<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP + SSL in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18599#M8505</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;From &lt;/SPAN&gt;&lt;A href="http://java.sun.com/j2se/1.3/docs/guide/jndi/jndi-ldap-gl.html" rel="nofollow noopener noreferrer"&gt;http://java.sun.com/j2se/1.3/docs/guide/jndi/jndi-ldap-gl.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;java.naming.security.protocol &lt;BR /&gt;The value of this property is a string that specifies the security protocol for the provider to use. The following value is defined for this property: &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;ssl &lt;BR /&gt;use Secure Sockets Layer version 3.0. &lt;BR /&gt;If this property is set to ssl, the provider must use SSL sockets, or throw ConfigurationException if it is unable to do so. In addition to the value listed above, a provider may support other security protocols. However, such provider-specific protocols might not be supported by all providers. If this property is set to a security protocol that the provider does not recognize or support, it should throw ConfigurationException. &lt;BR /&gt;&lt;BR /&gt;If the&amp;nbsp; java.naming.ldap.factory.socket&amp;nbsp; property is set, then the socket factory identified by that property must create sockets that are appropriate for this protocol setting. For example, if the security protocol is set to ssl, then the socket factory must create SSL-compliant sockets. &lt;BR /&gt;&lt;BR /&gt;If this property is not set then the default is to use no security protocol. &lt;BR /&gt;&lt;BR /&gt;As a developer of the LDAP provider, you should be aware that using SSL to connect to a server on a port that is not listening for SSL connections causes the socket to hang. Similarly, using a plain socket to connect to a server that is listening for SSL connections also leads to hanging. This is a characteristic of the protocol that some implementations may choose to correct but is not otherwise required to do so. The provider's documentation, however, should describe this behavior to its users. See SSL for information on how to use SSL. &lt;BR /&gt;&lt;BR /&gt;For example: &lt;BR /&gt;&lt;BR /&gt;env.put(Context.SECURITY_PROTOCOL, "ssl");&lt;BR /&gt;specifies that SSL-compliant sockets be used to communicate with the server.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Set the java.naming.security.protocol&amp;nbsp; property on bean&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt; &amp;lt;bean id="ldapInitialDirContextFactory" class="org.alfresco.repo.security.authentication.ldap.LDAPInitialDirContextFactoryImpl"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="initialDirContextEnvironment"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;map&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry key="java.naming.security.protocol"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;value&amp;gt;ssl&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Use simple authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then you need to find the certificates:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://java.sun.com/products/jsse/doc/guide/API_users_guide.html" rel="nofollow noopener noreferrer"&gt;http://java.sun.com/products/jsse/doc/guide/API_users_guide.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Describes this in detail.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You need to set up a trust store for you certificates, put the appropriate certificates in and then tell java where to look.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;java -Djavax.net.ssl.trustStore=MyCacertsFile&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am not sure if this can be set in the ldapInitialDirContextFactory bean or&amp;nbsp; if this has to go on the java command line. There is no other way that I can think of to set system properties.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When this is done - the default SSL implementation should find the appropriate certificates to make the connection.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;SSL is a bit of a pain as always &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 May 2006 11:15:12 GMT</pubDate>
    <dc:creator>andy</dc:creator>
    <dc:date>2006-05-05T11:15:12Z</dc:date>
    <item>
      <title>LDAP + SSL</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18596#M8502</link>
      <description>Hi,I configured successfully Alfresco (1.2.0 Enterprise version on Linux) to use LDAP simple authentication.I wish to add SSL. Replacing ldap://myopenldap.comp.be:389 by ldaps://myopenldap.comp.be:636 in ldap-authentication-context.xml is not enough.Can you help me ?On the same system, the command l</description>
      <pubDate>Thu, 04 May 2006 12:51:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18596#M8502</guid>
      <dc:creator>france</dc:creator>
      <dc:date>2006-05-04T12:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP + SSL</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18597#M8503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You need to do some work creating, storing and finding certificates.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have not set up ssl for LDAP but know it is often used.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;There is at least one group I know of who have it up and going.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The following resources should point you in the right direction.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.sun.com/blueprints/0602/816-5203-10.pdf" rel="nofollow noopener noreferrer"&gt;http://www.sun.com/blueprints/0602/816-5203-10.pdf&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.phptr.com/articles/article.asp?p=28710&amp;amp;rl=1" rel="nofollow noopener noreferrer"&gt;http://www.phptr.com/articles/article.asp?p=28710&amp;amp;rl=1&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;321051" rel="nofollow noopener noreferrer"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;321051&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.openldap.org/doc/admin23/tls.html" rel="nofollow noopener noreferrer"&gt;http://www.openldap.org/doc/admin23/tls.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://java.sun.com/j2se/1.4.2/docs/guide/security/jsse/JSSERefGuide.html#HowSSLWorks" rel="nofollow noopener noreferrer"&gt;http://java.sun.com/j2se/1.4.2/docs/guide/security/jsse/JSSERefGuide.html#HowSSLWorks&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Your test is probably finding the correct certificate or you are not connecting to the SSL port.