<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic One CAS server for multiple Alfresco servers in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200852#M153982</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi there,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm working on a Alfresco CAS LDAP installation. Most things are up and running but I have still some questions. My idea is to have one single CAS Server for SSO for Liferay and multiple Alfresco servers for different customers. The CAS server (with ApacheDS) is configured to search the whole directory (DC=ALL, DC=Customers), the Alfresco servers ldap authentification and synchronisation is configured with this searchbase:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.userNameFormat=cn=%s,ou=customer1people,ou=custumer1groups,dc=all,dc=customers.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now I have the following problem:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Every user who has a valid cas login (all users from ou=customer1, ou=customer2…) is allowed to login to the alfresco webclient on server customer1 despite he is definitely not in the list of users which is imported via ldap (I checked the XML files with the LPAD importdata)?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;There is one difference between the users who are importet from LDAP and those who can login through CAS: webdav login is only permitted for the LDAP authentificated users, that makes me sure that the LDAP settings for alfresco are correct.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there any chance to allow only the members of ou=customer1people,ou=custumer1groups to alfresco on server customer1 even if cas accept all members of my directory.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Another question is is it possible to authentificate against multiple ou like customer1 an support for server customer1, ou=customer2 and ou=support for server customer2 and so on?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I hope some of you will understand what I tried to explain and may have a solution for this setup.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Arne Kaiser&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Feb 2009 16:29:14 GMT</pubDate>
    <dc:creator>arnekaiser</dc:creator>
    <dc:date>2009-02-12T16:29:14Z</dc:date>
    <item>
      <title>One CAS server for multiple Alfresco servers</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200852#M153982</link>
      <description>Hi there,I'm working on a Alfresco CAS LDAP installation. Most things are up and running but I have still some questions. My idea is to have one single CAS Server for SSO for Liferay and multiple Alfresco servers for different customers. The CAS server (with ApacheDS) is configured to search the who</description>
      <pubDate>Thu, 12 Feb 2009 16:29:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200852#M153982</guid>
      <dc:creator>arnekaiser</dc:creator>
      <dc:date>2009-02-12T16:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: One CAS server for multiple Alfresco servers</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200853#M153983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Did you solve it?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2009 20:51:11 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200853#M153983</guid>
      <dc:creator>juan</dc:creator>
      <dc:date>2009-03-02T20:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: One CAS server for multiple Alfresco servers</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200854#M153984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;no, its still open.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Mar 2009 18:43:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200854#M153984</guid>
      <dc:creator>arnekaiser</dc:creator>
      <dc:date>2009-03-08T18:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: One CAS server for multiple Alfresco servers</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200855#M153985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have found a workaround for a similar issue;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Import desired LDAP users and change authentication-services-context.xml at line 280:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(change default "createMissingPeople" value from&amp;nbsp; ${server.transaction.allow-writes} -&amp;gt; false )&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color:#0000FF;"&gt;&amp;lt;bean id="personService" class="org.alfresco.repo.security.person.PersonServiceImpl" init-method="init"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color:#00BF00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– Some authentication mechanisms may need to create people –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– in the repository on demand. This enables that feature.&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– If dsiabled an error will be generated for missing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– people. If enabled then a person will be created and&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– persisted.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– Valid values are&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ${server.transaction.allow-writes}&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; false&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color:#0000BF;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="createMissingPeople"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;value&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color:#000000;"&gt; &lt;STRONG&gt;false&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color:#0000BF;"&gt; &amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;…&lt;BR /&gt;…&lt;BR /&gt;&amp;lt;/bean&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This way prevents Alfresco from creating any new user.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2009 08:29:20 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200855#M153985</guid>
      <dc:creator>juan</dc:creator>
      <dc:date>2009-03-10T08:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: One CAS server for multiple Alfresco servers</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200856#M153986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Juan,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;that sounds like a suitable workaround, ich will try that ass soon as possible.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank You!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Arne&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Mar 2009 17:00:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/one-cas-server-for-multiple-alfresco-servers/m-p/200856#M153986</guid>
      <dc:creator>arnekaiser</dc:creator>
      <dc:date>2009-03-15T17:00:57Z</dc:date>
    </item>
  </channel>
</rss>

