<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfresco CE 5.0.b SPP AD LDAP Authentication Issues in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-spp-ad-ldap-authentication-issues/m-p/312306#M265436</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've been attempting to implement an Alfresco CE 5.0.b instance on a CentOS 6.6 box authenticating against a Windows Server 2008 AD domain, however I'm encountering issues with the SPP interacting with MS Office 2013 on the clients.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've managed to get Alfresco to sync with the AD servers and have visibility of the AD Security groups &amp;amp; users within the Alfresco web front-end.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue I'm encountering is with the "edit online" functionality, where Office will open and attempt to open the file, however the user is being constantly challenged to provide credentials (which ultimately don't work).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The steps to reproduce this are:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;- Log into Alfresco web gui using AD credentials.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Navigate to SharePoint site (which the user is a manager of).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Access the documents library.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Select a spreadsheet that has been placed into the documents library as a test.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Click on "Edit Online".&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Excel 2013 will open, however will challenge for credentials constantly - before failing (with the AD credentials).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have tried to plug the AD credentials into the Excel 2013 credential challenge for the hostname &amp;lt;alfresco_server_name.domain.co.uk&amp;gt; in the folllowing formats (just as a punt):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;username@domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:username@domain.co.uk" rel="nofollow noopener noreferrer"&gt;username@domain.co.uk&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;domain\username&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;domain.co.uk\username&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;alfresco_server_name&amp;gt;\username&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;username@&amp;lt;alfresco_server_name&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;alfresco_server_name.domain.co.uk&amp;gt;\username&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;username@&amp;lt;alfresco_server_name.domain.co.uk&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;But none of these worked &amp;amp; ultimatley fails with the error "Microsoft Excel cannot access the file '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow noopener noreferrer"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;alfresco_server_name.domain.co.uk&amp;gt;:7070/alfresco/&amp;lt;sitename&amp;gt;/documentLibrary/&amp;lt;filename&amp;gt;'. There are several possible reasons.".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;On the off chance I did provide the Alfresco admin's credentials into the Excel 2013 credential challenge, which allowed me to access &amp;amp; edit the file online within Excel.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below is my alfresco-global.proerties file (which has been sanitized of any internal data):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;###############################&lt;BR /&gt;## Common Alfresco Properties #&lt;BR /&gt;###############################&lt;BR /&gt;&lt;BR /&gt;dir.root=/home/alfresco-5.0.b/alf_data&lt;BR /&gt;&lt;BR /&gt;authentication.chain=alfinst:alfrescoNtlm,ldap1:ldap-ad&lt;BR /&gt;#You can login by bulidin alfresco authentication system and ldap&lt;BR /&gt;&lt;BR /&gt;ntlm.authentication.sso.enabled=true&lt;BR /&gt;&lt;BR /&gt;ldap.authentication.allowGuestLogin=false&lt;BR /&gt;#do not allow guest logon&lt;BR /&gt;&lt;BR /&gt;ldap.authentication.userNameFormat=%s@domain.co.uk&lt;BR /&gt;#your login is the same like user name in windows&lt;BR /&gt;&lt;BR /&gt;ldap.authentication.java.naming.provider.url=ldap://&amp;lt;activedirectoryserver&amp;gt;:389&lt;BR /&gt;#adres of ldap server&lt;BR /&gt;ldap.authentication.defaultAdministratorUserNames=admin&lt;BR /&gt;#users with admin rights&lt;BR /&gt;ldap.synchronization.java.naming.security.principal=_ALFRESCO_SERVICE@domain.co.uk&lt;BR /&gt;#account ldap