<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understanding Alfresco subsystems for authentication (3.3) in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220631#M173761</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;So every changes have to be done in alfresco-global.properties? I'll try this.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Sep 2010 08:25:59 GMT</pubDate>
    <dc:creator>bnice</dc:creator>
    <dc:date>2010-09-15T08:25:59Z</dc:date>
    <item>
      <title>Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220628#M173758</link>
      <description>Hi,I need to get my fresh Alfresco 3.3 installation to run together with a W2K3 ADS - SSON is not a must, but would be nice to have.I tried to configure Kerberos for that reason with help of the wiki http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Kerberos, but still got some diffic</description>
      <pubDate>Tue, 14 Sep 2010 12:51:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220628#M173758</guid>
      <dc:creator>bnice</dc:creator>
      <dc:date>2010-09-14T12:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220629#M173759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;From my understanding you can:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1) put your properties inside alfresco-global.properties (which is what I have tested with and seems to work fine) &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2) you can make a new directory inside WEB-INF/classes/alfresco/subsystems/Authentication/kerberos/ called kerebos1 and then override.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Spring Beans&lt;BR /&gt;&lt;BR /&gt;For advanced purposes, you can also extend or override the Spring Bean definitions of the subsystem.&lt;BR /&gt;&lt;BR /&gt;If you add a Spring Bean file to your application server's global classpath (e.g. under $TOMCAT_HOME/shared/classes) with a path matching the following pattern you can add to or override the subsystem bean definitions.&lt;BR /&gt;&lt;BR /&gt;alfresco/extension/subsystems/&amp;lt;category&amp;gt;/&amp;lt;type&amp;gt;/&amp;lt;id&amp;gt;/*-context.xml&lt;BR /&gt;&lt;BR /&gt;Here, the ID is the subsystem instance identifier, which will be default for single instance subsystems, or the provided ID for chained subsystems.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;So, for example, suppose your authentication chain looked like this:&lt;BR /&gt;&lt;BR /&gt;authentication.chain=alfrescoNtlm1:alfrescoNtlm,ldap1:ldap&lt;BR /&gt;&lt;BR /&gt;Then you could put bean definition overrides for alfrescoNtlm1 in&lt;BR /&gt;&lt;BR /&gt;alfresco/extension/subsystems/Authentication/alfrescoNtlm/alfrescoNtlm1/custom-context.xml&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Remembering that the default type and ID of non-chained subsystems is default you could put overrides for file server beans in&lt;BR /&gt;&lt;BR /&gt;alfresco/extension/subsystems/fileServers/default/default/custom-file-servers-context.xml&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;*Edit&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After re-reading your question I realized that this really only pertains to your question regarding properties and locations. I thought I have read that everything should at the bare minimum work with Explorer before it works with Share (someone please correct me if I'm wrong).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 15:40:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220629#M173759</guid>
      <dc:creator>rhoefer</dc:creator>
      <dc:date>2010-09-14T15:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220630#M173760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Please don't change anything in the WEB-INF folder.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 08:01:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220630#M173760</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2010-09-15T08:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220631#M173761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;So every changes have to be done in alfresco-global.properties? I'll try this.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 08:25:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220631#M173761</guid>
      <dc:creator>bnice</dc:creator>
      <dc:date>2010-09-15T08:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220632#M173762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I followed this guide&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Kerberos" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Kerberos&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;and I've added the following in the alfresco-global.properties:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;# The default authentication chain&lt;BR /&gt;# To configure external authentication subsystems see:&lt;BR /&gt;# &lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems&lt;/A&gt;&lt;BR /&gt;#————-&lt;BR /&gt;#authentication.chain=alfrescoNtlm1:alfrescoNtlm&lt;BR /&gt;authentication.chain=alfrescoNtlm1:alfrescoNtlm, kerberos:kerberos&lt;BR /&gt;kerberos.authentication.realm=MYDOMAIN.LOCAL&lt;BR /&gt;kerberos.authentication.sso.enabled=false&lt;BR /&gt;kerberos.authentication.authenticateCIFS=true&lt;BR /&gt;kerberos.authentication.user.configEntryName=alfresco&lt;BR /&gt;kerberos.authentication.cifs.configEntryName=alfrescocifs&lt;BR /&gt;kerberos.authentication.http.configEntryName=alfrescohttp&lt;BR /&gt;kerberos.authentication.cifs.password=***&lt;BR /&gt;kerberos.authentication.http.password=***&lt;BR /&gt;kerberos.authentication.defaultAdministratorUserNames=admin&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;But must have missed something - Trying login with domain acounts fails:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;The Remote Server is unreachable, or your credentials were not recognized.&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt;(I translated that from German…)&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 11:46:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220632#M173762</guid>
