<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: simple LDAP authentication with several OUs in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22430#M10746</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) Active Directory does not advertise that it supports DIGEST-MD5 authentication method. I would expect this authentication method to be fine for extracting users and groups. If you can authenticate and the user has read rights that is enough.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2 &amp;amp; 3) I have set up OpenLDAP using DIGEST-MD5. The configuration is on the enterprise bit of the wiki.&amp;nbsp; &lt;/SPAN&gt;&lt;A href="http://wiki.alfresco.com/wiki/Enterprise_Security_and_Authentication_Configuration" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Enterprise_Security_and_Authentication_Configuration&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As I understand it, in OpenLDAP you need plain text to support all auth methods. If you just want to support DIGEST-MD5 you should be able to store the MD5 password hash. Then simple/SHA etc would not be possible.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have not confirmed this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4) I have answered some questions that may help on referral.&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://forums.alfresco.com/viewtopic.php?t=1518&amp;amp;highlight=referral" rel="nofollow noopener noreferrer"&gt;http://forums.alfresco.com/viewtopic.php?t=1518&amp;amp;highlight=referral&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like to know how you get on.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;5) Chaining will allow you to combine any number of authentication services. This can be two LDAP instances with different config and the built in Alfresco authenitcation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Apr 2006 09:11:35 GMT</pubDate>
    <dc:creator>andy</dc:creator>
    <dc:date>2006-04-10T09:11:35Z</dc:date>
    <item>
      <title>simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22427#M10743</link>
      <description>Hi, I would like to use the LDAP authentication with the "simple" mechanism(combined with SSL). I see in the ldap-authentication-context.xml file thatI have to specify the full DN of the user in the userNameFormat. It doesn'tsuit us because the users are spread over different OUs. Is there a way ofi</description>
      <pubDate>Fri, 07 Apr 2006 11:49:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22427#M10743</guid>
      <dc:creator>france</dc:creator>
      <dc:date>2006-04-07T11:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22428#M10744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't think this is possible as you need the full DN of the user for simple authentication. (See &lt;/SPAN&gt;&lt;A href="http://java.sun.com/products/jndi/tutorial/ldap/security/simple.html" rel="nofollow noopener noreferrer"&gt;http://java.sun.com/products/jndi/tutorial/ldap/security/simple.html&lt;/A&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What are you using as the back end?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If Active Directory I would go with JAAS/Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It would then be fine to use SSL+simple jsut to extract groups and users. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If OpenLDAP I would go with DIGEST MD5.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2006 13:10:13 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22428#M10744</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-04-07T13:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22429#M10745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Andy,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your answer.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'd like to give you more information about my ldap "setting".&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1. I tried to realize the authentication with Active Directory. It works with&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"simple", but also with "DIGEST-MD5". According to the documentation, it&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;should not work with Active Directory and DIGEST-MD5, but it does. I tried&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;first from a Windows installation during the course in Belgium; now I am&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;using Alfresco on a Linux platform and it works too.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;But maybe I'll have problem to extract groups and users ? I didn't try yet.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. I built a small openldap server. I can realize the authentication from&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco to this ldap server with the "simple" mechanism. But it's not good&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;because we are using different OUs for the users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Up to now I didn't succeed in setting the DIGEST-MD5 mechanism on the openldap server. Anyway, it raises an important question: according to the openldap documentation, I need to keep the user passwords in clear text in the ldap server. It is not so nice … Can the passwords be encrypted ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4. The final setup for our company would be a combination of an openldap&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;server with referrals to Active Directory for the internal users, as&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;explained by Simon in his post "Alfresco ignores LDAP referrals". I do&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;need 1 unique way of defining the authentication that can work for both&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;openldap and Active Directory.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5. You mentioned that Alfresco 1.3 will support authentication chaining.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;But will it be with simple authentication or DIGEST-MD5 or will it be&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;possible to choose the mechanism depending on the kind of ldap server ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; France&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2006 16:24:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22429#M10745</guid>