administrator on your server&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=REMOVED&lt;BR /&gt;ldap.synchronization.groupSearchBase=dc=\domain,dc\=co,dc\=uk&lt;BR /&gt;ldap.synchronization.userSearchBase=dc=\domain,dc\=co,dc\=uk&lt;BR /&gt;&lt;BR /&gt;alfresco.context=alfresco&lt;BR /&gt;alfresco.host=&amp;lt;alfresco_server_name&amp;gt;.domain.co.uk&lt;BR /&gt;alfresco.port=8080&lt;BR /&gt;alfresco.protocol=http&lt;BR /&gt;&lt;BR /&gt;share.context=share&lt;BR /&gt;share.host=&amp;lt;alfresco_server_name&amp;gt;.domain.co.uk&lt;BR /&gt;share.port=8080&lt;BR /&gt;share.protocol=http&lt;BR /&gt;&lt;BR /&gt;### database connection properties ###&lt;BR /&gt;db.driver=org.gjt.mm.mysql.Driver&lt;BR /&gt;db.username=alfresco&lt;BR /&gt;db.password=REMOVED&lt;BR /&gt;db.name=alfresco&lt;BR /&gt;db.url=jdbc:mysql://localhost/alfresco?useUnicode=yes&amp;amp;characterEncoding=UTF-8&lt;BR /&gt;# Note: your database must also be able to accept at least this many connections.&amp;nbsp; Please see your database documentation for instructions on how to configure this.&lt;BR /&gt;db.pool.max=275&lt;BR /&gt;db.pool.validate.query=SELECT 1&lt;BR /&gt;&lt;BR /&gt;# The server mode. Set value here&lt;BR /&gt;# UNKNOWN | TEST | BACKUP | PRODUCTION&lt;BR /&gt;system.serverMode=TEST&lt;BR /&gt;&lt;BR /&gt;### FTP Server Configuration ###&lt;BR /&gt;ftp.port=21&lt;BR /&gt;&lt;BR /&gt;### RMI registry port for JMX ###&lt;BR /&gt;alfresco.rmi.services.port=50500&lt;BR /&gt;&lt;BR /&gt;### External executable locations ###&lt;BR /&gt;ooo.exe=/home/alfresco-5.0.b/libreoffice/program/soffice&lt;BR /&gt;ooo.enabled=true&lt;BR /&gt;ooo.port=8100&lt;BR /&gt;img.root=/home/alfresco-5.0.b/common&lt;BR /&gt;img.dyn=${img.root}/lib&lt;BR /&gt;img.exe=${img.root}/bin/convert&lt;BR /&gt;swf.exe=/home/alfresco-5.0.b/common/bin/pdf2swf&lt;BR /&gt;swf.languagedir=/home/alfresco-5.0.b/common/japanese&lt;BR /&gt;&lt;BR /&gt;jodconverter.enabled=false&lt;BR /&gt;jodconverter.officeHome=/home/alfresco-5.0.b/libreoffice&lt;BR /&gt;jodconverter.portNumbers=8100&lt;BR /&gt;&lt;BR /&gt;### Initial admin password ###&lt;BR /&gt;alfresco_user_store.adminpassword=REMOVED&lt;BR /&gt;&lt;BR /&gt;### E-mail site invitation setting ###&lt;BR /&gt;notification.email.siteinvite=false&lt;BR /&gt;&lt;BR /&gt;### License location ###&lt;BR /&gt;dir.license.external=/home/alfresco-5.0.b&lt;BR /&gt;&lt;BR /&gt;### Solr indexing ###&lt;BR /&gt;index.subsystem.name=solr4&lt;BR /&gt;dir.keystore=${dir.root}/keystore&lt;BR /&gt;solr.port.ssl=8443&lt;BR /&gt;&lt;BR /&gt;### BPM Engine ###&lt;BR /&gt;system.workflow.engine.jbpm.enabled=false&lt;BR /&gt;&lt;BR /&gt;### Allow extended ResultSet processing&lt;BR /&gt;security.anyDenyDenies=false&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Enabling NTLMv1 on the clients and using passthru isn't an option within the environment that this Alfresco instance will be operating within.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any guidance/or any obvious corrections that anybody could provide, would be gratefully received.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Nov 2014 11:21:59 GMT</pubDate>
    <dc:creator>plar</dc:creator>
    <dc:date>2014-11-12T11:21:59Z</dc:date>
    <item>
      <title>Alfresco CE 5.0.b SPP AD LDAP Authentication Issues</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-spp-ad-ldap-authentication-issues/m-p/312306#M265436</link>
      <description>Hi,I've been attempting to implement an Alfresco CE 5.0.b instance on a CentOS 6.6 box authenticating against a Windows Server 2008 AD domain, however I'm encountering issues with the SPP interacting with MS Office 2013 on the clients.I've managed to get Alfresco to sync with the AD servers and have</description>
      <pubDate>Wed, 12 Nov 2014 11:21:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-spp-ad-ldap-authentication-issues/m-p/312306#M265436</guid>
      <dc:creator>plar</dc:creator>
      <dc:date>2014-11-12T11:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco CE 5.0.b SPP AD LDAP Authentication Issues</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-spp-ad-ldap-authentication-issues/m-p/312307#M265437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Did you find any solution, im havind the same problem.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Aug 2015 14:02:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-ce-5-0-b-spp-ad-ldap-authentication-issues/m-p/312307#M265437</guid>
      <dc:creator>javier_vargas</dc:creator>
      <dc:date>2015-08-28T14:02:05Z</dc:date>
    </item>
  </channel>
</rss>

