<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP (AD) group imports in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ad-group-imports/m-p/251534#M204664</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The directory i need to integrate with has a top level (as far as i'm concerned) group with a load of groups one level below. Among these lower groups are a few that need alfresco access, so there is a sibling group on the same lewer level called 'admin alfresco'. This group has members which are other groups at the same level.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now the problem is that if I set the group search base to be the top level, then I get all groups including ones i don't want. And if i set the search query to then limit the search with memberOf:1.2.840.113556.1.4.1941:CN=admin alfresco, blah blah blah…&amp;nbsp;&amp;nbsp; then the groups imported are properly limited to only those that are members of the admin alfresco group, BUT what gets imported as a group is ANYTHING that matches the query. So I get a nested tree of groups (which is what I want) plus every group individually.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Eg:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;*top level import&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;————*sub1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;————*sub2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/////////————*sub2a&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*sub1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*sub2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*sub 2a&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When what is required is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;*top level import&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;————*sub1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;————*sub2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/////////————*sub2a&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And obviously is I just use memberOf without the LDAP_MATCHING_RULE_IN_CHAIN then i'll only get direct member groups and won't get sub2a (sub2a memberOf sub2 memberOf toplevel)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Does that make sense? and is there a way to resolve this other than completely restructuring the AD ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Many thanks.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jan 2012 12:01:27 GMT</pubDate>
    <dc:creator>aaronshaw</dc:creator>
    <dc:date>2012-01-16T12:01:27Z</dc:date>
    <item>
      <title>LDAP (AD) group imports</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ad-group-imports/m-p/251534#M204664</link>
      <description>Hi.The directory i need to integrate with has a top level (as far as i'm concerned) group with a load of groups one level below. Among these lower groups are a few that need alfresco access, so there is a sibling group on the same lewer level called 'admin alfresco'. This group has members which are</description>
      <pubDate>Mon, 16 Jan 2012 12:01:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-ad-group-imports/m-p/251534#M204664</guid>
      <dc:creator>aaronshaw</dc:creator>
      <dc:date>2012-01-16T12:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP (AD) group imports</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ad-group-imports/m-p/251535#M204665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I just had a further play and it seems that any group that matches the query at all is created. So the memberOf doesn't have to be the chained version.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; So if I say memberOf=aspace | distinguishedName=subspace, it will create a group called aspace, with a group caled subspace alongside it, and then the subspace again within aspace.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 13:27:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-ad-group-imports/m-p/251535#M204665</guid>
      <dc:creator>aaronshaw</dc:creator>
      <dc:date>2012-01-16T13:27:51Z</dc:date>
    </item>
  </channel>
</rss>

