<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I know LDAP Sync is working? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240470#M193600</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am actually working in 3.2.&amp;nbsp; How does it work there?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Jun 2009 17:51:08 GMT</pubDate>
    <dc:creator>jriker1</dc:creator>
    <dc:date>2009-06-19T17:51:08Z</dc:date>
    <item>
      <title>How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240467#M193597</link>
      <description>So I have LDAP working, and have configured my Sync xml file.&amp;nbsp; How do I know it's working?&amp;nbsp; If I go into the admin screen and add a user, what should I see?&amp;nbsp; Do I enter their network ID and the rest fills in from AD?&amp;nbsp; Any info would be appreciated.JR</description>
      <pubDate>Fri, 19 Jun 2009 16:29:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240467#M193597</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2009-06-19T16:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240468#M193598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Until v3.2, LDAP sync is done through a scheduled job. You can only edit cron expressions to change the frequency with which Alfresco queries users and groups and brings them in to its own repository.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You shouldn't be adding users manually via the admin screen. They are all added during a sync operation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://wiki.alfresco.com/wiki/Enterprise_Security_and_Authentication_Configuration#LDAP_Synchronization" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Enterprise_Security_and_Authentication_Configuration#LDAP_Synchronization&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Or if you try the latest and greatest nightly build, the synchronization capability is actually integrated into the authentication chain and users and their groups can actually be pulled in 'on demand' as you are probably expecting.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm guessing you're going to ask me about that&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So suppose I have this in my alfresco-global.properties (see &lt;/SPAN&gt;&lt;A href="http://wiki.alfresco.com/wiki/Developer_Runtime_Configuration" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Developer_Runtime_Configuration&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=myldap1:ldap,myldap2:ldap&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i.e. I have a chain of two LDAP servers&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then, assuming you have configured the properties for myldap1 and myldap2 (look at other forum posts for how to do this - about to publish on Wiki) the preconfigured synchronization service will kick in as soon as a user is successfully authenticated and retrieve the users and groups added since the last sync. 'Collision' resolution is done using the directory's position in the chain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Note we are still working on ironing out some AD compatibility problems in the nightly build- it currently works with openldap.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2009 16:46:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240468#M193598</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-06-19T16:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240469#M193599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Should I bother trying to get LDAP sync working with AD until there's a new nightly build?&amp;nbsp; I installed the June 18th build and it's not going so well.&amp;nbsp; I had almost everything working with LDAP and NTLM on the June 1 or 2nd build except SSO on Share.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2009 16:57:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240469#M193599</guid>
      <dc:creator>jtp</dc:creator>
      <dc:date>2009-06-19T16:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240470#M193600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am actually working in 3.2.&amp;nbsp; How does it work there?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2009 17:51:08 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240470#M193600</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2009-06-19T17:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240471#M193601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;If a user is successfully authenticated via LDAP but a person object doesn't yet exist for them in Alfresco, the sync service is called to do a differential sync (fetch all users and groups modified since it last synced) and the person object is created automatically.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2009 18:43:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240471#M193601</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-06-19T18:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240472#M193602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;If a user is successfully authenticated via LDAP but a person object doesn't yet exist for them in Alfresco, the sync service is called to do a differential sync (fetch all users and groups modified since it last synced) and the person object is created automatically.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;So I'm assuming this is automatic.&amp;nbsp; Is there something I can enable in log4g to check if the sync piece is running or has run?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2009 18:45:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240472#M193602</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2009-06-19T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240473#M193603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;With the default log settings you would see this in alfresco.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:56,575 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Synchronizing users and groups with user registry 'lap1'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:56,575 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Retrieving users changed since 18-Jun-2009 13:45:34 from user registry 'AUTH.EXT.lap1'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:56,966 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'dward'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:56,981 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'hippo'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:56,997 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'fullname'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,012 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'walrus'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,028 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'platypus'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,044 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'emu'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,059 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Creating user 'koala'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,403 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Updating user 'kangaroo'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,419 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Creating user 'hippo2'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,669 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Retrieving groups changed since 18-Jun-2009 13:30:59 from user registry 'AUTH.EXT.lap1'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,716 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] Finished synchronizing users and groups with user registry 'AUTH.EXT.lap1'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:44:57,716 INFO&amp;nbsp; [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] 9 user(s) and 3 group(s) processed&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2009 18:49:12 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240473#M193603</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-06-19T18:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240474#M193604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the info.&amp;nbsp; I now have LDAP sync working however have tried adding some custom attributes to the sync pull.&amp;nbsp; Not sure that it is working.&amp;nbsp; Is there any way to make the output more verbose to see the properties that are being pulled from AD for each user?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 13:46:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240474#M193604</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2009-06-25T13:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240475#M193605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm afraid we don't log at the attribute level, but see my response to your "Synchronization questions" thread on attribute mapping. We may consider making the attribute map a 'composite property' one day so that it would be fully controllable via alfresco-global.properties (see the Subsystems Wiki).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 14:23:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240475#M193605</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-06-25T14:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240476#M193606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I was able to get my attributes to pull so all is good there.&amp;nbsp; Now to try and figure out why thru Share my personal account doesn't show up in the people search but in the Alfresco client it does.&amp;nbsp; I am listed in the properties file as an admin, however if I manually pull up my account it shows all my LDAP details I pulled so know I'm physically in there.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 18:31:13 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240476#M193606</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2009-06-25T18:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240477#M193607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;FYI in the next nightly build you should find AD sync + auth is working and supports differential sync (only pull in changes since last sync) when a new user is successfully authenticated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We've also created a new authentication subsystem type called ldap-ad that has some more useful defaults preconfigured for Active Directory.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We found that if you use a userNameFormat that matches the userPrincipalName (UPN) of your users (these seem to be &amp;lt;sAMAccountName&amp;gt;@&amp;lt;domain.dns&amp;gt;) you can get authentication and sync working in tandem&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.userNameFormat=%s@domain.dns&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.authentication=simple&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.java.naming.security.principal=alfresco@domain.dns&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userIdAttributeName=sAMAccountName&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;use DIGEST-MD5 instead of simple if your user passwords are stored with reversible encryption, but this is not the default and passwords would have to be reset.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Alternatively, chain the passthru subsystem so that authentication is performed more securely.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 19:21:43 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240477#M193607</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-06-25T19:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240478#M193608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have everything working now however due to some waiting for my domain groups to store valid users, have tried synching up a couple people manually by hard coding them one at a time in my ldap-ad property file under ldap.synchronization.userSearchBase=&amp;nbsp; Problem is after it syncs up the first user, when I change the name of the user in this field and restart Alfresco it doesn't find the next user that I put in there.&amp;nbsp; I think this is because it may be looking for changes since last start and technically that user existed last time it checked.&amp;nbsp; Is there a way to force Alfresco on start to sync up finding the user irregardless of if they existed before as they may have been in the AD last check but are not in Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 19:06:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240478#M193608</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2009-08-24T19:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I know LDAP Sync is working?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240479#M193609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Only the scheduled sync job will do a full re-sync. By default it runs every 24 hours, but you can change this by editing&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;synchronization.import.cron&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This page explains the cron format in use&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.opensymphony.com/quartz/wikidocs/TutorialLesson6.html" rel="nofollow noopener noreferrer"&gt;http://www.opensymphony.com/quartz/wikidocs/TutorialLesson6.html&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 11:24:55 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-do-i-know-ldap-sync-is-working/m-p/240479#M193609</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-25T11:24:55Z</dc:date>
    </item>
  </channel>
</rss>

