<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP (Active Directory) Group Permissions in Nuxeo Forum</title>
    <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315364#M2365</link>
    <description>&lt;P&gt;Hi DerekLechner - I'm facing serious issues with integrating with AD. I've followed the example .xml file in Nuxeo docs and modified it to suit our environment. But all AD logins are failing. It appears that you've managed to get that part working. It'll be great if you can guide me here / share the XML file. Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jun 2014 16:13:03 GMT</pubDate>
    <dc:creator>miCRoSCoPiC_eaR</dc:creator>
    <dc:date>2014-06-16T16:13:03Z</dc:date>
    <item>
      <title>LDAP (Active Directory) Group Permissions</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315363#M2364</link>
      <description>&lt;P&gt;Fast Track 5.9.3&lt;/P&gt;
&lt;P&gt;Ok, I setup basic LDAP authentication with our Active Directory.&lt;/P&gt;
&lt;P&gt;The only file I configured is the &lt;STRONG&gt;default-ldap-users-directory-config.xml&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In the userManager section, I manually have the defaultAdministratorId set to my AD useraccount, which grants me Admin access.&lt;BR /&gt; /&amp;gt;
I also have the defaultGroup set to members, which gives everyone else access, as members.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;So far so good, but here is what I want.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I have 3 Groups created in my AD, I would like these mapped to corresponding groups within Nuxeo.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;NuxeoAdmin - Administrators&lt;/LI&gt;
&lt;LI&gt;NuxeoPower - PowerUsers&lt;/LI&gt;
&lt;LI&gt;NuxeoUser - Members&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you are a member of the NuxeoAdmin group, when you log into Nuxeo you will be an Admin in Nuxeo.&lt;/P&gt;
&lt;P&gt;If you are a member of the NuxeoPower group, when you log into Nuxeo you will be in the Power Users group in Nuxeo.&lt;/P&gt;
&lt;P&gt;If you are a member of the NuxeoUser group, when you log into Nuxeo you will be a member in Nuxeo.&lt;/P&gt;
&lt;P&gt;Is this the right way of thinking about this?  To me this seems to be the easiest, and most straight-forward.  I don't need any permissions to be updated, managed through Nuxeo, as we can can do everything through AD.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2014 16:11:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315363#M2364</guid>
      <dc:creator>DerekLechner_</dc:creator>
      <dc:date>2014-06-13T16:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP (Active Directory) Group Permissions</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315364#M2365</link>
      <description>&lt;P&gt;Hi DerekLechner - I'm facing serious issues with integrating with AD. I've followed the example .xml file in Nuxeo docs and modified it to suit our environment. But all AD logins are failing. It appears that you've managed to get that part working. It'll be great if you can guide me here / share the XML file. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 16:13:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315364#M2365</guid>
      <dc:creator>miCRoSCoPiC_eaR</dc:creator>
      <dc:date>2014-06-16T16:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP (Active Directory) Group Permissions</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315365#M2366</link>
      <description>&lt;P&gt;I couldn't find a good way to copy/paste the XML into the forum, so I uploaded a very lightly modified copy of the config to a website.  Let me know if you have questions.  I have setup LDAP for other solutions (VMWare, SAN, etc) so I know it was working.  It was best to enable debugging then monitor the log files within Linux/Nuxeo to see where it saw the problem.  The only real change I had to make was changing the following&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2014 16:57:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315365#M2366</guid>
      <dc:creator>DerekLechner_</dc:creator>
      <dc:date>2014-06-16T16:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP (Active Directory) Group Permissions</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315366#M2367</link>
      <description>&lt;P&gt;&lt;A href="http://www.vidbrochure.com/nuxeoad.xml"&gt;Here is my config file.....slightly modified&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 15:33:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315366#M2367</guid>
      <dc:creator>DerekLechner_</dc:creator>
      <dc:date>2014-06-18T15:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP (Active Directory) Group Permissions</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315367#M2368</link>
      <description>&lt;P&gt;Thank you very much Derek. I was able to get it up and running right-away following your example. Our config files were pretty much the same - only mistake I was making was to pass the bind username in nuxeo@domain format, which is the norm for binding AD with most third-party apps. Changing it to the CN=nuxeo,DC=blah,DC=blah format it worked perfectly.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 18:15:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315367#M2368</guid>
      <dc:creator>miCRoSCoPiC_eaR</dc:creator>
      <dc:date>2014-06-18T18:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP (Active Directory) Group Permissions</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315368#M2369</link>
      <description>&lt;P&gt;I guess there isn't a way to do this.&lt;/P&gt;
&lt;P&gt;The defaultGroup is Members, so everyone with a domain account can log in and view whatever a member can.&lt;/P&gt;
&lt;P&gt;Then if we need to elevate a specific user's permissions: Within Nuxeo, we search for the user, and add them to the appropriate Nuxeo group (Administrators, PowerUsers, ContentReview, etc).&lt;/P&gt;
&lt;P&gt;This works for us, and takes the overhead off of our Network Admins and onto our Training Staff to administer permissions (which is either good or bad), but we are a smaller organization.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2014 15:38:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/ldap-active-directory-group-permissions/m-p/315368#M2369</guid>
      <dc:creator>DerekLechner_</dc:creator>
      <dc:date>2014-07-16T15:38:23Z</dc:date>
    </item>
  </channel>
</rss>

