<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help configuring LDAP in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113448#M31546</link>
    <description>&lt;P&gt;I guess you're missing to set the "create.missing.people" flag.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.alfresco.com/community/concepts/auth-ldap-props.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.alfresco.com/community/concepts/auth-ldap-props.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Add following configuration:&lt;/P&gt;
&lt;PRE&gt;create.missing.people=false&lt;/PRE&gt;</description>
    <pubDate>Wed, 08 Apr 2020 13:15:53 GMT</pubDate>
    <dc:creator>angelborroy</dc:creator>
    <dc:date>2020-04-08T13:15:53Z</dc:date>
    <item>
      <title>Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113447#M31545</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Alfresco Community v6.2.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am connecting a test system to my test domain controller, in the&amp;nbsp;LDAP configuration properties page (&lt;A href="https://docs.alfresco.com/5.0/concepts/auth-ldap-props.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://docs.alfresco.com/5.0/concepts/auth-ldap-props.html&lt;/A&gt;) it has a section for group and user search bases. The advice given is 'The DN below which to run the group queries.'. My test system is configured as follows:&lt;/P&gt;&lt;P&gt;authentication.chain=alfinst:alfrescoNtlm,ldap1:ldap-ad&lt;/P&gt;&lt;P&gt;ntlm.authentication.sso.enabled=false&lt;/P&gt;&lt;P&gt;ldap.authentication.active=true&lt;BR /&gt;ldap.authentication.allowGuestLogin=false&lt;BR /&gt;ldap.authentication.userNameFormat=%s@chris.com&lt;BR /&gt;ldap.authentication.java.naming.provider.url=ldap://192.168.56.220:389&lt;BR /&gt;ldap.authentication.defaultAdministratorUserNames=Administrator,alfresco&lt;BR /&gt;ldap.synchronization.java.naming.security.principal=xxxxxxxx&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=xxxxxxxx&lt;BR /&gt;ldap.synchronization.groupSearchBase=Alfresco,OU=Groups,OU=Blackburn,DC=Chris,DC=com&lt;BR /&gt;ldap.synchronization.userSearchBase=Alfresco,OU=Users,OU=Blackburn,DC=Chris,DC=com&lt;/P&gt;&lt;P&gt;Within both users and groups I have set up 2 OUs (alfresco &amp;amp; nonalfresco), then I have created a test user in each group. From the advice given, one would assume that only the users below the Alfresco OUs would be able to log in, but I can log in with the users in the nonalfresco OUs too, can anyone explain why this is?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 11:38:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113447#M31545</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-08T11:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113448#M31546</link>
      <description>&lt;P&gt;I guess you're missing to set the "create.missing.people" flag.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.alfresco.com/community/concepts/auth-ldap-props.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.alfresco.com/community/concepts/auth-ldap-props.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Add following configuration:&lt;/P&gt;
&lt;PRE&gt;create.missing.people=false&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 Apr 2020 13:15:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113448#M31546</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2020-04-08T13:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113449#M31547</link>
      <description>&lt;P&gt;Hi, thanks for your reply, I have added that configuration to the file and it has now prevented all users from logging in, even the built in admin/admin account&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 14:29:12 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113449#M31547</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-08T14:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113450#M31548</link>
      <description>&lt;P&gt;Check that you have also included both authentication systems:&lt;/P&gt;
&lt;PRE&gt;authentication.chain=alfinst:alfrescoNtlm,ldap1:ldap-ad&lt;/PRE&gt;
&lt;P&gt;And take a look at this video:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=pJNpqAOelmE" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.youtube.com/watch?v=pJNpqAOelmE&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 14:34:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113450#M31548</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2020-04-08T14:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113451#M31549</link>
      <description>&lt;P&gt;Hi, sorry about my last message... The reason I could not authenticate any users was because my VM had a network issue, so Alfresco could not contact the server. I have added in the&amp;nbsp;create.missing.people=false setting and it will still allow users from another OU log in, so this has seemingly not changed anything that I can notice&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 15:22:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113451#M31549</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-09T15:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113452#M31550</link>
      <description>&lt;P&gt;To avoid auto-creation of users, we are currently using the following property:&lt;/P&gt;&lt;PRE&gt;synchronization.autoCreatePeopleOnLogin=false&lt;/PRE&gt;&lt;P&gt;We got this property by looking at &lt;A href="https://github.com/Alfresco/alfresco-repository/blob/master/src/main/resources/alfresco/subsystems/Synchronization/default/default-synchronization.properties" target="_blank" rel="noopener nofollow noreferrer"&gt;default-synchronization.properties&lt;/A&gt; file. I think Alfresco should update the documentation about this.&lt;/P&gt;&lt;P&gt;I hope it solves your problem.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 08:10:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113452#M31550</guid>
