<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sync-ing users in multiple AD directory trees in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/sync-ing-users-in-multiple-ad-directory-trees/m-p/293621#M246751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have been able to sync Active Directory Users and Groups to Alfresco, but there is a sub tree of test user accounts outside of the main directory tree that we would like to use for development and testing that I cannot sync. I could expand the search to an even greater scope, but this would sync way too much data. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is it possible to sync users, groups from different Base OU's in Active Directory? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For Example…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The Real Users live here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;DN: CN=Users,OU=Corporate,DC=myco,DC=net&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The Test Users live here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;DN: OU=Service Accounts,OU=Corporate,DC=myco,DC=net&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My naive assumption is that in order to sync from 2 different sub trees, the userSearchBase in the ldap-ad-authentication.properties file would look like this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.userSearchBase=OU\=Service Accounts,OU\=Users,OU\=Corporate,DC\=wgenhq,DC\=net&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But the Service Accounts don't come across the wire.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The only subtle difference is that the Real Users have a userAccountControl Number = 512, which is the AD Default. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;… while the Service Accounts have a userAccountControl Number = 66048&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and when I changed the following parameters to the Service Account userAccountControl Number…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# The query to select all objects that represent the users to import.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.personQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=66048))&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# The query to select objects that represent the users to import that have changed since a certain time.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.personDifferentialQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=66408)(!(whenChanged&amp;lt;\={0})))&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Nothing happened.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So, is it possible to have Alfresco read from different parts of AD, and if so, how would I configure this?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance for any assistance you can give me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;~jj&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Jun 2013 20:51:40 GMT</pubDate>
    <dc:creator>jbecker-amplify</dc:creator>
    <dc:date>2013-06-28T20:51:40Z</dc:date>
    <item>
      <title>Sync-ing users in multiple AD directory trees</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sync-ing-users-in-multiple-ad-directory-trees/m-p/293621#M246751</link>
      <description>Hello,I have been able to sync Active Directory Users and Groups to Alfresco, but there is a sub tree of test user accounts outside of the main directory tree that we would like to use for development and testing that I cannot sync. I could expand the search to an even greater scope, but this would</description>
      <pubDate>Fri, 28 Jun 2013 20:51:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sync-ing-users-in-multiple-ad-directory-trees/m-p/293621#M246751</guid>
      <dc:creator>jbecker-amplify</dc:creator>
      <dc:date>2013-06-28T20:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sync-ing users in multiple AD directory trees</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sync-ing-users-in-multiple-ad-directory-trees/m-p/293622#M246752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I think you can do this with two separate authenticaton subsystems.&amp;nbsp;&amp;nbsp; The first one is your regular users and groups the second one is for your test users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There are details on the wiki of how to configure subsystems, and the authentication chain.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 21:26:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sync-ing-users-in-multiple-ad-directory-trees/m-p/293622#M246752</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2013-06-28T21:26:52Z</dc:date>
    </item>
  </channel>
</rss>