      <dc:creator>france</dc:creator>
      <dc:date>2006-04-07T16:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22430#M10746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) Active Directory does not advertise that it supports DIGEST-MD5 authentication method. I would expect this authentication method to be fine for extracting users and groups. If you can authenticate and the user has read rights that is enough.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2 &amp;amp; 3) I have set up OpenLDAP using DIGEST-MD5. The configuration is on the enterprise bit of the wiki.&amp;nbsp; &lt;/SPAN&gt;&lt;A href="http://wiki.alfresco.com/wiki/Enterprise_Security_and_Authentication_Configuration" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Enterprise_Security_and_Authentication_Configuration&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As I understand it, in OpenLDAP you need plain text to support all auth methods. If you just want to support DIGEST-MD5 you should be able to store the MD5 password hash. Then simple/SHA etc would not be possible.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have not confirmed this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4) I have answered some questions that may help on referral.&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://forums.alfresco.com/viewtopic.php?t=1518&amp;amp;highlight=referral" rel="nofollow noopener noreferrer"&gt;http://forums.alfresco.com/viewtopic.php?t=1518&amp;amp;highlight=referral&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like to know how you get on.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;5) Chaining will allow you to combine any number of authentication services. This can be two LDAP instances with different config and the built in Alfresco authenitcation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Apr 2006 09:11:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22430#M10746</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-04-10T09:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22431#M10747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Easter holidays are over so time to solve some LDAP problems… again.&amp;nbsp; :roll: I'll continue where France stopped in her last post (we are colleagues).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We tried the following combinations to authenticate against an LDAP with Alfresco and they all worked:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- SIMPLE authentication and Active Directory&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- SIMPLE authentication and OpenLDAP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- DIGEST-MD5 authentication and Active Directory&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- DIGEST-MD5 authentication and OpenLDAP&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now we would like to use these mechanisms to authenticate against multiple LDAP's. The LDAP referrals (from OpenLDAP to Active AD) don't work at the moment (see other post) so we should find a way to authenticate both our internal and external users (internals are kept in AD and externals are stored in OpenLDAP) when they login to Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;France came up with the following construction:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. Copy all the users to one single OU in OpenLDAP (both internals and externals).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. The externals have their full credentials stored here but the internals have a &lt;/SPAN&gt;&lt;EM&gt;cn=username&lt;/EM&gt;&lt;SPAN&gt; and a password &lt;/SPAN&gt;&lt;EM&gt;userpassword={SASL}username@company.be&lt;/EM&gt;&lt;SPAN&gt; (their full credentials are stored in AD).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. When an internal user tries to login their password is looked up by the salsauthentication deamon which in his turn tries to find the Kerberos server (which is Active Directory in our case).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could this work and is this the best way to solve our problem?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2006 10:02:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22431#M10747</guid>
      <dc:creator>simon</dc:creator>
      <dc:date>2006-04-18T10:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22432#M10748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Simon&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See the other post…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have discovered you can have more than one LDAP server in the URL (space separated) and it will try them in turn for authentication. There is an example for simple auth.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have not tried this yet myself.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This should solve the referral problem by removing it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2006 10:08:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22432#M10748</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-04-18T10:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: simple LDAP authentication with several OUs</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22433#M10749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Indeed Andy, I should have read your other post first, sorry.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The "more than one LDAP server in the URL" trick did it! I tested it with simple authentication against an AD and an OpenLDAP server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;DIGEST-MD5 is still a problem but this is a "wrong OpenLDAP version" problem so we'll try another version.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Apr 2006 13:59:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/simple-ldap-authentication-with-several-ous/m-p/22433#M10749</guid>
      <dc:creator>simon</dc:creator>
      <dc:date>2006-04-18T13:59:27Z</dc:date>
    </item>
  </channel>
</rss>

