<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication CIFS using LDAP in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309687#M262817</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I can login to share using ldap user &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;but unable login ldap user to cifs use smb:\\X.X.X.X\alfresco log show as below.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[security.sync.ChainingUserRegistrySynchronizer] [AlfJLANWorker11] Synchronization,Category=directory,id1=ldap1,id2=1 Group Analysis: Commencing batch of 0 entries&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[security.sync.ChainingUserRegistrySynchronizer] [AlfJLANWorker11] 0 user(s) and 0 group(s) processed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;log show below is the schedule sync&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[security.sync.ChainingUserRegistrySynchronizer] [DefaultScheduler_Worker-10] Synchronization,Category=directory,id1=ldap1,id2=1 Group Analysis: Completed batch of 3 entries&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[security.sync.ChainingUserRegistrySynchronizer] [DefaultScheduler_Worker-6] 2 user(s) and 3 group(s) processed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Nov 2015 09:09:44 GMT</pubDate>
    <dc:creator>nshong</dc:creator>
    <dc:date>2015-11-06T09:09:44Z</dc:date>
    <item>
      <title>Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309687#M262817</link>
      <description>I can login to share using ldap user but unable login ldap user to cifs use smb:\\X.X.X.X\alfresco log show as below.[security.sync.ChainingUserRegistrySynchronizer] [AlfJLANWorker11] Synchronization,Category=directory,id1=ldap1,id2=1 Group Analysis: Commencing batch of 0 entries[security.sync.Chain</description>
      <pubDate>Fri, 06 Nov 2015 09:09:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309687#M262817</guid>
      <dc:creator>nshong</dc:creator>
      <dc:date>2015-11-06T09:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309688#M262818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Although Authentication could be via LDAP, Sync is a different process from authentication.&amp;nbsp;&amp;nbsp; Your log file extract above is not relevant, expect to show you are syncing something.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What is important is your authentication configuration.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And unfortunatly SMB authentication can be complicated due to an old obsolete authentication mechanism called NTLM. &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2015 10:09:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309688#M262818</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2015-11-06T10:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309689#M262819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;any different [security.sync.ChainingUserRegistrySynchronizer][AlfJLANWorker] vs [security.sync.ChainingUserRegistrySynchronizer] [DefaultScheduler_Worker] , do it read the same ldap-authentication.properties file?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Nov 2015 02:22:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309689#M262819</guid>
      <dc:creator>nshong</dc:creator>
      <dc:date>2015-11-11T02:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309690#M262820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you mean it's hard or 'impossible' to chain alfresco native NTLM with ldap?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've similar problem.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When try accessing \\server.name\alfresco, only internal user (registered through Alfresco user mgmt) could access that CIFS shared folder. Exported LDAP users (I used samba) will always fail, repeated pop-up window login.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What's the correct guidance combining native Alfresco NTLM and ldap?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've read this documentation [1] but still confused &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://connect.hyland.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[bayu]&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[1] &lt;/SPAN&gt;&lt;A href="http://docs.alfresco.com/4.1/concepts/auth-subsystem-types.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/4.1/concepts/auth-subsystem-types.html&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Nov 2015 18:14:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309690#M262820</guid>
      <dc:creator>billydekid</dc:creator>
