<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP + ActiveDirectory Configuration problems in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-activedirectory-configuration-problems/m-p/45066#M24992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In ldapInitialDirContextFactory you have configured this for digest authentication but are providing a DN base uid for the user used to import. What is required will depend on your configuration and LDAP server. I have always set this up to use a simple uid (for example in open ldap). You should use a simple ldap browser client to confirm what is required here. Also, in authenticationComponentImpl userNameFormat is set to sAMAccountName=%s. This is probably just %s to pass through the uid typed in by the user to the LDAP digest auth stack. Again, you need to confirm this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Note, you can use NTLM authentication and also use LDAP to pull in users and groups. The LDAP sync does not rely on the authentication component, only ldapInitialDirContextFactory. Ldap authentication relies on ldapInitialDirContextFactory and updates the uid and password as required rather then using the default in the xml.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For AD, NTLM auth and ldap auth will be broadly similar.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It sounds like CIFS is configured to go direct to your AD server using Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you wnat SSO from the client then you need to use NTLM (v1 enabled on the client). If you want to authenticate against AD you could use LDAP, NTLM or JAAS flavours of the authentication component. So you could stick with what you had and just add LDAP import of users and groups.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Nov 2006 11:25:15 GMT</pubDate>
    <dc:creator>andy</dc:creator>
    <dc:date>2006-11-24T11:25:15Z</dc:date>
    <item>
      <title>LDAP + ActiveDirectory Configuration problems</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-activedirectory-configuration-problems/m-p/45065#M24991</link>
      <description>I am running alfresco 1.4.0 beta.So far, I make alfresco to authenticate users against AD by generating theNTLM configuration from ntlm-authentication-context.xml.sample. Now I intend to import/synchronize the groups/users information from ADinto alfresco system.What I did includes: (1) As I think N</description>
      <pubDate>Mon, 06 Nov 2006 10:46:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-activedirectory-configuration-problems/m-p/45065#M24991</guid>
      <dc:creator>hfrank</dc:creator>
      <dc:date>2006-11-06T10:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP + ActiveDirectory Configuration problems</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-activedirectory-configuration-problems/m-p/45066#M24992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In ldapInitialDirContextFactory you have configured this for digest authentication but are providing a DN base uid for the user used to import. What is required will depend on your configuration and LDAP server. I have always set this up to use a simple uid (for example in open ldap). You should use a simple ldap browser client to confirm what is required here. Also, in authenticationComponentImpl userNameFormat is set to sAMAccountName=%s. This is probably just %s to pass through the uid typed in by the user to the LDAP digest auth stack. Again, you need to confirm this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Note, you can use NTLM authentication and also use LDAP to pull in users and groups. The LDAP sync does not rely on the authentication component, only ldapInitialDirContextFactory. Ldap authentication relies on ldapInitialDirContextFactory and updates the uid and password as required rather then using the default in the xml.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For AD, NTLM auth and ldap auth will be broadly similar.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It sounds like CIFS is configured to go direct to your AD server using Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you wnat SSO from the client then you need to use NTLM (v1 enabled on the client). If you want to authenticate against AD you could use LDAP, NTLM or JAAS flavours of the authentication component. So you could stick with what you had and just add LDAP import of users and groups.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Nov 2006 11:25:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-activedirectory-configuration-problems/m-p/45066#M24992</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-11-24T11:25:15Z</dc:date>
    </item>
  </channel>
</rss>

