<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please help with connecting Activiti and Active Directory in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245919#M199049</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello all, long story short, im doing this pilot/test project for a company, and also writing Bachelor's degree on topic "Use of Alfresco Activiti for process reeingineering" at the same time. Problem is, I am catastrophically stuck at this AD problem for the past 1 month.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco is on version 5.0.2.5 and Activiti is on 1.3.3 &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I used "demo setup" from activiti-share-connector-1.3.2, and it is working. If I started a process in activiti, it was shown in Alfresco dashboard too. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Then I configured Active Directory for Alfresco, that worked too. It imported all 1600 users and groups. Configuration file for that is located on this path (and also attached it) &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;C:\Alfresco\Alfresco-5.0.2.5-january\tomcat\webapps\alfresco\WEB-INF\classes\alfresco\extension\subsystems\Authentication\ldap\ldap1\ldap-authentication.properties &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Then I wanted to configure AD on Activiti too. And it is not working with similar settings. Configuration file for that is located on this path (and also attached it) &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;C:\Alfresco\Activiti-1.3.3-january\tomcat\webapps\activiti-app\WEB-INF\classes\META-INF\activiti-app\activiti-ldap.properties &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I also enabled debugging by setting log4j.logger.com.activti.idm.ldap=debug in log4j.properties file. Unfortunately it doesn't provide much information. All it does is it shows this message when we try to log in: &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;09:43:23,392 [http-nio-8080-exec-4] DEBUG com.activti.idm.ldap.auth.ActivitiActiveDirectoryAuthenticationProvider&amp;nbsp; - Authentication for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:luka.bizjak@skb.si" rel="nofollow noopener noreferrer"&gt;luka.bizjak@skb.si&lt;/A&gt;&lt;SPAN&gt; failed:javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1 ] &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;09:43:23,392 [http-nio-8080-exec-4] INFO&amp;nbsp; com.activti.idm.ldap.auth.ActivitiActiveDirectoryAuthenticationProvider&amp;nbsp; - Active Directory authentication failed: Supplied password was invalid &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I believe that Activiti doesn't import users from AD, so problem has to be in importing part. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Also catalina.log and localhost.log don't show any errors at all. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;So can you help please? &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap-authentication.properties file is from Alfresco AD configuration, and that works. Can you create/fix file for Activiti AD configuration out of that Alfresco's working file? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would be eternally grateful, this is the only thing standing between me and my graduation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PS: I only removed "ldap.synchronization.java.naming.security.credentials" so that it is hidden.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PSS: I had to change .properties extension to .txt, so that i could upload ithere. You can simply change it back to .properties if you want &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Feb 2016 08:40:38 GMT</pubDate>
    <dc:creator>bizilux</dc:creator>
    <dc:date>2016-02-05T08:40:38Z</dc:date>
    <item>
      <title>Please help with connecting Activiti and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245919#M199049</link>
      <description>Hello all, long story short, im doing this pilot/test project for a company, and also writing Bachelor's degree on topic "Use of Alfresco Activiti for process reeingineering" at the same time. Problem is, I am catastrophically stuck at this AD problem for the past 1 month.Alfresco is on version 5.0.</description>
      <pubDate>Fri, 05 Feb 2016 08:40:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245919#M199049</guid>
      <dc:creator>bizilux</dc:creator>
      <dc:date>2016-02-05T08:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with connecting Activiti and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245920#M199050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Moved to Enterprise forum.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We've got many customers running AD with Activiti, so I'm sure there is a way to get it working.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I see ldap.authentication.active-directory.enabled=true. I've heard many people have success by NOT using that, and accessing AD as a regular Ldap server (so just use the traditional ldap queries etc).&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Feb 2016 14:38:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245920#M199050</guid>
      <dc:creator>jbarrez</dc:creator>
      <dc:date>2016-02-05T14:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with connecting Activiti and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245921#M199051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello, yes I did find that already, and I tried it a month ago, but no luck.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've also found this bug report which is basically describing exact problem that we have…&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ACTIVITI-225" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ACTIVITI-225&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;this is the interesting bit:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;code&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If Users were anywhere created elsewhere in the domain besides the "CN=Users" it would never authenticate. This can be problematic as enterprise AD will not always have all the users created under "CN=Users, DC=…,DC=…" they may exists else where in the domain.&amp;lt;/code&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Our AD structure is different, it was modified, so we dont have all users under this default AD structure. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please ask one of your guys to take a look at this bug? I am almost certain this is the problem. Afterall, AD is working on Alfresco. And on Activiti it wont even import users.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 10:08:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245921#M199051</guid>
      <dc:creator>bizilux</dc:creator>
      <dc:date>2016-02-09T10:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with connecting Activiti and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245922#M199052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;This issue is specifically about the AD specific properties. In the same issues it also states:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"I could never figure out how to get any of these properties to work, instead I stripped it down to basics and removed all activite-directory properties and it works. It was never the synchronization that was of issue but authentication did not work otherwise."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I checked with the person who created the issue and she confirmed me it was working once she changed the configuration to be a 'regular ldap' instead of an AD one (so simply talking to AD as if it were an LDAP server).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2016 08:51:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245922#M199052</guid>
      <dc:creator>jbarrez</dc:creator>
      <dc:date>2016-02-11T08:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with connecting Activiti and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245923#M199053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;thanks for replying… I was even thinking right now of installing another AD that would be in test environment and not in production, so that i could figure this out &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So if I understand you correctly, you are saying that in documentation, I should just look at "LDAP Example" and not at "Active Directory Example" right?&amp;nbsp; I should just use settings for LDAP examples?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you tell me who was the person who created the issue? I would like to contact him/her for a few more follow up questions… is it Jennie Soria or is she just managing this issue, since she is an employee?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2016 09:10:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245923#M199053</guid>
      <dc:creator>bizilux</dc:creator>
      <dc:date>2016-02-11T09:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Please help with connecting Activiti and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245924#M199054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Indeed, acting like AD is a regular LDAP solved the issue (and I've heard the same before).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Jennie is indeed an Alfresco employee and she created this issue. &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2016 09:58:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/please-help-with-connecting-activiti-and-active-directory/m-p/245924#M199054</guid>
      <dc:creator>jbarrez</dc:creator>
      <dc:date>2016-02-11T09:58:39Z</dc:date>
    </item>
  </channel>
</rss>