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.openldap.org/software/man.cgi?query=ldapsearch&amp;amp;apropos=0&amp;amp;sektion=0&amp;amp;manpath=OpenLDAP+2.3-Release&amp;amp;format=html" rel="nofollow noopener noreferrer"&gt;http://www.openldap.org/software/man.cgi?query=ldapsearch&amp;amp;apropos=0&amp;amp;sektion=0&amp;amp;manpath=OpenLDAP+2.3-Release&amp;amp;format=html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would suggest you set the port on the ldap uri on the -H option.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2006 15:15:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18597#M8503</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-05-04T15:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP + SSL</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18598#M8504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Andy,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry, my question was perhaps not so clear.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here is the current situation:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. LDAP + SSL works between my linux client and my OpenLDAP server&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(correct server certificate, correct port 636)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2. LDAP authentication works within Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. LDAP authentication + SSL does NOT work within Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What do I have to do within Alfresco to be able to use SSL for the &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;LDAP authentication ? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; France&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 May 2006 09:45:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18598#M8504</guid>
      <dc:creator>france</dc:creator>
      <dc:date>2006-05-05T09:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP + SSL</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18599#M8505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;From &lt;/SPAN&gt;&lt;A href="http://java.sun.com/j2se/1.3/docs/guide/jndi/jndi-ldap-gl.html" rel="nofollow noopener noreferrer"&gt;http://java.sun.com/j2se/1.3/docs/guide/jndi/jndi-ldap-gl.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;java.naming.security.protocol &lt;BR /&gt;The value of this property is a string that specifies the security protocol for the provider to use. The following value is defined for this property: &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;ssl &lt;BR /&gt;use Secure Sockets Layer version 3.0. &lt;BR /&gt;If this property is set to ssl, the provider must use SSL sockets, or throw ConfigurationException if it is unable to do so. In addition to the value listed above, a provider may support other security protocols. However, such provider-specific protocols might not be supported by all providers. If this property is set to a security protocol that the provider does not recognize or support, it should throw ConfigurationException. &lt;BR /&gt;&lt;BR /&gt;If the&amp;nbsp; java.naming.ldap.factory.socket&amp;nbsp; property is set, then the socket factory identified by that property must create sockets that are appropriate for this protocol setting. For example, if the security protocol is set to ssl, then the socket factory must create SSL-compliant sockets. &lt;BR /&gt;&lt;BR /&gt;If this property is not set then the default is to use no security protocol. &lt;BR /&gt;&lt;BR /&gt;As a developer of the LDAP provider, you should be aware that using SSL to connect to a server on a port that is not listening for SSL connections causes the socket to hang. Similarly, using a plain socket to connect to a server that is listening for SSL connections also leads to hanging. This is a characteristic of the protocol that some implementations may choose to correct but is not otherwise required to do so. The provider's documentation, however, should describe this behavior to its users. See SSL for information on how to use SSL. &lt;BR /&gt;&lt;BR /&gt;For example: &lt;BR /&gt;&lt;BR /&gt;env.put(Context.SECURITY_PROTOCOL, "ssl");&lt;BR /&gt;specifies that SSL-compliant sockets be used to communicate with the server.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Set the java.naming.security.protocol&amp;nbsp; property on bean&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt; &amp;lt;bean id="ldapInitialDirContextFactory" class="org.alfresco.repo.security.authentication.ldap.LDAPInitialDirContextFactoryImpl"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="initialDirContextEnvironment"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;map&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry key="java.naming.security.protocol"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;value&amp;gt;ssl&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Use simple authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then you need to find the certificates:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://java.sun.com/products/jsse/doc/guide/API_users_guide.html" rel="nofollow noopener noreferrer"&gt;http://java.sun.com/products/jsse/doc/guide/API_users_guide.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Describes this in detail.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You need to set up a trust store for you certificates, put the appropriate certificates in and then tell java where to look.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;java -Djavax.net.ssl.trustStore=MyCacertsFile&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am not sure if this can be set in the ldapInitialDirContextFactory bean or&amp;nbsp; if this has to go on the java command line. There is no other way that I can think of to set system properties.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When this is done - the default SSL implementation should find the appropriate certificates to make the connection.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;SSL is a bit of a pain as always &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope this helps&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 May 2006 11:15:12 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-ssl/m-p/18599#M8505</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-05-05T11:15:12Z</dc:date>
    </item>
  </channel>
</rss>