      <dc:creator>narkuss</dc:creator>
      <dc:date>2020-04-10T08:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113453#M31551</link>
      <description>&lt;P&gt;I've added that setting and it is still allowing users from the wrong OU in AD to log in. I'm using the Bitnami installer, would that make a difference? Something else worth pointing out too, is that when I navigate to:&lt;/P&gt;&lt;P&gt;&lt;A href="http://127.0.0.1:81/share/page/console/admin-console/users" target="_blank" rel="nofollow noopener noreferrer"&gt;http://127.0.0.1:81/share/page/console/admin-console/users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I get an error '&lt;SPAN&gt;Error loading items'&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:59:06 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113453#M31551</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-14T12:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113454#M31552</link>
      <description>&lt;P&gt;This error is a &lt;A href="https://github.com/Alfresco/acs-community-packaging/issues/367" target="_blank" rel="noopener nofollow noreferrer"&gt;known bug&lt;/A&gt; in share 6.2.&lt;/P&gt;&lt;P&gt;Regarding ldap users, have you checked that these users from the wrong OU are not there from past wrong logins? The simplest way would be checking that these users can change their password from share UI. Ldap users can't change their password from share UI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, afaik, there is no bitnami installer for Alfresco 6.2...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 16:41:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113454#M31552</guid>
      <dc:creator>narkuss</dc:creator>
      <dc:date>2020-04-14T16:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113455#M31553</link>
      <description>&lt;P&gt;If I log in to my build and click the alfresco logo, it gives me the following detail:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alfresco Share v6.2.0&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="bd"&gt;&lt;DIV class="logo-com logo"&gt;&lt;DIV class="about"&gt;&lt;DIV&gt;(r7791ffba8f0b22f1ef9fa25ba17400c4657068e3-b9, Aikau 1.0.101.19, Spring Surf 6.2.0, Spring WebScripts 7.10, Freemarker 2.3.28, Rhino 1.7.11, Yui 2.9.0-alfresco-20141223)&lt;/DIV&gt;&lt;DIV class="header"&gt;Alfresco Community v6.2.0&lt;/DIV&gt;&lt;DIV&gt;(r05dbaf43-b368) schema 13001&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class="header"&gt;Alfresco Community v6.2.0&lt;/DIV&gt;&lt;DIV&gt;(r05dbaf43-b368) schema 13001&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;With the latest settings, I've now found that a new user created within the 'none alfresco' user/group OUs does not get given access to the front end, so tested creating one in the alfresco OU, but wouldn't let that log in either, was hoping I had resolved the issue, as I've been banging my head against a brick wall with this trying to get a setting to work.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I just don't understand why the setting says:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;ldap.synchronization.userSearchBase&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;The DN below which to run the user queries.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Surely if the&amp;nbsp;LDAP configuration properties page states this, then it should function as outlined? Otherwise it is a bug?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Don't suppose you have any idea with regards to the '&lt;SPAN&gt;Error loading items' issue in admin tools/users?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 15 Apr 2020 09:19:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113455#M31553</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-15T09:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113456#M31554</link>
      <description>&lt;P&gt;The error loading items issue is a known share 6.2 bug as I stated in last comment.&lt;/P&gt;&lt;P&gt;Regarding your ldap error, I think Alfresco is not synchronizing users correctly. Check your logs, and escape the equals signs in your usersSearchBase property value adding a backslash in front of them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 11:39:24 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113456#M31554</guid>
      <dc:creator>narkuss</dc:creator>
      <dc:date>2020-04-15T11:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113457#M31555</link>
