cancel
Showing results for 
Search instead for 
Did you mean: 

Active Directory Authentication & registration

senthil_chinnai
Champ in-the-making
Champ in-the-making
Hi,

I am new to Alfresco, I need to enable Active Directory authentication. I have followed instructions on wiki and it imports all users data at the startup.

I would like to authenticate users and register upon successful authentication. I have seen one thread for that, but it doesn't have step by step process. Can any one share the document to achieve the functionality please?



Thanks,
Senthil.
5 REPLIES 5

andy
Champ on-the-rise
Champ on-the-rise
Hi

To clarify, do you want to

1) pull/add/update user and group information from LDAP as user authenticate?

2) audit authentication?

Regards

Andy

senthil_chinnai
Champ in-the-making
Champ in-the-making
Andy,

Yes exactly, Please help me in doing that.

Thanks,
Senthil.

andy
Champ on-the-rise
Champ on-the-rise
Hi

See the audit information on the wiki.
http://wiki.alfresco.com/wiki/Audit#Configuration_Guide

Regards

Andy

senthil_chinnai
Champ in-the-making
Champ in-the-making
Thanks Andy. How to disable importing all users and groups at the server startup and register only the authenticated users.

Thanks,
Senthil.

andy
Champ on-the-rise
Champ on-the-rise
Hi

It is possible to create people as they log in. At the moment there is no support to pull information out of LDAP as people log in.

I know people are rolling their own code to do similar stuff (e.g. SSO filters that pull personal information from the headers provided by the SSO framework - whatever that may be - and sync up user and group info)

There would be a few alternatives.

1) Pull people as they log in - you would have to write some code

2) Sync a limited set of people from LDAP (by limiting the query on some ldap attribute or group membership) - you would have to filter the users found on the query

3) LDAP update for known users (log in would create a default entry - at some time later the full details would be pulled from LDAP) - this would require less of a code change.

Regards

Andy