<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfresco Community Version 4.2.c and Active Directory in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288117#M241247</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello allow. I hope everyone is well. I just started to configure Alfresco 4.2.c and trying to integrate it with Active directory and I'm having issues trying to sync the groups and since I am having issues, I can't seem to get everyone over to Alfresco so they can login, etc. So first off here is what I have:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;——————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AD:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Windows 2008 R2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Users: cn=users,dc=company,dc=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Groups: cn=users,dc-company,dc=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco Server:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CentOS 6.4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Version 4.2.c&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;——————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The error I'm receiving:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2013-06-10 13:03:26,773&amp;nbsp; WARN&amp;nbsp; [sync.ldap.LDAPUserRegistry] [localhost-startStop-1] Failed to resolve member of group 'DnsAdmins' with distinguished name: CN=XXXXX XXXXX,OU=Users,OU=Information Systems,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;——————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here is an LDIF of the group:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;dn: CN=DnsAdmins,CN=Users,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;objectClass: top&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;objectClass: group&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cn: DnsAdmins&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;description: DNS Administrators Group&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Users,OU=Information Systems,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx,OU=Users,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=dnsuser dnsuser,CN=Users,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Users,OU=Information Systems,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Users,OU=Information Systems,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Users,OU=Information Systems,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Users,OU=Information Systems,OU=City,DC=company ,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Information Systems,OU=Users,OU=City,DC=company,DC =com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;member: CN=xxx xxx,OU=Users,OU=Information Systems,OU=City,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;distinguishedName: CN=DnsAdmins,CN=Users,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;instanceType: 4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;whenCreated: xxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;whenChanged: xxxxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;uSNCreated: 21016&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;uSNChanged: 54848339&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;name: DnsAdmins&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;objectGUID:: xxxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;objectSid:: xxxxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sAMAccountName: DnsAdmins&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sAMAccountType: 268435456&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;groupType: -2147483646&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=company,DC=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dSCorePropagationData: 20110228172317.0Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dSCorePropagationData: 20110228172311.0Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dSCorePropagationData: 20110228171706.0Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dSCorePropagationData: 20110228171633.0Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dSCorePropagationData: 16010714223649.0Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;——————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is my config file I'm using: &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;TOP&amp;gt;/alfresco-4.2.c/tomcat/shared/classes/alfresco-global.properties&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;### LDAP ###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=passthru1&lt;img id="smileytongue" class="emoticon emoticon-smileytongue" src="https://connect.hyland.com/i/smilies/16x16_smiley-tongue.png" alt="Smiley Tongue" title="Smiley Tongue" /&gt;assthru,ldap1:ldap&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.sso.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.allowGuestLogin=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.authenticateCIFS=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.authenticateFTP=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.servers=XX.X.X.13,XX.X.X.14&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.domain=company.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.useLocalServer=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.defaultAdministratorUserNames=privuser&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.connectTimeout=5000&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.offlineCheckInterval=300&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.protocolOrder=TCPIP,NETBIOS&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.active=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.authentication=simple&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.userNameFormat=%s&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.allowGuestLogin=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.provider.url=ldap://XX.X.X.13:389&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.escapeCommasInBind=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.escapeCommasInUid=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.active=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldap.synchronization.java.naming.security.principal=privuser@company.com" rel="nofollow noopener noreferrer"&gt;ldap.synchronization.java.naming.security.principal=privuser@company.com&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.java.naming.security.credentials=secretpw&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.queryBatchSize=1000&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupDifferentialQuery=(&amp;amp;(objectclass=nogroup)(!(modifyTimestamp&amp;lt;\={0})))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.personQuery=(&amp;amp;(objectclass=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=512))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.personDifferentialQuery=(&amp;amp; (objectclass=user)(!(modifyTimestamp&amp;lt;\={0})))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupQuery=(objectclass\=group)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupSearchBase=cn\=users,dc=company,dc=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userSearchBase=cn\=users,dc=company,dc=com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.modifyTimestampAttributeName=modifyTimestamp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.timestampFormat=yyyyMMddHHmmss'.0Z'&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userIdAttributeName=sAMAccountName&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userFirstNameAttributeName=givenName&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userLastNameAttributeName=sn&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userEmailAttributeName=mail&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userOrganizationalIdAttributeName=msExchALObjectVersion&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.defaultHomeFolderProvider=userHomesHomeFolderProvider&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupIdAttributeName=cn&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupType=Nogroup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.personType=user&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.groupMemberAttributeName=member&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;synchronization.synchronizeChangesOnly=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;——————————————————–&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I know it has something to do with the group members and references into other groups/OU's. But I have read so many blogs, forums and such on this subject and I'm just so totally confused now. I'm not an LDAP expert and the search strings and such confuse me so much. I am also not a windows admin. Just a lonely UNIX admin. I'm just looking for someone who would want to share their working configuration. Anyone?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;(Of cousre I had to clean up the output as to not put anything out there about the internals of my company)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Glen&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Jun 2013 20:28:29 GMT</pubDate>
    <dc:creator>glenc2004</dc:creator>
    <dc:date>2013-06-10T20:28:29Z</dc:date>
    <item>
      <title>Alfresco Community Version 4.2.c and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288117#M241247</link>
      <description>Hello allow. I hope everyone is well. I just started to configure Alfresco 4.2.c and trying to integrate it with Active directory and I'm having issues trying to sync the groups and since I am having issues, I can't seem to get everyone over to Alfresco so they can login, etc. So first off here is w</description>
      <pubDate>Mon, 10 Jun 2013 20:28:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288117#M241247</guid>
      <dc:creator>glenc2004</dc:creator>
      <dc:date>2013-06-10T20:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Community Version 4.2.c and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288118#M241248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi, Glen.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You write ldap.synchronization.groupDifferentialQuery=(&amp;amp;(objectclass=nogroup)blah blah blah…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I think you must prepend backslashes to every "=" operator in LDAP queries. Also, shouldn' t it read objectClass\=group? "nogroup"?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;(I do know, it is case insensitive but I always use mixed case naming style.)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"not an LDAP expert, not a windows admin"… Nice description, the same here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope that helps.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 09:58:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288118#M241248</guid>
      <dc:creator>albertocabello</dc:creator>
      <dc:date>2013-06-21T09:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Community Version 4.2.c and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288119#M241249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am having the same problem where I cannot sync AD users information in Alfresco. Were you able to figure out your problem? My configs look similar to yours too&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 05:40:55 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288119#M241249</guid>
      <dc:creator>pete109</dc:creator>
      <dc:date>2013-11-20T05:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Community Version 4.2.c and Active Directory</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288120#M241250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The "Failed to resolve member" error may not be the source of your problem.&amp;nbsp; I have logs filled with that error, but yet LDAP authentication is working just fine…&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:21:25 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-community-version-4-2-c-and-active-directory/m-p/288120#M241250</guid>
      <dc:creator>sscbrian</dc:creator>
      <dc:date>2015-07-07T19:21:25Z</dc:date>
    </item>
  </channel>
</rss>