      <description>&lt;P&gt;Sorry, I didn't notice your link for the fix, but I've updated the file now and I can now see users in the admin console, which makes life a lot easier for me, thanks for that!&lt;/P&gt;&lt;P&gt;Currently, without the&amp;nbsp;&lt;STRONG&gt;synchronization.autoCreatePeopleOnLogin=false&lt;/STRONG&gt; setting, when I delete all of the users and restart the services, they don't appear in the users section, but if I attempt to login with any of the test users from either of the Alfresco/NonAlfresco groups, it allows me to log in and creates them as a user. If I apply that setting, it does not let me log in with the test users from either groups. I seem to get the same reaction from the system if I edit that setting out and use&amp;nbsp;&lt;STRONG&gt;create.missing.people=false&lt;/STRONG&gt; instead, so neither seem to be doing what I require. I have tried changing the searchbase properties to what you suggested:&lt;/P&gt;&lt;P&gt;ldap.synchronization.groupSearchBase=OU\=Alfresco,OU\=Groups,OU\=Blackburn,DC\=Chris,DC\=com&lt;BR /&gt;ldap.synchronization.userSearchBase=OU\=Alfresco,OU\=Users,OU\=Blackburn,DC\=chris,DC\=com&lt;/P&gt;&lt;P&gt;This doesn't seem to have any effect.&lt;/P&gt;&lt;P&gt;I have had a look at the tomcat errors (in alfrescotomcat-stdout.2020-04-15.log), but I'm not sure what error to look for to determine why Alfresco either allows no users to log in, or all of them.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 15:11:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113457#M31555</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-15T15:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113458#M31556</link>
      <description>&lt;P&gt;Then it seems that Alfresco is not correctly synchronizing your ldap users. Look at alfresco.log at startup time, or share your alfresco.log file here. It could be an authentication error against your ldap, or maybe that Alfresco cannot reach your ldap server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 15:50:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113458#M31556</guid>
      <dc:creator>narkuss</dc:creator>
      <dc:date>2020-04-15T15:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113459#M31557</link>
      <description>&lt;P&gt;I'm not sure how to share my log file here, there doesn't seem to be any upload facility? I've checked the log file and found this error though:&lt;/P&gt;&lt;P&gt;org.alfresco.repo.security.authentication.AuthenticationException: 03150018 Failed to authenticate, username or password is wrong. User name:Administrator Reason [LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042A, comment: AcceptSecurityContext error, data 52e, v3839 ]&lt;/P&gt;&lt;P&gt;I originally had a user called Alfresco for authentication and found that error in the log file, so I changed the username to the administrator UN/PW that I use for the server, but still getting the error for the Administrator account. I've set the settings in the following config:&lt;/P&gt;&lt;P&gt;ldap.synchronization.java.naming.security.principal=Alfresco&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=Pa55word&lt;/P&gt;&lt;P&gt;The previous error was the same:&lt;/P&gt;&lt;P&gt;org.alfresco.repo.security.authentication.AuthenticationException: 03150056 Failed to authenticate, username or password is wrong. User name:Alfresco Reason [LDAP: error code 49 - 80090308: LdapErr: DSID-0C09042A, comment: AcceptSecurityContext error, data 52e, v3839 ]&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 16:33:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113459#M31557</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-15T16:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113460#M31558</link>
      <description>&lt;P&gt;Ok then the error is about ldap authentication. Don't provide your server user to authenticate against your AD, there must be some user in the same AD application that grants you read access to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can try to connect from an external tool to check you can connect properly, or ask who provided you these credentials to check their validity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 17:18:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113460#M31558</guid>
      <dc:creator>narkuss</dc:creator>
      <dc:date>2020-04-15T17:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring LDAP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113461#M31559</link>
      <description>&lt;P&gt;Thanks a lot for your help, it turned out that the reason LDAP was not authenticating was due to the username I was using not containing&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/37748"&gt;@chris&lt;/A&gt;.com on the end of it, once I changed it to that it worked and I now only have the users I want in Alfresco. For anyone visiting this thread in the future, I will list my settings that are now working:&lt;/P&gt;&lt;P&gt;### LDAP - AUTHENTICATION ###&lt;/P&gt;&lt;P&gt;authentication.chain=alfinst:alfrescoNtlm,ldap1:ldap-ad&lt;/P&gt;&lt;P&gt;ldap.authentication.active=true&lt;BR /&gt;ldap.authentication.java.naming.provider.url=ldap://192.168.56.220:389&lt;BR /&gt;ldap.authentication.userNameFormat=%s@chris.com&lt;BR /&gt;ldap.authentication.allowGuestLogin=false&lt;/P&gt;&lt;P&gt;create.missing.people=false&lt;/P&gt;&lt;P&gt;### LDAP - SYNCRONISATION ###&lt;/P&gt;&lt;P&gt;ldap.synchronization.active=true&lt;/P&gt;&lt;P&gt;ldap.synchronization.java.naming.security.principal=Administrator@chris.com&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=********&lt;/P&gt;&lt;P&gt;ldap.synchronization.groupSearchBase=OU\=Alfresco,OU\=Groups,OU\=Blackburn,DC\=Chris,DC\=com&lt;BR /&gt;ldap.synchronization.groupQuery=(objectclass\=group)&lt;/P&gt;&lt;P&gt;ldap.synchronization.userSearchBase=OU\=Alfresco,OU\=Users,OU\=Blackburn,DC\=Chris,DC\=com&lt;BR /&gt;ldap.synchronization.personQuery=(&amp;amp;(objectclass\=user)(memberOf=cn\=TechSupport,OU\=Alfresco,OU\=Groups,OU\=Blackburn,DC\=Chris,DC\=com))&lt;/P&gt;&lt;P&gt;synchronization.syncOnStartup=true&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 13:43:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/help-configuring-ldap/m-p/113461#M31559</guid>
      <dc:creator>ChrisAlker</dc:creator>
      <dc:date>2020-04-16T13:43:57Z</dc:date>
    </item>
  </channel>
</rss>

