<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP - Bind Account Logs in no one else in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-bind-account-logs-in-no-one-else/m-p/196972#M150102</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have followed all the forum post for getting LDAP to work and believe I have it right but the only user that can log in is the actual bind account user. I am on Alfresco 3.x, Windows Server 2003 Standard, Full Install from Alfresco Community, etc. Please review the following file and let me know if anyone sees anything wrong that would cause just the actual bind account to login and no one else.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My ldap-authentication.properties file is the following:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;#&lt;BR /&gt;# This properties file brings together the common options for LDAP authentication rather than editing the bean definitions&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;# How to map the user id entered by the user to taht passed through to LDAP&lt;BR /&gt;# - simple &lt;BR /&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; - this must be a DN and would be something like&lt;BR /&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CN=%s,DC=company,DC=com&lt;BR /&gt;# - digest&lt;BR /&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp; - usually pass through what is entered&lt;BR /&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %s&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.userNameFormat=%s&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;# The LDAP context factory to use&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;# The URL to connect to the LDAP server &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.provider.url=ldap://pxdc05.us.pxd.pvt:389&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;#ldap.authentication.java.naming.provider.url=ldap://172.01.120.3:389&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;# The authentication mechanism to use&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.authentication=SIMPLE&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;# The default principal to use (only used for LDAP sync)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.principal=CN=alf-mgr,OU=ServiceAccounts,OU=Communities,DC=us,DC=pxd,DC=pvt&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;#ldap.authentication.java.naming.security.principal=CN=alf-mgr&lt;BR /&gt;# The password for the default principal (only used for LDAP sync)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.credentials=Xb1z3R5#&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;# Escape commas entered by the user at bind time&lt;BR /&gt;# Useful when using simple authentication and the CN is part of the DN and contains commas&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.escapeCommasInBind=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#008000;"&gt;# Escape commas entered by the user when setting the authenticated user&lt;BR /&gt;# Useful when using simple authentication and the CN is part of the DN and contains commas, and the escaped \, is &lt;BR /&gt;# pulled in as part of an LDAP sync&lt;BR /&gt;# If this option is set to true it will break the default home folder provider as space names can not contain \&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.escapeCommasInUid=false&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Mar 2009 18:12:42 GMT</pubDate>
    <dc:creator>neomlsra</dc:creator>
    <dc:date>2009-03-05T18:12:42Z</dc:date>
    <item>
      <title>LDAP - Bind Account Logs in no one else</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-bind-account-logs-in-no-one-else/m-p/196972#M150102</link>
      <description>I have followed all the forum post for getting LDAP to work and believe I have it right but the only user that can log in is the actual bind account user. I am on Alfresco 3.x, Windows Server 2003 Standard, Full Install from Alfresco Community, etc. Please review the following file and let me know i</description>
      <pubDate>Thu, 05 Mar 2009 18:12:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-bind-account-logs-in-no-one-else/m-p/196972#M150102</guid>
      <dc:creator>neomlsra</dc:creator>
      <dc:date>2009-03-05T18:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - Bind Account Logs in no one else</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-bind-account-logs-in-no-one-else/m-p/196973#M150103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I resolved this issue and everyone can log in now by changing from SIMPLE to DIGEST-MD5.&amp;nbsp; Now on to chaining so I get the Admin to work.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2009 20:56:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-bind-account-logs-in-no-one-else/m-p/196973#M150103</guid>
      <dc:creator>neomlsra</dc:creator>
      <dc:date>2009-03-05T20:56:57Z</dc:date>
    </item>
  </channel>
</rss>

