<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ldap-ad subsystem - sync error in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/ldap-ad-subsystem-sync-error/m-p/109244#M30627</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I have configured authentication and synchronization with ldap-ad subsystem and got errors in alfresco.log. Can anybody help please? Thanks!&amp;nbsp; (I have used the doc in&amp;nbsp;&lt;A href="http://docs.alfresco.com/6.0/concepts/auth-ldap-props.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/6.0/concepts/auth-ldap-props.html&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-weight: normal; font-size: 14.04px; padding: 0px 0px 0.5em;"&gt;Community&amp;nbsp;-&amp;nbsp;6.1.2 (r4fe1d0d0-b205)&lt;BR /&gt;Repository Information&lt;BR /&gt;&lt;SPAN class=""&gt;Edition:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;Community&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Version Number:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;6.1.2 (r4fe1d0d0-b205)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Version Label:&lt;/SPAN&gt;&lt;SPAN class="" style="color: #555555; font-size: 12.09px; padding-top: 2px;"&gt;Alfresco Content Services version and build number.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Schema:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;13&amp;nbsp;001&lt;/SPAN&gt;&lt;SPAN class="" style="color: #555555; font-size: 12.09px; padding-top: 2px;"&gt;Alfresco Content Services database schema number.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Repository Identifier:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;bd79a43e-b957-4c59-856e-81d68192eb44&lt;/SPAN&gt;&lt;SPAN class="" style="color: #555555; font-size: 12.09px; padding-top: 2px;"&gt;Unique identifier for this repository instance.&lt;BR /&gt;&lt;/SPAN&gt;System Information&lt;BR /&gt;Java Home:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;C:\Program Files\Java\jdk-12.0.1&lt;BR /&gt;&lt;/SPAN&gt;Java Version:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;12.0.1&lt;BR /&gt;&lt;/SPAN&gt;Java VM Vendor:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;Oracle Corporation&lt;BR /&gt;&lt;/SPAN&gt;Operating System:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;Windows Server 2016&lt;BR /&gt;Version:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;10.0&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Architecture:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="" style="padding-left: 4px; padding-top: 2px;"&gt;amd64&lt;/SPAN&gt;&lt;/PRE&gt;&lt;DIV class="" style="color: #000000;"&gt;&lt;PRE style="padding: 0px 0px 12px;"&gt;&lt;BR /&gt;My alfresco.log shows:&lt;/PRE&gt;&lt;/DIV&gt;&lt;PRE&gt;&lt;BR /&gt;2019-05-31 13:58:35,336 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, alfrescoNtlm1]&lt;BR /&gt;2019-05-31 13:58:35,451 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Authentication' subsystem, ID: [Authentication, managed, alfrescoNtlm1] complete&lt;BR /&gt;2019-05-31 13:58:35,451 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, ldap1]&lt;BR /&gt;2019-05-31 13:58:35,726 WARN [org.alfresco.repo.security.authentication.ldap.LDAPInitialDirContextFactoryImpl] [localhost-startStop-1] LDAP server supports anonymous bind ldaps://srv-dc03.emel.sk:636&lt;BR /&gt;2019-05-31 13:58:36,014 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Authentication' subsystem, ID: [Authentication, managed, ldap1] complete&lt;/PRE&gt;&lt;PRE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple o lines later comes this:&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;2019-05-31 13:58:47,877 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronizing users and groups with user registry 'ldap1'&lt;BR /&gt;2019-05-31 13:58:47,917 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Retrieving all groups from user registry 'ldap1'&lt;BR /&gt;2019-05-31 13:58:47,991 ERROR [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronization aborted due to error&lt;BR /&gt;org.alfresco.error.AlfrescoRuntimeException: 04310018 Error during LDAP Search. Reason:[LDAP: error code 32 - 0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:&lt;BR /&gt; 'DC=emel,DC=sk'&lt;BR /&gt; ]&lt;BR /&gt; at