<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco 3, AD NTLM, LDAP Sync Issue in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207966#M161096</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I took that info, out as well as passwords and the Domain of the application server.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Apr 2009 16:56:23 GMT</pubDate>
    <dc:creator>rubicon49bc</dc:creator>
    <dc:date>2009-04-06T16:56:23Z</dc:date>
    <item>
      <title>Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207964#M161094</link>
      <description>I have NTLM Authentication working and I can access the CIFS shares as a user with out a problem. My issue is with LDAP Sync, I can not seem to get it working. When I configure ldap-authentication.properties I can no longer get into Alfresco.[#|2009-04-06T14:22:40.227+0000|INFO|sun-appserver2.1|org.</description>
      <pubDate>Mon, 06 Apr 2009 15:25:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207964#M161094</guid>
      <dc:creator>rubicon49bc</dc:creator>
      <dc:date>2009-04-06T15:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207965#M161095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I think you forgot to specify the IP/DNS of the LDAP-Server:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# The URL to connect to the LDAP server&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.provider.url=ldap://&amp;lt;ip address&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Greetings&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Steffen&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 16:15:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207965#M161095</guid>
      <dc:creator>steffen</dc:creator>
      <dc:date>2009-04-06T16:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207966#M161096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I took that info, out as well as passwords and the Domain of the application server.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 16:56:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207966#M161096</guid>
      <dc:creator>rubicon49bc</dc:creator>
      <dc:date>2009-04-06T16:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207967#M161097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I also tested against an openldap server with no problem, of course I need CIFS so NTLM it needs to be.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 16:57:28 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207967#M161097</guid>
      <dc:creator>rubicon49bc</dc:creator>
      <dc:date>2009-04-06T16:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207968#M161098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have ldap-authenication work and the user accounts sync'd. CIFS will only work in passthru mode, but NTLM users can not log into the CIFS share. So if you use ldap-sync you lose NTLM and so you lose CFIS SSO. Is this correct? If so, how do you manage groups in AD for Alfresco? How do you get all the users in? file-server.xml with Alfresco or enterprise won't work if you are using ldap-auth. So how do you import AD accounts using the ldap-sync?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Apr 2009 20:22:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207968#M161098</guid>
      <dc:creator>rubicon49bc</dc:creator>
      <dc:date>2009-04-06T20:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207969#M161099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;this suggests to me it is not even binding correctly&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;[#|2009-04-06T14:22:49.913+0000|INFO|sun-appserver2.1|org.alfresco.repo.security.authentication.ldap.LDAPInitialDirContextFactoryImpl|_ThreadID=16;_ThreadName=pool-1-thread-8;|LDAP &lt;SPAN style="color:#FF0000;"&gt;server does not fall back to anonymous bind for known principal and invalid credentials at ldap://&amp;lt;ip address&amp;gt;&lt;/SPAN&gt;|#]&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;It probably worked on OpenLDAP because OpenLDAP will anonymously bind until you explicitly forbid it.&amp;nbsp; AD will not anonymously bind till you make it&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;what does your NTLM and File-server configuration look like?&amp;nbsp; The file servers are a bit picky with the NTLM syntax.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;file-server.xml has nothing to do with LDAP sync.&amp;nbsp; you can set the file servers to use pass through to the LDAP but, that wont do anything about the sync.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When you have both NTLM and LDAP enabled.&amp;nbsp; NTLM &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;should&lt;/SPAN&gt;&lt;SPAN&gt; over ride LDAP. Though it sounds like something is a bit funky.&amp;nbsp; Did you change any other authentication files?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;NTLM will give you SSO.&amp;nbsp; LDAP will not.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you only want to use NTLM you will have to manually enter user details (email, phone, etc).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;With Both NTLM and LDAP a user account is created as soon as they log into alfresco.&amp;nbsp; you &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;do not&lt;/SPAN&gt;&lt;SPAN&gt; need to sync as soon as they correctly authenticate they are allowed in&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would not use SYNC for groups because Share creates its own groups and SYNC will do one of two things.&amp;nbsp; It will either delete these groups when Alfresco sees they are not in AD or, Alfresco will only be able to add users to groups.&amp;nbsp;&amp;nbsp;&amp;nbsp; Depending on your network size you may only want to sync once and handle user details and group changes by hand.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;try this…..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;auth file&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.authentication.userNameFormat=%s&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;better safe than sorry with the port&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.authentication.java.naming.provider.url=ldap://&amp;lt;ip address&amp;gt;:389&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;dont know if it counts but mine is caps…i remember caps greif somewhere in here dont know where though&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.authentication.java.naming.security.authentication=SIMPLE&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;again verify capitalization….I think it gave me grief before… this is my capitalization pattern&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.authentication.java.naming.security.principal=CN=Alfresco Ldap,CN=Users,DC=COMPANY,DC=net&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;yours should be valid but this is mine&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.synchronisation.personQuery=(objectclass=user)&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;and the search file&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;again check caps…i would guess it would be more like this.&amp;nbsp; your path here and above dont match even if you did scrub them?&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.synchronisation.personSearchBase=OU=Users,OU=pkmm,DC=PKMM-INC,DC=net&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;this isnt required information in AD have you filled it in.&amp;nbsp; if not 'o' does not exist.&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.synchronisation.userOrganizationalIdAttributeName=o&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;shouldn't matter but i used user&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.synchronisation.personType=user&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Apr 2009 19:14:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207969#M161099</guid>
      <dc:creator>ofrxnz</dc:creator>
      <dc:date>2009-04-10T19:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 3, AD NTLM, LDAP Sync Issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207970#M161100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I will give that a try. I did use :389 in the server address. I wasn't not paying attention to case in the config for the windows configs. I am also running Glassfish so share doesn't work with that. Maybe in the next release.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Matt&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Apr 2009 19:45:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-3-ad-ntlm-ldap-sync-issue/m-p/207970#M161100</guid>
      <dc:creator>rubicon49bc</dc:creator>
      <dc:date>2009-04-21T19:45:38Z</dc:date>
    </item>
  </channel>
</rss>

