<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic md5-digest authetication and openldap in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/md5-digest-authetication-and-openldap/m-p/272236#M225366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have followed the wiki to setup authentication via ldap.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the relevant section in my tomcat/shared/classes/alfresco-global.properties reads:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# The default authentication chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# To configure external authentication subsystems see:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;# &lt;/SPAN&gt;&lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;#————-&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#authentication.chain=alfrescoNtlm1:alfrescoNtlm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=ldap1:ldap,alfrescoNtlm1:alfrescoNtlm&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ntlm.authentication.sso.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ntlm.authentication.authenticateCIFS=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# LDAP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.active=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.active=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.authentication=DIGEST-MD5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.userNameFormat=%s&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.provider.url=ldap://127.0.0.1:389&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#ldap.authentication.java.naming.provider.url=ldaps://127.0.0.1:636&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication fails with "Unable to login - unknown username/password."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;alfresco.log show no entry, when followed with tail -f&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;tcpdump shows the following conversation:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;0….`………&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;DIGEST-MD50…..a..&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;……SASL(0): successful result: …nonce="9FNZhZzKL/bK4gp0p0w8zDm4d+5wPSON+gvRj4VA/0Q=",realm="&amp;lt;obscured-FQDN-of-server&amp;gt;",qop="auth,auth-int,auth-conf",cipher="rc4-40,rc4-56,rc4,des,3des",maxbuf=65536,charset=utf-8,algorithm=md5-sess0..,…`..%……….&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;DIGEST-MD5….charset=utf-8,username="graylion",realm="&amp;lt;obscured-FQDN-of-server&amp;gt;",nonce="9FNZhZzKL/bK4gp0p0w8zDm4d+5wPSON+gvRj4VA/0Q=",nc=00000001,cnonce="OS6PHN4gmvJLXurtScwftI5ybn7tX2KqTt++fi+F",digest-uri="ldap/127.0.0.1",maxbuf=65536,response=e45bf289ac2786cd10f173714ed2c63d,qop=auth0&amp;lt;…a7&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;.1…0SASL(-13): user not found: no secret in database&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;my sasl and ldap setup is fully functional and successfully authenticates users for cyrus, apache and postfix.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;any ideas?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Jun 2011 19:12:50 GMT</pubDate>
    <dc:creator>graylion</dc:creator>
    <dc:date>2011-06-01T19:12:50Z</dc:date>
    <item>
      <title>md5-digest authetication and openldap</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/md5-digest-authetication-and-openldap/m-p/272236#M225366</link>
      <description>HiI have followed the wiki to setup authentication via ldap.the relevant section in my tomcat/shared/classes/alfresco-global.properties reads:## The default authentication chain# To configure external authentication subsystems see:# http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#——</description>
      <pubDate>Wed, 01 Jun 2011 19:12:50 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/md5-digest-authetication-and-openldap/m-p/272236#M225366</guid>
      <dc:creator>graylion</dc:creator>
      <dc:date>2011-06-01T19:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: md5-digest authetication and openldap</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/md5-digest-authetication-and-openldap/m-p/272237#M225367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;If not already done, try to configure your AD server to get reversible encryption for password.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If it still doesn't work, comments here might be insightful:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ETHREEOH-2556" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ETHREEOH-2556&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For example try to &lt;/SPAN&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;configure ldap.authentication.userNameFormat using the UPN format&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt;and maybe try &lt;/SPAN&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Using FQDN in the ldap.authentication.java.naming.provider.url variable&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Sincerely,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Scouil&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;EDIT: You should definitely try to change ldap.authentication.userNameFormat. As stated here &lt;/SPAN&gt;&lt;A href="http://forums.alfresco.com/en/viewtopic.php?t=3156" rel="nofollow noopener noreferrer"&gt;http://forums.alfresco.com/en/viewtopic.php?t=3156&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;The value you enter here has to be listed in the serverPrincipalName attribute of your domain controller. Things like localhost will most likely not work&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt; It's an old post and might have changed since but…well… try it!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 06:32:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/md5-digest-authetication-and-openldap/m-p/272237#M225367</guid>
      <dc:creator>scouil</dc:creator>
      <dc:date>2011-07-05T06:32:27Z</dc:date>
    </item>
  </channel>
</rss>

