<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between platform endpoints? in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3209#M1089</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't found any documentation about this so I thought I'd ask a question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I have all this working, I'm just trying to understand it all a bit better)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My aim is to have SSO set up and configured - share is relatively straightforward but I'm trying to understand the detail behind the platform/repo endpoints as the documentation doesn't really cover this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the only URL I need to expose is:&amp;nbsp;/alfresco/s/admin/admin-communitysummary (or /alfresco/s/enterprise/admin)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The information for configuring a proxy&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/5.1/tasks/configure-ssl-prod.html" title="http://docs.alfresco.com/5.1/tasks/configure-ssl-prod.html" rel="nofollow noopener noreferrer"&gt;Configuring SSL for a production environment | Alfresco Documentation&lt;/A&gt;&amp;nbsp;is pretty good here but I think the /alfresco mount point exposes rather more than is necessary these days&lt;/P&gt;&lt;P&gt;I think /alfresco would be better as:&lt;/P&gt;&lt;P&gt;JkMount /alfresco/s/admin alfresco-worker&lt;BR /&gt; JkMount /alfresco/s/admin/* alfresco-worker&lt;BR /&gt;JkMount /alfresco/admin/css/* alfresco-worker&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(For enterprise add /service/enterprise/admin/* and /s/enterprise/admin/* ?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(And if you're using the nice new ootb support tools extension&lt;/P&gt;&lt;P&gt;JkMount /alfresco/s/ootbee/* alfresco-worker&lt;BR /&gt; JkMount /alfresco/ootbee-support-tools/* alfresco-worker&lt;/P&gt;&lt;P&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The implication here is that these, or at least /alfresco/.../admin, are the endpoints that need to be covered by SSO at the alfresco level (have I missed anything?) + the ones for public API access if you want those&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentication mappings in alfresco/WEB-INF/web.xml seem to have changed a fair bit recently&lt;/P&gt;&lt;P&gt;(a clue! - there is a CSRF token filter on&amp;nbsp;/service/enterprise/admin/* and&amp;nbsp;/s/enterprise/admin/*)&lt;/P&gt;&lt;P&gt;There appear to be authentication filters around /wcs and /wcservice, as well as /api, /webdav and /cmisatom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation on configuration the SSO endpoint (incidentally the examples don't even all have the same number of endpoints listed...)&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/community/tasks/auth-alfrescoexternal-sso.html" title="http://docs.alfresco.com/community/tasks/auth-alfrescoexternal-sso.html" rel="nofollow noopener noreferrer"&gt;Configuring Alfresco Share to use an external SSO | Alfresco Documentation&lt;/A&gt;&amp;nbsp;(code doesn't match text...), &lt;A class="link-titled" href="http://docs.alfresco.com/5.2/tasks/share-change-port.html" title="http://docs.alfresco.com/5.2/tasks/share-change-port.html" rel="nofollow noopener noreferrer"&gt;Configuring the Share default port | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&amp;nbsp;and&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/community5.1/tasks/share-change-port.html" title="http://docs.alfresco.com/community5.1/tasks/share-change-port.html" rel="nofollow noopener noreferrer"&gt;Configuring the Share default port | Alfresco Documentation&lt;/A&gt;&amp;nbsp;has for a long time said to use the wcs endpoint in share-custom-config.xml when external auth is being used, however now I believe that the s endpoint is recommended (although it's not entirely clear) e.g.&amp;nbsp;&lt;A class="link-titled" href="https://issues.alfresco.com/jira/browse/ACE-5661" title="https://issues.alfresco.com/jira/browse/ACE-5661" rel="nofollow noopener noreferrer"&gt;[ACE-5661] External authentication Problem with CAS - Alfresco JIRA&lt;/A&gt;&amp;nbsp;(and other issues) see the comment from&amp;nbsp;&lt;B&gt;Kevin Roast&lt;/B&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this is a rather long winded way of asking what is the purpose of the /wcs endpoint and how does it differ from the /s endpoint? (obviously there are authentication filters in front of /wcs)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jan 2017 10:44:14 GMT</pubDate>
    <dc:creator>idwright</dc:creator>
    <dc:date>2017-01-13T10:44:14Z</dc:date>
    <item>
      <title>Difference between platform endpoints?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3209#M1089</link>
      <description>I haven't found any documentation about this so I thought I'd ask a question.(I have all this working, I'm just trying to understand it all a bit better)My aim is to have SSO set up and configured - share is relatively straightforward but I'm trying to understand the detail behind the platform/repo</description>
      <pubDate>Fri, 13 Jan 2017 10:44:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3209#M1089</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2017-01-13T10:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between platform endpoints?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3210#M1090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ian:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same question.&amp;nbsp;First, I&amp;nbsp;agree that Share SSO is quite straightfoward, configuring external auth subsystem and enabling the Remote configuration in Share. For old Alfresco Explorer, we needed to add&amp;nbsp;additional cas client library in /alfresco/WEB-INF/lib and to change web.xml as you commented, which is not necessary for Alfresco 5, except in Admin Console (and maybe for&amp;nbsp;/alfresco/webdav).&lt;/P&gt;&lt;P&gt;On the other hand, I can only say that I have seen&amp;nbsp;the WCS&amp;nbsp;endpoint, when activating&amp;nbsp;Remote config in Alfresco Share configured for an external or NTLM based SSO. I understood&amp;nbsp;that Alfresco Share needed /wcs endpoint to pass NTML challenge for&amp;nbsp;Alfresco Repository Services (in case of AlfrescoNtlm with SSO). I would expect in this case, that once enabled /wcs you can go directly to admin console via /alfresco/wcs instead of /alfresco/s. Maybe it is not the case with an external web SSO like CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2017 14:35:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3210#M1090</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-01-13T14:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between platform endpoints?</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3211#M1091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The /wcs endpoint is essentially the same as the /s endpoint, but only with a different HTTP authentication factory being used during the dispatch to the web script layer. The /s endpoint (actually, the /service endpoint - /s is just an alias) uses a simple authentication factory that only supports HTTP BASIC. /wcs (or to be more precise /wcservice) uses an authentication factory that ties in with the Repository-tier SSO handling and thus is required to be used by Share when enabling SSO there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2017 16:10:28 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/difference-between-platform-endpoints/m-p/3211#M1091</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2017-01-13T16:10:28Z</dc:date>
    </item>
  </channel>
</rss>