      <dc:date>2015-11-18T18:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309691#M262821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I'm stuck with CIFS authentication too.&amp;nbsp; This is 5.0.d on ubuntu 14.04 x64.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I can get internal CIFS working (see step 1 below).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I can get LDAP sync to my AD's DC, so that I can authenticate through the share interface for both internal and external users (see step 2 below).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But when I then configure the passthru for CIFS authentication, internal users can no longer authenticate (which is expected, since I turned it off), but LDAP users also cannot authenticate, and all I get in tomcat's catalina.log is "&amp;lt;TIMESTAMP&amp;gt;&amp;nbsp; ERROR [auth.cifs.PassthruCifsAuthenticator] [AlfJLANWorker21] org.alfresco.jlan.smb.SMBException: Invalid parameter".&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;For the purposes of documentation, I'm going to pretend my AD domain is "TEST-TEST", with IP domain "test-test.local", and my server is testalfresco.test-test.local with IP address 10.10.1.20&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) internal CIFS is easy enough.&amp;nbsp; Just need to do:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;filesystem.name=Alfresco&lt;BR /&gt;cifs.enabled=true&lt;BR /&gt;cifs.serverName=testalfresco&lt;BR /&gt;cifs.domain=&lt;BR /&gt;cifs.broadcast=10.255.255.255&lt;BR /&gt;cifs.bindto=10.10.1.20&lt;BR /&gt;cifs.disableNativeCode=false&lt;BR /&gt;cifs.hostannounce=true&lt;BR /&gt;ftp.enable=false&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Then from a test system, "sudo mount -t cifs -o user=admin //10.10.1.20/Alfresco/sites /usr/share/testMount", type in the Alfresco admin password and it will mount the sites folder to /usr/share/testMount.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2) Next I do an LDAP sync with my AD's DC.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;For this, had to configure the alfresco/extensions/subsystems/Authentication/ldap/ldap1/ldap-ad-authentication.properties file (copied the original from the alfresco-repository-5.0.d.jar file).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Main changes:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;ldap.authentication.active=false&lt;BR /&gt;ldap.authentication.allowGuestLogin=false&lt;BR /&gt;ldap.authentication.userNameFormat=%s&lt;BR /&gt;ldap.authentication.java.naming.provider.url=ldap://10.10.1.20:389&lt;BR /&gt;ldap.authentication.defaultAdministratorUserNames=Administrator&lt;BR /&gt;ldap.synchronization.java.naming.security.principal=non-admin-user@test-test.local&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=thepassword&lt;BR /&gt;# sync all active users and groups from the entire AD tree&lt;BR /&gt;ldap.synchronization.groupSearchBase=dc\=test-test,dc\=local&lt;BR /&gt;ldap.synchronization.userSearchBase=dc\=test-test,dc\=local &lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then, added to the authentication chain in alfresco-properties:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;authentication.chain=alfrescoNtlm1:alfrescoNtlm,ldap1:ldap-ad&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;After an alfresco service restart, I can see users and groups synchronized, and can browse/search LDAP users in Admin Tools/ Users, and Groups.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now, I add the passthru for LDAP authentication (but not CIFS yet)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Configure /alfresco/extension/subsystems/Authentication/passthru/passthru1/passthru-authentication.properties (again, copied the original from the alfresco-repository-5.0.d.jar file).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Main changes:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;passthru.authentication.useLocalServer=false&lt;BR /&gt;passthru.authentication.domain=&lt;BR /&gt;passthru.authentication.servers=TEST-TEST\\10.10.1.200,10.10.1.200 # DC's IP address&lt;BR /&gt;passthru.authentication.guestAccess=false&lt;BR /&gt;passthru.authentication.defaultAdministratorUserNames=administrator&lt;BR /&gt;passthru.authentication.connectTimeout=5000&lt;BR /&gt;passthru.authentication.offlineCheckInterval=300&lt;BR /&gt;passthru.authentication.protocolOrder=TCPIP,NetBIOS&lt;BR /&gt;passthru.authentication.authenticateCIFS=false&lt;BR /&gt;passthru.authentication.authenticateFTP=true&lt;BR /&gt;passthru.authentication.sessionCleanup=true&lt;BR /&gt;passthru.authentication.broadcastMask=&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And added to the authentication chain:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;authentication.chain=alfrescoNtlm1:alfrescoNtlm,passthru1:passthru,ldap1:ldap-ad&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After an alfresco service restart, I tested that I can login to the share interface with both internal and LDAP users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Currently, CIFS for internal users is working, but not for LDAP users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3) Following instructions found in &lt;/SPAN&gt;&lt;A href="https://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Example_1:_Advanced_AD_Chain" rel="nofollow noopener noreferrer"&gt;https://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Example_1:_Advanced_AD_Chain&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i)deactivate SSO in order to activate chained password-based login alfrescoNtlm1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ntlm.authentication.sso.enabled=false &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;alfresco.authentication.authenticateCIFS=false &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ii) target CIFS at passthru1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ntlm.authentication.sso.enabled=false &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;passthru.authentication.authenticateCIFS=true &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;iii)target synchronization (but not authentication) at ldap1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.active=false &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.synchronization.active=true &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Note1 in that link also says that I can only have either alfresco or passthru's authenticateCIFS=true, so I will expect that I can only have either internal or LDAP users be able to use CIFS, not both at the same time.