least a shot at minimizing it as most users do not know from an OU.

To me, user registration can be addressed up front to deal with these issues or have to be dealt with later.

Subject: RE: Everyone is going to tell you the same thing…

I agree with you about the disagreement thing – especially about the self-enlightenment part; I often disagree with myself in an attempt to achieve enlightenment. (Usually it’s just about whether to have that last whiskey, but I like to think it’s still a healthy debate.) But you don’t need to worry that I was offended; I just don’t know the right emoticon for “I’m not tremendously thin-skinned.”

The shortname issue is a potentially serious one; nothing stops you from registering new users with shortnames identical to an existing user’s. Two things about that: (1) One could use this issue as support for the argument to disallow shortname authentication. (2) It doesn’t relate to the issue of whether to use middle initials or UUOUs to distinguish matching common names.

Your point about John A Smith vs. John B Smith and the propensity to choose the first match is of course my point exactly for why middle initials aren’t a good solution. And nicknames have their own drawbacks. You say “most users do not know from an OU,” and while that may be true, if you compare the user’s guessing a middle initial to the user’s choosing between John Smith/Accounting/Acme and John Smith/IT/Acme, I’d pick the latter for both better odds of guessing right AND better odds of not just choosing the first type-ahead match, since even if I don’t have an OU in my name, when I see that I’m sending mail to someone in the completely wrong department, I might just notice.

What I wonder is what you’re suggesting as a tie-breaker up front besides middle initials, nicknames, or UUOUs?

Subject: RE: Everyone is going to tell you the same thing…

There is no “easy solution”. COBIT ™ Standards state that each user should have a unique username. To an extent, that happens when we use OUs to form a Hierarchal name. But I have seen to many users use Type ahead and consitently select the wrong name because they are either not paying attention or do not know how to tell the difference. And many times they do not notice a misaddressed mail unless pointed out to them. If they missend a condidential piece of information, you risk running afoul of SOX, HIPAA, Patriot Act, etc.

Or they just mis-send a piece of Juicy gossip.

Yes, it should form a different policy basis for acceptable User Names for authentication purposes. BUT, routing of inbound SMTP mail? Unless you have alternative email address such as bstapely@finance.stapley.com and bstapely@hr.stapley.com, you are going to have problems, especially of the short name has NOT been paid attention to in processing User registrations.

Then what happens when Bernice Stapley gets transferred to HR with Bruce Stapely (and of course they are not related). Where is the tiebreaker then? Do you now add it AFTER the fact, which has its own set of problems/issues?

How do you disciple your developers to avoind the use of @name([CN];…) which users prefer to see in applications.

This discussions really requires much whiskey and time, but my bottom line is that it is easier to use the combination of Initials AND OUs, and hope for the best. The biggest hassle is deciding who gets the initial and who does not. And of course, what iof you have to Vruce A. Stapeleys…?

A little story. I used to work for a Federal Agency where someone else had the same First name and Last name AND MI as I, and he kept getting my mail. When he called me and we talked, it turned out that he was also the same guy CBS Sports kept sending MY paychecks to because they did not check our SSNs. Too bizarre for words.

Subject: Now we’re back to agreeing again

Now if I could just figure out who’s getting MY paychecks…