<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AD authentication in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295356#M248486</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a problem setting up Active Directory authentication. I did a setup by the book and it works, I can authenticate with AD, I can synchronize with AD, but what bothers me is that ALL users can authenticate with AD. This is not what I want. I have two organizational units, Teachers and Students. I want only users within Teachers OU to authenticate and others not. If I put a filter on ldap.synchronization.personQuery it's only for synchronization. Only these users are synced with alfresco, but when I try to login as a Student user, I can. Does anyone have a suggestion? Thank you.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 May 2014 11:07:04 GMT</pubDate>
    <dc:creator>zugs</dc:creator>
    <dc:date>2014-05-06T11:07:04Z</dc:date>
    <item>
      <title>AD authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295356#M248486</link>
      <description>Hello,I have a problem setting up Active Directory authentication. I did a setup by the book and it works, I can authenticate with AD, I can synchronize with AD, but what bothers me is that ALL users can authenticate with AD. This is not what I want. I have two organizational units, Teachers and Stu</description>
      <pubDate>Tue, 06 May 2014 11:07:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295356#M248486</guid>
      <dc:creator>zugs</dc:creator>
      <dc:date>2014-05-06T11:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: AD authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295357#M248487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;It seems Alfresco is creating a new user on successful AD authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You should disable create.missing.people property by overriding spring bean for Alfresco 4.2.c or by setting it to false on alfresco-global.properties for Alfresco 4.2.d.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2014 11:30:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295357#M248487</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2014-05-06T11:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: AD authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295358#M248488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;It seems to be working. Thank you very much. Although, I can't say I like this solution, because what if don't want or need synchronization? I just want to authenticate against AD.. Why can't there be a possibility to filter which users you want, which ou or group to look for, like in the sync case?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2014 14:20:26 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295358#M248488</guid>
      <dc:creator>zugs</dc:creator>
      <dc:date>2014-05-06T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: AD authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295359#M248489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Using only AD authentication, you must prepare an LDAP branch on your system containing only Alfresco desired users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Another alternative is to filter users request based on user DN by extending the LDAP subsystem.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The main reason is that no binding user is required for authentication, because of this no filter or lookup can be configured.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 May 2014 10:32:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ad-authentication/m-p/295359#M248489</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2014-05-07T10:32:04Z</dc:date>
    </item>
  </channel>
</rss>