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So the main changes now are:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;# you can set this in alfresco-global.properties, but I made a copy of &lt;BR /&gt;# /alfresco/extension/subsystems/Authentication/passthru/passthru1/passthru-authentication.properties&lt;BR /&gt;# from the alfresco-repository-5.0.d.jar file, and made changes in there instead&lt;BR /&gt;alfresco.authentication.authenticateCIFS=false&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;# in passthru1/passthru-authentication.properties&lt;BR /&gt;passthru.authentication.authenticateCIFS=true&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;# in ldap1/ldap-ad-authentication.properties&lt;BR /&gt;ldap.authentication.active=false # already done in step (2)&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After an alfresco service restart, I can still login to the share interface with both internal and LDAP users, however now CIFS has stopped working for internal (expected) and sadly doesn't work for LDAP users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"sudo mount -t cifs -o user=non-admin-user,domain=TEST-TEST //10.10.1.20/Alfresco/sites /usr/share/testMount"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;just gives me an error like this in catalina.out: "TIMESTAMP&amp;nbsp; ERROR [auth.cifs.PassthruCifsAuthenticator] [AlfJLANWorker21] org.alfresco.jlan.smb.SMBException: Invalid parameter"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I tried to debug further by changing some parameters in /opt/alfresco-5.0.d/tomcat/webapps/alfresco/WEB-INF/classes/log4j.properties, but nothing else extra appears in the catalina.out file other than the above error about invalid parameter:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;# CIFS server debugging&lt;BR /&gt;#log4j.logger.org.alfresco.smb.protocol=error&lt;BR /&gt;log4j.logger.org.alfresco.smb.protocol=debug&lt;BR /&gt;log4j.logger.org.alfresco.smb.protocol.auth=debug&lt;BR /&gt;log4j.logger.org.alfresco.acegi=debug&lt;BR /&gt;# passthru debug&lt;BR /&gt;log4j.logger.org.alfresco.passthru.auth=debug&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I checked with wireshark from the client side (IP=10.10.1.40) that the parameters sent for the domain login are correct, and I do see something like this:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10.10.1.40&amp;nbsp;&amp;nbsp;&amp;nbsp;10.10.1.20&amp;nbsp;&amp;nbsp;&amp;nbsp;SMB&amp;nbsp;&amp;nbsp;&amp;nbsp;384&amp;nbsp;&amp;nbsp;&amp;nbsp;Session Setup AndX Request, User: TEST-TEST\non-admin-user&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I thought this would be relatively simple, and for Alfresco internal users it is, but despite numerous hits in google for how people have done it (including this very useful site: &lt;/SPAN&gt;&lt;A href="https://andoylang.wordpress.com/2010/07/20/alfresco-with-cifs/" rel="nofollow noopener noreferrer"&gt;https://andoylang.wordpress.com/2010/07/20/alfresco-with-cifs/&lt;/A&gt;&lt;SPAN&gt;), I am at a loss for why this is not working in my test environment.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Anybody have any other suggestions?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2015 08:30:47 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309691#M262821</guid>
      <dc:creator>xarope</dc:creator>
      <dc:date>2015-12-21T08:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309692#M262822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I am trying to configure 5.0d Community on CENTOS 7 work with CIFS.&amp;nbsp; I am using Kerberos as the authentication method.&amp;nbsp; I have Kerberos working fine for Share.&amp;nbsp; I have followed the instructions on docs.alfresco to do the configuration.&amp;nbsp; Now I am stuck.&amp;nbsp; When I check the Audit logs from the Active Directory DC I find that for CIFS, Alfresco is trying to authenicate to AD to get a kerberos token with the username "admin". With Share it Authenticates with HTTP/teamdocs.team.local. I have no idea where it is getting "admin" from.&amp;nbsp; Do you guys have any ideas?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Andrew&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Dec 2015 14:01:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309692#M262822</guid>
      <dc:creator>andrew_hegerty</dc:creator>
      <dc:date>2015-12-30T14:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication CIFS using LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309693#M262823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can u share the code please.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Feb 2018 18:23:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/authentication-cifs-using-ldap/m-p/309693#M262823</guid>
      <dc:creator>nileshyadav326</dc:creator>
      <dc:date>2018-02-15T18:23:23Z</dc:date>
    </item>
  </channel>
</rss>

