<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco Authorization Server in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31289#M13260</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.alfresco.com/people/mromano" rel="nofollow noopener noreferrer"&gt;Mario Romano&lt;/A&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.alfresco.com/people/kgastaldo" rel="nofollow noopener noreferrer"&gt;Kristen Gastaldo&lt;/A&gt;&amp;nbsp;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.alfresco.com/people/fcorti" rel="nofollow noopener noreferrer"&gt;Francesco Corti&lt;/A&gt;&amp;nbsp;Any chance this thread could get some insight from Alfresco folks or a pointer to somewhere else where these items are covered?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 May 2017 13:26:32 GMT</pubDate>
    <dc:creator>binduwavell</dc:creator>
    <dc:date>2017-05-09T13:26:32Z</dc:date>
    <item>
      <title>Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31287#M13258</link>
      <description>I noticed this bullet point for the upcoming release of alfresco-js-api 1.3.0:Add support Alfresco Authorization server js-apiThis is then backed up by this commit:Release 1.3.0 by eromano · Pull Request #208 · Alfresco/alfresco-js-api · GitHub&amp;nbsp;&amp;nbsp;From these, I discovered this&amp;nbsp;documentation&lt;IMG id="smileysurprised" class="emoticon emoticon-smileysurprised" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-surprised.png" alt="Smiley Surprised" title="Smiley Surprised" /&gt;Auth 2 SS</description>
      <pubDate>Fri, 31 Mar 2017 04:08:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31287#M13258</guid>
      <dc:creator>binduwavell</dc:creator>
      <dc:date>2017-03-31T04:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31288#M13259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would certainly welcome some work in this area for content services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My observations are that non standard auth is pretty fragile, and probably not well understood, at the moment as it seems to break with most new releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made some comments in this JIRA&amp;nbsp;&lt;A class="link-titled" href="https://issues.alfresco.com/jira/browse/ALF-21848" title="https://issues.alfresco.com/jira/browse/ALF-21848" rel="nofollow noopener noreferrer"&gt;[ALF-21848] Improve support for third party SSO via web-fragment.xml - Alfresco JIRA&lt;/A&gt;&amp;nbsp; but this is only tweaking the current implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AFAIK the current SAML work is for Enterprise only, I haven't heard about any OAuth work but that would be interesting as I think I might be able to set CAS up as an OAuth provider and could retire my CAS work which would be nice!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be an expectation that basic-auth will be used e.g. by mobile clients, ADF, CMIS and if SSO is introduced to the platform end points then that will be broken (rumour has it the internal instance can't be accessed via mobile)&lt;/P&gt;&lt;P&gt;(I have a nasty hack in my CAS amps to get around this)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think that SSO has been properly considered in the context of ADF - I expect to be able to make it work but haven't had the time yet - from what I understand it's relying heavily on using a ticket after basic-auth, which isn't great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting comment&amp;nbsp;&lt;/P&gt;&lt;UL class="" style="color: #58595b; background-color: #ffffff; margin: 20px 0px;"&gt;&lt;LI class="" style="margin-bottom: 20px;"&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;The server needs to be used in conjunction with the LDAP sync for users from the Alfresco Content Services LDAP directory.&lt;/BLOCKQUOTE&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I can't see why this would be the case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2017 09:01:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31288#M13259</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2017-04-06T09:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31289#M13260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.alfresco.com/people/mromano" rel="nofollow noopener noreferrer"&gt;Mario Romano&lt;/A&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.alfresco.com/people/kgastaldo" rel="nofollow noopener noreferrer"&gt;Kristen Gastaldo&lt;/A&gt;&amp;nbsp;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.alfresco.com/people/fcorti" rel="nofollow noopener noreferrer"&gt;Francesco Corti&lt;/A&gt;&amp;nbsp;Any chance this thread could get some insight from Alfresco folks or a pointer to somewhere else where these items are covered?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 May 2017 13:26:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31289#M13260</guid>
      <dc:creator>binduwavell</dc:creator>
