<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use Alfresco to Manage users, AD for Authentication in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308817#M261947</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can authenticate against Active Directory but manage the users locally in Alfresco. The only relevant constraint is on the user name which must obviously be identical.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Sep 2016 14:33:28 GMT</pubDate>
    <dc:creator>afaust</dc:creator>
    <dc:date>2016-09-26T14:33:28Z</dc:date>
    <item>
      <title>Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308816#M261946</link>
      <description>We are currently using Activity Directory to synchronize and authenticate users to Alfresco. We keep having random synchronization issues when adding new users, sometimes takes up to 2 weeks for them to show up, but others added afterwards show up on our 20 minute synch schedule as expected. New gro</description>
      <pubDate>Thu, 22 Sep 2016 15:08:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308816#M261946</guid>
      <dc:creator>hsturner</dc:creator>
      <dc:date>2016-09-22T15:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308817#M261947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can authenticate against Active Directory but manage the users locally in Alfresco. The only relevant constraint is on the user name which must obviously be identical.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 14:33:28 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308817#M261947</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-09-26T14:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308818#M261948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do I setup this up?&amp;nbsp;Do I just need to turn off synchronization in the ldap-ad-authentication.properties files? Do I need to set up Kerberos?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 14:45:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308818#M261948</guid>
      <dc:creator>hsturner</dc:creator>
      <dc:date>2016-09-26T14:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308819#M261949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You just disable synchronization and make sure you have alfrescoNtlm in your authentication chain after LDAP-AD. alfrescoNtlm is needed to allow you to create local users and the order in the chain guarantees that LDAP-AD has a chance to authenticate a user first before a locally stored (dummy) password is checked. Unfortunately you must assigne a password to locally created users even in your case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 14:51:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308819#M261949</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-09-26T14:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308820#M261950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That helps a lot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple of&amp;nbsp;related question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Does the password for the local alfresco user have to be the same as the password that is in AD or can I use a generic password?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am guessing that if for some reason the AD server is down, that alfresco with authenticate the user using the password in local profile.&amp;nbsp; I know this is a security issue and I will make our corporate security team aware of that so they can decide if we are going to use this authentication model.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Do&amp;nbsp;you know if we keep the same user names for the users for the local profile that is in the ad profile that they will retain ownership of their current documents, or do I have to figure out some script to change owners of the documents to their local profile?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 15:02:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308820#M261950</guid>
      <dc:creator>hsturner</dc:creator>
      <dc:date>2016-09-26T15:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308821#M261951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) Correct, if AD is down Alfresco will fall back to the local password. If it is not the same then login will oviously fail - also, if the user enters the incorrect AD password then Alfresco can still authenticate. So by setting a different password you effectively have two "valid" ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) As long as user names stay the same they will retain ownership and permissions. Even if you temporarily delete users and re-create them with identical names will this be the case, as deleting ownership and permissions would be such an expensive operation that deleting a user could take hours or days on larger systems - so it isn't actually done at all until a user operation starts to edit those.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 15:07:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308821#M261951</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-09-26T15:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308822#M261952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Axel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing issue with user synchronization. Before we created users in the AD and added to Alfresco group for login. But now we are facing issue related to user login. If we create a new user on the AD it will not able to log in on Alfresco. We want to create users locally on Alfresco but new user option in Admin console is disabled. Could you please help with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pratiksha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Oct 2017 07:15:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308822#M261952</guid>
      <dc:creator>pratu9</dc:creator>
      <dc:date>2017-10-06T07:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Use Alfresco to Manage users, AD for Authentication</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308823#M261953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As long as you have alfrescoNtlm enabled in the authentication chain, you should be able to create any user as a local user. That button is only grayed out if alfrescoNtlm is not enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Oct 2017 17:40:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/use-alfresco-to-manage-users-ad-for-authentication/m-p/308823#M261953</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-10-06T17:40:16Z</dc:date>
    </item>
  </channel>
</rss>