      <dc:creator>bnice</dc:creator>
      <dc:date>2010-09-15T11:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220633#M173763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I found a hint how to work with the subsystems here: &lt;/SPAN&gt;&lt;A href="http://forums.alfresco.com/en/viewtopic.php?f=9&amp;amp;t=28656" rel="nofollow noopener noreferrer"&gt;http://forums.alfresco.com/en/viewtopic.php?f=9&amp;amp;t=28656&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Now trying to adopt this for my system.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So I copied the files from &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/subsystems/Authentication/…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;to&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;opt/Alfresco/shared/classes/extension/subsystems/Authentication/…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(/ldap-ad/ldap-ad1, /alfrescoNtlm/alfrescoNtlm1, /passthru/passthru1, …)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;where I edited these (when necessary).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Am I correct so far?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My alfresco-global.properties is now only containing&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;authentication.chain=alfrescoNtlm1:alfrescoNtlm,ldap-ad1:ldap-ad&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt;for authentication, I'll later extend this to kerberos&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 12:50:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220633#M173763</guid>
      <dc:creator>bnice</dc:creator>
      <dc:date>2010-09-15T12:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220634#M173764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Found the problem regarding the subsystems:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Was caused by a "File not found"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;tail -f alfresco.log&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt;is always your friend… &lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;Caused by: java.io.FileNotFoundException: &lt;BR /&gt;/opt/Alfresco/tomcat/shared/classes/alfresco/extension/subsystems/Authentication/ldap-ad/ldap-ad1/../common-ldap-context.xml (No such file or directory)&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;The file "common-ldap-context.xml" has to be located under&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;/opt/Alfresco/shared/classes/extension/subsystems/Authentication/ldap-ad&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;respective&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;/opt/Alfresco/shared/classes/extension/subsystems/Authentication/ldap&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;(for non Windows-LDAP)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;At first, I copied it to&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/Alfresco/shared/classes/extension/subsystems/Authentication/ldap-ad&lt;/SPAN&gt;&lt;STRONG&gt;/ldap-ad1&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After correcting that, LDAP was used for authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Share is now running with LDAP-login, Alfresco explorer still has an error, as it is not supporting NTLMv2:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;16:24:13,865 DEBUG [org.alfresco.web.app.servlet.NTLMAuthenticationFilter] Received type3 [Type3:,LM:000000000000000000000000000000000000000000000000,&lt;BR /&gt;NTLM:35fb5be1dba846ea300a95190c2ff33d0101000000000000af8ab392e154cb01578d66ff7ea7475a000000000200060061006c0066000000000000000000,&lt;BR /&gt;Dom:,User:user@mydomain.local,Wks:Workstationname]&lt;BR /&gt;16:24:13,866 ERROR [org.alfresco.web.app.servlet.NTLMAuthenticationFilter] Client Workstationname using NTLMv2 logon, not valid with passthru authentication&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;So, I'll have to use Kerberos for that (please correct me if I'm wrong)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'll stick to this guide &lt;/SPAN&gt;&lt;A href="http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/" rel="nofollow noopener noreferrer"&gt;http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/&lt;/A&gt;&lt;SPAN&gt; for configuring Kerberos.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 14:40:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220634#M173764</guid>
      <dc:creator>bnice</dc:creator>
      <dc:date>2010-09-15T14:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Alfresco subsystems for authentication (3.3)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220635#M173765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Seems to be working now&amp;nbsp; &lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://connect.hyland.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Used authentication chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;authentication.chain=kerberos1:kerberos,ldap-ad1:ldap-ad&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;and configured everything else in the config files for the authentication subsystem.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 15:32:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/understanding-alfresco-subsystems-for-authentication-3-3/m-p/220635#M173765</guid>
      <dc:creator>bnice</dc:creator>
      <dc:date>2010-09-15T15:32:48Z</dc:date>
    </item>
  </channel>
</rss>

