<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco LDAP-AD Questions in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312028#M265158</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am still stuck on this issue, but have found some more useful info:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/community/concepts/auth-passthru-intro.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/concepts/auth-passthru-intro.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;This method of authentication is much more secure than simple LDAP-based authentication or form-based authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Why is passthru more secure than Active Directory ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For LDAP-AD:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/community/concepts/auth-ldap-props.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/concepts/auth-ldap-props.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;To change to secure logins, do you just change the word: simple to DIGEST-MD5 ? and ports 389 to 636?&amp;nbsp; Is that it???&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now, my question is, what is the best method to use to have secure logins from Active Directory?&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Nov 2014 04:20:22 GMT</pubDate>
    <dc:creator>sab</dc:creator>
    <dc:date>2014-11-12T04:20:22Z</dc:date>
    <item>
      <title>Alfresco LDAP-AD Questions</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312026#M265156</link>
      <description>Hi,I have some questions i hope someone can answer.First, i have 2 Microsoft Active Servers running 2008 on my main network.I also have a separate network with 1 test server: Microsoft Active Server 2008 DC and 1 test server running Ubuntu 14, joined to the test domain using Centrify software and Al</description>
      <pubDate>Tue, 11 Nov 2014 04:15:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312026#M265156</guid>
      <dc:creator>sab</dc:creator>
      <dc:date>2014-11-11T04:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco LDAP-AD Questions</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312027#M265157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have found Some answers myself:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;On encryption:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(about 1/3 the way down)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ldap.authentication.java.naming.security.authentication&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The mechanism used to validate passwords with the LDAP server. Should be one of the standard values documented here or one of the values supported by the LDAP provider. Sun's LDAP provider supports the SASL mechanisms documented here. Recommended values are:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; simple&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the basic LDAP authentication mechanism requiring the username and password to be passed over the wire unencrypted. You may be able to add SSL for secure access; otherwise, only use this for testing. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; DIGEST-MD5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; More secure RFC 2831 Digest Authentication. Note that with Active Directory, this requires your user accounts to be set up with reversible encryption, not the default setting. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ports 389 is non-SSL, and 636 is SSL&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2014 22:13:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312027#M265157</guid>
      <dc:creator>sab</dc:creator>
      <dc:date>2014-11-11T22:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco LDAP-AD Questions</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312028#M265158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am still stuck on this issue, but have found some more useful info:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/community/concepts/auth-passthru-intro.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/concepts/auth-passthru-intro.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;This method of authentication is much more secure than simple LDAP-based authentication or form-based authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Why is passthru more secure than Active Directory ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For LDAP-AD:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/community/concepts/auth-ldap-props.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/concepts/auth-ldap-props.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;To change to secure logins, do you just change the word: simple to DIGEST-MD5 ? and ports 389 to 636?&amp;nbsp; Is that it???&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now, my question is, what is the best method to use to have secure logins from Active Directory?&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2014 04:20:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312028#M265158</guid>
      <dc:creator>sab</dc:creator>
      <dc:date>2014-11-12T04:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco LDAP-AD Questions</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312029#M265159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have been doing more testing and found some results:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) Using Pure LDAP-AD (only), the username + password is sent in PLAIN TEXT&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2) Using passthru + LDAP-AD mixed, only the username is sent in PLAIN TEXT. Passwords are encrypted, but use Weak encryption: NTLM v1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Back to number 1, if i change the port number from 389 &amp;gt; 636, and change simple passwords to DIGEST-MD5, and tick reversible encryption in a user in AD, It does Not work.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Both 1 and 2 can be proven using Wireshark.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;packets that have LDAP will have the password inside and smb packets for the second one will have the password encrypted in the 3rd SMB packet (210 session setup andx request)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;By pure LDAP-AD, i mean following instructions here: &lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/community/tasks/auth-example-oneldap-ad.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/tasks/auth-example-oneldap-ad.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#LDAP" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#LDAP&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;inside global properties file only. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So, does anyone have info on using number 1 with encryption??? or is the only real way is using Kerberos?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 02:09:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312029#M265159</guid>
      <dc:creator>sab</dc:creator>
      <dc:date>2014-11-19T02:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco LDAP-AD Questions</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312030#M265160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Another idea i came across is to add a SSL Cert to tomcat.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.alfresco.com/forum/installation-upgrades-configuration-integration/configuration/change-alfresco-use-ssl-and" rel="nofollow noopener noreferrer"&gt;http://forums.alfresco.com/forum/installation-upgrades-configuration-integration/configuration/change-alfresco-use-ssl-and&lt;/A&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Nov 2014 22:44:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ldap-ad-questions/m-p/312030#M265160</guid>
      <dc:creator>sab</dc:creator>
      <dc:date>2014-11-23T22:44:01Z</dc:date>
    </item>
  </channel>
</rss>