      <dc:date>2017-05-09T13:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31290#M13261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this one snuck by, as discussions don't seem to get the coverage questions do. I'll send this to a few employees for some insight.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 May 2017 13:46:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31290#M13261</guid>
      <dc:creator>kgastaldo</dc:creator>
      <dc:date>2017-05-09T13:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31291#M13262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I spoke, briefly, to Brian Remington about SSO at BeeCon and apparently SSO is somewhere near the top of his list.&lt;/P&gt;&lt;P&gt;However I got the impression that it's more to do with SSO between content services and process services than external SSO providers. (external SSO is a very strong requirement for me)&lt;/P&gt;&lt;P&gt;OpenID connect did come up as part of the discussion so it's possible external authentication providers will also be included.&lt;/P&gt;&lt;P&gt;We did, again very briefly, talk about the problems with external authorization (what you can do/group membership) as well as authentication (who you are) - for the record I'm happy with authentication and using the LDAP sync for the overlapping authorization (despite some problems with it e.g. &lt;A class="link-titled" href="https://issues.alfresco.com/jira/browse/ACE-5679" title="https://issues.alfresco.com/jira/browse/ACE-5679" rel="nofollow noopener noreferrer"&gt;[ACE-5679] Indirect groups no longer work as site manager - Alfresco JIRA&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 May 2017 14:06:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31291#M13262</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2017-05-09T14:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31292#M13263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have some additional information on the topic?&lt;/P&gt;&lt;P&gt;We would like to use oauth2 with Content Services in Community Edition.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jul 2017 09:46:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31292#M13263</guid>
      <dc:creator>pkhazzaka</dc:creator>
      <dc:date>2017-07-27T09:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Authorization Server</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31293#M13264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I was asked a few times to respond but didn't get it done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This discussion brings together a few separate engineering projects:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A short-term effort to make OAuth work with APS to meet an immediate customer requirement. This was recently delivered, and encompasses most of Bindu's questions. &lt;A __default_attr="165480" __jive_macro_name="user" _jive_internal="true" data-id="165480" data-objecttype="3" data-type="person" href="https://community.alfresco.com/people/eugenio_romano" rel="nofollow noopener noreferrer"&gt;&lt;/A&gt;‌ would have to answer the specific questions.&lt;/LI&gt;&lt;LI&gt;An immediate effort to provide an API and SSO gateway so that users of the ADF can access the various components of the Alfresco Digital Business Platform without having to change endpoints and re-authenticate. This project recently kicked off, but we don't yet have any details to share.&lt;/LI&gt;&lt;LI&gt;A long term project to build a platform wide authentication and identity service, which would work with both the content repository and the process engine. We are currently scoping this effort and evaluating underlying technologies that could speed our implementation. Our challenge is that there are a lot of related standards in the industry, and our customers have already adopted many of them. We are not yet sure how many we can support. The current list is: LDAP synchronization, SAML, OAuth, OpenID Connect, Kerberos, NTLMv2, JSON Web Token, and continuing to allow External Auth providers.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mention these on the &lt;A __default_attr="1085" __jive_macro_name="document" _jive_internal="true" data-id="1085" data-objecttype="102" data-type="document" href="https://community.alfresco.com/docs/DOC-1085-alfresco-ecm-product-roadmap?sr=search&amp;amp;searchId=ec692342-43bb-44b4-813b-4490691e97e3&amp;amp;searchIndex=0" rel="nofollow noopener noreferrer"&gt;&lt;/A&gt;‌ to explain the direction we are headed, but I'm not yet in a position to provide details as we are still experimenting in order to find the best approach.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Sep 2017 21:15:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-authorization-server/m-p/31293#M13264</guid>
      <dc:creator>resplin</dc:creator>
      <dc:date>2017-09-28T21:15:52Z</dc:date>
    </item>
  </channel>
</rss>

