cancel
Showing results for 
Search instead for 
Did you mean: 

Active directory configuration

p3d3r0s0
Champ in-the-making
Champ in-the-making
Hey, ive seen lots of post regarding this, but i cant find anything that tells me exactly what to do. I never used AD before and i have pretty much no idea at all on what i should be doing.
I looked that the wiki and a few other sites, but there always seems to be missing some sort of "action".

I saw in a post that we should only need to change the alfresco-global.properties, and so i did. I uncommented and changed:
authentication.chain=alfrescoNtlm1:alfrescoNtlm
to
authentication.chain=alfrescoNtlm1:alfrescoNtlm,ldap1:ldap-ad

and added the lines:

    ntlm.authentication.sso.enabled=false
    alfresco.authentication.authenticateCIFS=false

    ntlm.authentication.sso.enabled=false
    passthru.authentication.authenticateCIFS=true

    ldap.authentication.active=false
    ldap.synchronization.active=true

dont i need to configure the AD domain somewhere or mention its IP or something?
im completely lost.
12 REPLIES 12

marcobusetto
Champ in-the-making
Champ in-the-making
Hi. Thanks a lot for all these info. I could never had done my configuration without your help. May I ask you a question? Do you think that the presence of a "OU" item in the ldap.synchronization.userSearchBase and ldap.synchronization.groupSearchBase parameters is mandatory? Is there a way to tell Alfresco to search from the "root" and not from an OU? I tryed to remove the "OU" item (i.e. "DC\=mylab,DC\=loc") but it seems it doesn't work…
Thanks in advance.

p3d3r0s0
Champ in-the-making
Champ in-the-making
I lost a lot of time trying to make it work from "Root" with no luck as well. It was a desperate attempt on my part, i know very little about AD, and when it work i just assumed it wasnt possible any other way.

marcobusetto
Champ in-the-making
Champ in-the-making
when it work i just assumed it wasnt possible any other way
It's very strange that somebody has not yet faced and fixed this problem… I think that if you're installing Alfresco into a pretty complex company, it's impractical to adjust the AD organization to the Alfresco configuration and not the Alfresco configuration to the AD organization… I tried to open a discussion about this: http://forums.alfresco.com/en/viewtopic.php?f=9&t=27153
Thanks.