<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP Sync against large Active Directory groups in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244519#M197649</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello All,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We're using Alfresco 3.2r here and are running into a problem synchronizing against large groups served up by active directory. If a group has more than 1500 members (on versions after win2000), AD wants to serve up the member list in a paged manner (see &lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/aa367017%28VS.85%29.aspx" rel="nofollow noopener noreferrer"&gt;http://msdn.microsoft.com/en-us/library/aa367017%28VS.85%29.aspx&lt;/A&gt;&lt;SPAN&gt;). Alfresco doesn't seem to support this, and our large groups are coming up empty. We have no problem synchronizing the users themselves or populating groups with less than 1500 members.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So my question is, does Alfresco support the AD member;range style paging on the group members attribute? It seems to me that would be a common requirement and there must be some bit of configuration we just haven't turned up yet. If it isn't supported, does anyone have any idea how we might work around this – it's a crucial feature for us. Searching the forums turns up nothing about this, so I am really hoping we have just overlooked something here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Dec 2009 21:25:30 GMT</pubDate>
    <dc:creator>sburke2</dc:creator>
    <dc:date>2009-12-01T21:25:30Z</dc:date>
    <item>
      <title>LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244519#M197649</link>
      <description>Hello All,We're using Alfresco 3.2r here and are running into a problem synchronizing against large groups served up by active directory. If a group has more than 1500 members (on versions after win2000), AD wants to serve up the member list in a paged manner (see http://msdn.microsoft.com/en-us/lib</description>
      <pubDate>Tue, 01 Dec 2009 21:25:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244519#M197649</guid>
      <dc:creator>sburke2</dc:creator>
      <dc:date>2009-12-01T21:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244520#M197650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Still haven't found a solution to this.&amp;nbsp; I'm finding it hard to believe that Alfresco does not support this setup – surely there are plenty of groups out there backing Alfresco with AD where the groups have more than 1500 members?&amp;nbsp; If it works for you (or not) please let me know.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Dec 2009 14:34:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244520#M197650</guid>
      <dc:creator>sburke2</dc:creator>
      <dc:date>2009-12-10T14:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244521#M197651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Alfresco does support this. The default setting for the ldap-ad subsystem in v3.2 is a page size of 1000. So not a problem. Just use v3.2.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Dec 2009 15:04:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244521#M197651</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-12-10T15:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244522#M197652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;It's controlled by ldap.synchronization.queryBatchSize&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Configuration_2" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Configuration_2&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Dec 2009 15:06:12 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244522#M197652</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-12-10T15:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244523#M197653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the reply.&amp;nbsp; We're using 3.2(r) here and I have looked at the queryBatchSize setting.&amp;nbsp; From my understanding this setting is used to limit the results of, for example, the personQuery used to synchronize users.&amp;nbsp; Our personQuery looks like:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ldap.synchronization.personQuery=(&amp;amp;(objectClass=user) (memberOf=CN=Employees,OU=Groups,DC=XXX,DC=XXX,DC=XXX) (cn=*))&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;and it works great; all of the members of our Employees group (about 4000) get synced just fine.&amp;nbsp; Furthermore, our group query works fine – all of our groups get synchronized over and all groups which have &amp;lt; 1500 members have their members set correctly.&amp;nbsp; The trouble is that groups with over 1500 members come up empty (have no members at all).&amp;nbsp; I thought this might have something to do with the way AD serves up multi-valued attributes (see &lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/aa367017%28VS.85%29.aspx" rel="nofollow noopener noreferrer"&gt;http://msdn.microsoft.com/en-us/library/aa367017%28VS.85%29.aspx&lt;/A&gt;&lt;SPAN&gt;); I'm not sure queryBatchSize would have any effect on this.&amp;nbsp; I take it AD's paging of multi-valued attributes (the ;range) is non-standard?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Oh, here is a post where someone using a name service resolver against AD is experiencing the same problem.&amp;nbsp; &lt;/SPAN&gt;&lt;A href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476454" rel="nofollow noopener noreferrer"&gt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476454&lt;/A&gt;&lt;SPAN&gt; .&amp;nbsp; I know the software is unrelated, but the behavior he is experiencing looks the same to me.&amp;nbsp; In that case, libnss was not coded to handle AD's paging of multivalued attributes.&amp;nbsp; To me it looks very much like Alfresco is running into the same problem.&amp;nbsp; I hope I am wrong and that there is a simple solution that I'm overlooking.&amp;nbsp; What do you think?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Dec 2009 15:46:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244523#M197653</guid>
      <dc:creator>sburke2</dc:creator>
      <dc:date>2009-12-10T15:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244524#M197654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the link. This is news to us. We are using RFC 2696 paged results to overcome the limit on the number of individual results returned by a search. But we were not aware that AD also limits the number of values returned for a multi-valued attribute. Luckily there is an example of doing this in Java here&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.sun.com/thread.jspa?threadID=578347" rel="nofollow noopener noreferrer"&gt;http://forums.sun.com/thread.jspa?threadID=578347&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have logged this bug and hope to fix it soon&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ETHREEOH-3770" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ETHREEOH-3770&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Dec 2009 16:24:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244524#M197654</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-12-10T16:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Sync against large Active Directory groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244525#M197655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;FYI this is now fixed on HEAD.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2010 08:57:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-sync-against-large-active-directory-groups/m-p/244525#M197655</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2010-01-19T08:57:39Z</dc:date>
    </item>
  </channel>
</rss>

