<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NTLM passthru, LDAP synchro and user access restriction in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43092#M23406</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I configured a LDAP synchro (Active Directory) in order to copy users from a particular group into Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I also commented the bean &amp;lt;bean id="authenticationComponentImpl"&amp;nbsp; in the ldap-authentication-context.xml file&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I modified the web.xml file to activate the NTLM passthru (in order to allow the access to alfresco without login/password)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;the file ntlm-authentication-context.xml has been left to its default value (no "servers" values, "useLocalServer" set to true)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;A user from the AD group (so which is synchronized) can connect successfuly to alfresco, but it also allows people which are not part of the group to connect to alfresco (the account is then created in Alfresco).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;is it normal ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;How can we restrict the access only to the syncrhonized users ??&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sylvain&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Feb 2007 08:27:27 GMT</pubDate>
    <dc:creator>lascaux</dc:creator>
    <dc:date>2007-02-07T08:27:27Z</dc:date>
    <item>
      <title>NTLM passthru, LDAP synchro and user access restriction</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43092#M23406</link>
      <description>Hi,I configured a LDAP synchro (Active Directory) in order to copy users from a particular group into Alfresco.I also commented the bean &amp;lt;bean id="authenticationComponentImpl"&amp;nbsp; in the ldap-authentication-context.xml fileI modified the web.xml file to activate the NTLM passthru (in order to allow</description>
      <pubDate>Wed, 07 Feb 2007 08:27:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43092#M23406</guid>
      <dc:creator>lascaux</dc:creator>
      <dc:date>2007-02-07T08:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM passthru, LDAP synchro and user access restriction</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43093#M23407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You can turn off the auto creation of people - no one without imported details will be able to log in.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Over-ride the person service bean and change the property createMissingPeople to false.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;!– The person service.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;bean id="personService" class="org.alfresco.repo.security.person.PersonServiceImpl"&amp;gt;&lt;BR /&gt; …….&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="createMissingPeople"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;value&amp;gt;false&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&lt;BR /&gt;…….&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/bean&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2007 14:26:08 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43093#M23407</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2007-02-07T14:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM passthru, LDAP synchro and user access restriction</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43094#M23408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;You can turn off the auto creation of people - no one without imported details will be able to log in.&lt;BR /&gt;&lt;BR /&gt;Over-ride the person service bean and change the property createMissingPeople to false.&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;!– The person service.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;bean id="personService" class="org.alfresco.repo.security.person.PersonServiceImpl"&amp;gt;&lt;BR /&gt; …….&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="createMissingPeople"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;value&amp;gt;false&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&lt;BR /&gt;…….&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/bean&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks Andy,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But where to override this bean ??&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2007 17:17:06 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43094#M23408</guid>
      <dc:creator>lascaux</dc:creator>
      <dc:date>2007-02-07T17:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM passthru, LDAP synchro and user access restriction</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43095#M23409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Take the defintion from authentication-services-context.xml and put it in extensions, somewhere like custom-authentication-services-context.xml.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Then make your changes - this will over-ride the bean defintion. Any file matching *-context.xml will be found in the extensions directory.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Feb 2007 09:57:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ntlm-passthru-ldap-synchro-and-user-access-restriction/m-p/43095#M23409</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2007-02-13T09:57:34Z</dc:date>
    </item>
  </channel>
</rss>

