<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [SOLVED]Alfresco + Active Directory in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202760#M155890</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;So…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any of you can answer my question?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I can only login with AD users if I use &lt;/SPAN&gt;&lt;STRONG&gt;%s@company.com&lt;/STRONG&gt;&lt;SPAN&gt; in ldap.authentication.userNameFormat.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;If I use something like: &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="https://migration33.stage.lithium.com/" rel="nofollow noopener noreferrer"&gt;ldap.authentication.userNameFormat=CN=%s@company.pt&lt;/A&gt;&lt;SPAN&gt;, CN=AlfrescoUsers, OU=Alfresco, DC=company, DC=com, the users and the groups are imported, but I cant login…&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any of you had this problem?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 May 2009 08:55:38 GMT</pubDate>
    <dc:creator>luisg</dc:creator>
    <dc:date>2009-05-07T08:55:38Z</dc:date>
    <item>
      <title>[SOLVED]Alfresco + Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202759#M155889</link>
      <description>Hi there.I have been trying to configure Alfresco with Active Directory. Now, all the users in Active Directory can login in Alfresco.The thing is, I just want that some specific users, inside a specific group, can login.My AD tree is something like&lt;IMG id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;C=company, DC=pt&amp;nbsp;&amp;nbsp; OU=AlfrescoOU&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CN=Alfresco</description>
      <pubDate>Tue, 28 Apr 2009 14:59:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202759#M155889</guid>
      <dc:creator>luisg</dc:creator>
      <dc:date>2009-04-28T14:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED]Alfresco + Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202760#M155890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;So…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any of you can answer my question?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I can only login with AD users if I use &lt;/SPAN&gt;&lt;STRONG&gt;%s@company.com&lt;/STRONG&gt;&lt;SPAN&gt; in ldap.authentication.userNameFormat.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;If I use something like: &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="https://migration33.stage.lithium.com/" rel="nofollow noopener noreferrer"&gt;ldap.authentication.userNameFormat=CN=%s@company.pt&lt;/A&gt;&lt;SPAN&gt;, CN=AlfrescoUsers, OU=Alfresco, DC=company, DC=com, the users and the groups are imported, but I cant login…&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any of you had this problem?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 May 2009 08:55:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202760#M155890</guid>
      <dc:creator>luisg</dc:creator>
      <dc:date>2009-05-07T08:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED]Alfresco + Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202761#M155891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi there…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Just passed to say that I solved the thing….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;STRONG&gt;ldap.authentication.userNameFormat=&lt;/STRONG&gt;&lt;SPAN&gt; is just &lt;/SPAN&gt;&lt;STRONG&gt;%s@company.pt&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And if I want only the users in some OU, lets say, OU=Users,OU=Alfresco,dc=company,dc=com, I should do that in ldap-synchronization.properties.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is frustrating… I spend so many time in this stupid thing. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Why didnt you help me?!&amp;nbsp; &lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://connect.hyland.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;bye&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 May 2009 13:56:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202761#M155891</guid>
      <dc:creator>luisg</dc:creator>
      <dc:date>2009-05-19T13:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED]Alfresco + Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202762#M155892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Luis&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Found this thread very interesting, however we have e-directory and ldap, but I suppose the query from the Alfresco side to ldap would look the the same …. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The %s@nwu doesn't work ….&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If I have a user ABC, sitting in my ldap in ou=ACTIVE, ou=USERS,o=nwu and I want only the authorized users in cn=ALFRESCO, ou=GROUPS,o=nwu to be authenticated, how would my query from Alfresco look like??&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please help!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 May 2009 13:23:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202762#M155892</guid>
      <dc:creator>itbeb</dc:creator>
      <dc:date>2009-05-20T13:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED]Alfresco + Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202763#M155893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hi itbeb&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;one question… is 'o=nwu' correct? or should be 'ou=nwu'? I dont have a deep knowledge in AD, so I dont know if this is correct!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ATM i did some configurations of Alfresco and AD, and all are workin.Except for the CIFS+AD thing!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See this &lt;/SPAN&gt;&lt;STRONG&gt;ldap-authentication.properties&lt;/STRONG&gt;&lt;SPAN&gt; file I have (workin):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.authentication.userNameFormat=%s@company.com&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Giving this the user just need to give is username to login in Alfresco. If a user is registed as &lt;/SPAN&gt;&lt;STRONG&gt;jack@company.com&lt;/STRONG&gt;&lt;SPAN&gt;, he just need to give &lt;/SPAN&gt;&lt;STRONG&gt;jack&lt;/STRONG&gt;&lt;SPAN&gt; in alfresco login form.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Other thing, check if your &lt;/SPAN&gt;&lt;STRONG&gt;ldap.authentication.java.naming.provider.url&lt;/STRONG&gt;&lt;SPAN&gt; as the right name. This is very important!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.authentication.java.naming.security.authentication = simple&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.authentication.java.naming.security.principal=alfresco&lt;/STRONG&gt;&lt;SPAN&gt; -&amp;gt; 'alfresco' is a user created in AD&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.authentication.java.naming.security.credentials=(pass) &lt;/STRONG&gt;&lt;SPAN&gt; -&amp;gt; pass for user 'alfresco'&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.authentication.escapeCommasInBind=true&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.escapeCommasInUid=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In &lt;/SPAN&gt;&lt;STRONG&gt;ldap.synchronization.properties&lt;/STRONG&gt;&lt;SPAN&gt; i have:&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.personQuery=(objectclass=user)&lt;/STRONG&gt;&lt;SPAN&gt; -&amp;gt; If you see, this was changed from his original value: (objectclass=inetOrgPerson)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.personSearchBase=ou=Users,ou=abc,dc=company,dc=com&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;in you case, you will have:&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.personSearchBase=cn=ALFRESCO,ou=GROUPS,o=nwu,dc=company,dc=com&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.userIdAttributeName=sAMAccountName&lt;/STRONG&gt;&lt;SPAN&gt; - I changed uid to sAMAccountName&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.userFirstNameAttributeName=givenName&lt;/STRONG&gt;&lt;SPAN&gt; - not changed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.userLastNameAttributeName=sn&lt;/STRONG&gt;&lt;SPAN&gt;- not changed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.userEmailAttributeName=mail&lt;/STRONG&gt;&lt;SPAN&gt;- not changed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.userOrganizationalIdAttributeName=o&lt;/STRONG&gt;&lt;SPAN&gt;- not changed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.defaultHomeFolderProvider=userHomesHomeFolderProvider&lt;/STRONG&gt;&lt;SPAN&gt; - changed&amp;nbsp; frompersonalHomeFolderProvider to userHomesHomeFolderProvider to get users home folders in Users Home space&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;ldap.synchronisation.groupQuery=(objectclass=group)&lt;/STRONG&gt;&lt;SPAN&gt; - changed from (objectclass=groupOfNames) to (objectclass=group)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the rest still the default values.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Remember… If you want to access only the user in a specific path (OU=Users, OU=…) you do that in the &lt;/SPAN&gt;&lt;STRONG&gt;ldap.synchronization.properties&lt;/STRONG&gt;&lt;SPAN&gt; file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;see ya&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 18:01:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/solved-alfresco-active-directory/m-p/202763#M155893</guid>
      <dc:creator>luisg</dc:creator>
      <dc:date>2009-06-25T18:01:51Z</dc:date>
    </item>
  </channel>
</rss>

