<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AD and canonical username in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ad-and-canonical-username/m-p/269964#M223094</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello all,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've got Alfresco 4.0.d community successfully authenticating and synchronizing with ActiveDirectory (see config below).&amp;nbsp; I do have one problem however.&amp;nbsp; given that there's a test_user user in AD and given that we can login as test_user@domain and test_user@domain.local, I can login three different ways with the same password.&amp;nbsp; That is, I can login as:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; test_user&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; test_user@domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; test_user@domain.local&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Those are created in alfresco as three different users (with the usernames as above).&amp;nbsp; Is there a way to tell alfresco that the same AD user should map to just one alfresco user?&amp;nbsp; Otherwise, I'm going to have trouble later as users somehow login in more than one way and find that documents they've updated as one user aren't owned by them when they' logged in as a variant n the first user's login? Or that in the second login they aren't in the same groups or don't have access to sharepoint sites they had when logged in as the first user.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;==== config starts ====&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=ldap1:ldap-ad,passthru1&lt;img id="smileytongue" class="emoticon emoticon-smileytongue" src="https://connect.hyland.com/i/smilies/16x16_smiley-tongue.png" alt="Smiley Tongue" title="Smiley Tongue" /&gt;assthru,alfrescoNtlm1:alfrescoNtlm&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;alfrescoNtlm.ntlm.authentication.sso.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;alfrescoNtlm.alfresco.authentication.authenticateCIFS=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.ntlm.authentication.sso.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.passthru.authentication.authenticateCIFS=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.useLocalServer=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.servers=DOMAIN\\111.22.33.1,DOMAIN\\11.22.33.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.authenticateCIFS=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.active=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.active=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.userNameFormat=%s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.provider.url=ldap://111.22.33.3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.defaultAdministratorUserNames=Administrator,admin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.java.naming.security.principal=user@domain.local&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.java.naming.security.credentials=password&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupSearchBase=ou\=Security Groups,ou\=domain,dc\=domain,dc\=local&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userSearchBase=ou\=Users,ou\=domain,dc\=domain,dc\=local&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.authentication=DIGEST-MD5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.personQuery=(givenName\=*)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.defaultHomeFolderProvider=userHomesHomeFolderProvider&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;==== config ends ====&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Many thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Gerald&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Oct 2012 04:21:21 GMT</pubDate>
    <dc:creator>bopolissimus</dc:creator>
    <dc:date>2012-10-10T04:21:21Z</dc:date>
    <item>
      <title>AD and canonical username</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ad-and-canonical-username/m-p/269964#M223094</link>
      <description>Hello all,I've got Alfresco 4.0.d community successfully authenticating and synchronizing with ActiveDirectory (see config below).&amp;nbsp; I do have one problem however.&amp;nbsp; given that there's a test_user user in AD and given that we can login as test_user@domain and test_user@domain.local, I can login three</description>
      <pubDate>Wed, 10 Oct 2012 04:21:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ad-and-canonical-username/m-p/269964#M223094</guid>
      <dc:creator>bopolissimus</dc:creator>
      <dc:date>2012-10-10T04:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: AD and canonical username</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ad-and-canonical-username/m-p/269965#M223095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;After talking to the system administrators, It turns out this isn't an issue.&amp;nbsp; System administrators know about the domain. Users would never login with [username]@[domain1].[domain2], so the problem won't come up.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2012 03:15:47 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ad-and-canonical-username/m-p/269965#M223095</guid>
      <dc:creator>bopolissimus</dc:creator>
      <dc:date>2012-10-15T03:15:47Z</dc:date>
    </item>
  </channel>
</rss>