org.alfresco.repo.security.sync.ldap.LDAPUserRegistry.processQuery(LDAPUserRegistry.java:1335)&lt;BR /&gt; at org.alfresco.repo.security.sync.ldap.LDAPUserRegistry.getGroups(LDAPUserRegistry.java:713)&lt;BR /&gt; at org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer.syncWithPlugin(ChainingUserRegistrySynchronizer.java:993)&lt;BR /&gt; at org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer.synchronizeInternal(ChainingUserRegistrySynchronizer.java:739)&lt;BR /&gt; at org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer.access$16(ChainingUserRegistrySynchronizer.java:474)&lt;BR /&gt; at org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer$7.doWork(ChainingUserRegistrySynchronizer.java:2138)&lt;BR /&gt; at org.alfresco.repo.security.authentication.AuthenticationUtil.runAs(AuthenticationUtil.java:623)&lt;/PRE&gt;&lt;P&gt;more from log in attachement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My alfresco-global.properties for ldap-ad are:&lt;/P&gt;&lt;PRE&gt;authentication.chain=alfrescoNtlm1:alfrescoNtlm,ldap1:ldap-ad&lt;BR /&gt;&lt;BR /&gt;ldap.authentication.active=true&lt;BR /&gt;ldap.authentication.java.naming.security.authentication=simple&lt;BR /&gt;ldap.authentication.userNameFormat=%s&lt;BR /&gt;ldap.authentication.allowGuestLogin=false&lt;BR /&gt;ldap.authentication.java.naming.provider.url=ldaps://xxx.emel.sk:636&lt;BR /&gt;ldap.synchronization.java.naming.security.principal=yyy@emel.sk&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=zzz&lt;BR /&gt;ldap.authentication.escapeCommasInBind=false&lt;BR /&gt;ldap.authentication.escapeCommasInUid=false&lt;BR /&gt;ldap.synchronization.queryBatchSize=1000&lt;BR /&gt;ldap.synchronization.groupSearchBase=cn\=users,ou=EMEL,dc=emel,dc=sk&lt;BR /&gt;ldap.synchronization.userSearchBase=cn\=users,ou=EMEL Users,ou=Customizacia,dc=emel,dc=sk&lt;BR /&gt;ldap.synchronization.userFirstNameAttributeName=givenName&lt;BR /&gt;ldap.synchronization.userLastNameAttributeName=sn&lt;BR /&gt;ldap.synchronization.userEmailAttributeName=mail&lt;BR /&gt;ldap.synchronization.defaultHomeFolderProvider=userHomesHomeFolderProvider&lt;BR /&gt;ldap.synchronization.groupIdAttributeName=cn&lt;BR /&gt;ldap.synchronization.groupType=Nogroup&lt;BR /&gt;ldap.synchronization.personType=user&lt;BR /&gt;ldap.synchronization.groupMemberAttributeName=member&lt;BR /&gt;synchronization.synchronizeChangesOnly=true&lt;BR /&gt;cifs.enabled=false&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 31 May 2019 12:17:35 GMT</pubDate>
    <dc:creator>janovjak</dc:creator>
    <dc:date>2019-05-31T12:17:35Z</dc:date>
    <item>
      <title>ldap-ad subsystem - sync error</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ldap-ad-subsystem-sync-error/m-p/109244#M30627</link>
      <description>Hi, I have configured authentication and synchronization with ldap-ad subsystem and got errors in alfresco.log. Can anybody help please? Thanks!&amp;nbsp; (I have used the doc in&amp;nbsp;http://docs.alfresco.com/6.0/concepts/auth-ldap-props.html)Community&amp;nbsp;-&amp;nbsp;6.1.2 (r4fe1d0d0-b205)Repository InformationEdition:&amp;nbsp;Commun</description>
      <pubDate>Fri, 31 May 2019 12:17:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ldap-ad-subsystem-sync-error/m-p/109244#M30627</guid>
      <dc:creator>janovjak</dc:creator>
      <dc:date>2019-05-31T12:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: ldap-ad subsystem - sync error</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ldap-ad-subsystem-sync-error/m-p/109245#M30628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I found a solution which worked for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; after two weeks...&lt;/P&gt;&lt;P&gt;The problems are the "non existing" space in CN entry after comma.&lt;/P&gt;&lt;P&gt;For me its working with this entries&lt;/P&gt;&lt;PRE&gt;ldap.synchronization.groupSearchBase=OU=EMEL Users, DC=emel, DC=sk&lt;BR /&gt;ldap.synchronization.userSearchBase=OU=Customizacia, OU=EMEL Users, DC=emel, DC=sk&lt;BR /&gt;&lt;BR /&gt;Cheers!&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2019 14:31:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ldap-ad-subsystem-sync-error/m-p/109245#M30628</guid>
      <dc:creator>janovjak</dc:creator>
      <dc:date>2019-05-31T14:31:01Z</dc:date>
    </item>
  </channel>
</rss>

