Showing results for 
Search instead for 
Did you mean: 

Apache Ldap external Auth with Alf 4.0.d

Champ in-the-making
Champ in-the-making
I've been looking high and low trying to find steps to configure alfresco with remote authentication using apache ldap module.  essentially passing REMOTE_USER from apache to alf after authenticating.  I am able to configure where i can successfully log into /alfresco explorer, however, /share does not log me in.  Has anyone experienced/solved this issue?

i have
1) setup apache for the ldap mod (which works since i get automatcially logged into /alfresco)

2) setup ajp entry for both /alfresco and /share in apache.  

        # Alfresco Explorer
    ProxyPass /alfresco ajp://
    ProxyPassReverse /alfresco ajp://

      # Alfresco Share
    ProxyPass /share ajp://
    ProxyPassReverse /share ajp://

4) setup tomcat ajp entry
     <Connector port="8009" protocol="AJP/1.3" redirectPort="8443" tomcatAuthentication="false" />

5) set /tomcat/shared/classes/ with


6) in share-config-custom.xml, i have put in the suggested xml entries below:


   <!– Repository Library config section –>
   <config evaluator="string-compare" condition="RepositoryLibrary" replace="true">
         Whether the link to the Repository Library appears in the header component or not.

   <config evaluator="string-compare" condition="Remote">
            <name>Alfresco - unauthenticated access</name>
            <description>Access to Alfresco Repository WebScripts that do not require authentication</description>

            <name>Alfresco - user access</name>
            <description>Access to Alfresco Repository WebScripts that require user authentication</description>

            <name>Alfresco Feed</name>
            <description>Alfresco Feed - supports basic HTTP authentication via the EndPointProxyServlet</description>

            <name>Activiti Admin UI - user access</name>
            <description>Access to Activiti Admin UI, that requires user authentication</description>

<config evaluator="string-compare" condition="Remote">

                  <name>Alfresco Connector</name>
                   <description>Connects to an Alfresco instance using cookie-based authentication</description>

                       <name>Alfresco - user access</name>
                       <description>Access to Alfresco Repository WebScripts that require user authentication</description>

World-Class Innovator
World-Class Innovator
I don't have an answer to your question, but I am curious…What are the benefits of taking this approach over configuring Alfresco to authenticate against LDAP (which then automatically works for both /alfresco and /share)?


Champ in-the-making
Champ in-the-making
we want use shibboleth mod in apache which passes Remote_user.  to keep things simple we are using ldap for now.  In theory , if we can make this work, then we should be able to use shib.  We are close.  We just need to know how to config /share

Champ in-the-making
Champ in-the-making
Anyone have an idea?

Champ in-the-making
Champ in-the-making
Has anyone gotten external authentication to work with both /alfresco and /share?

Champ in-the-making
Champ in-the-making
I was able to set shibboleth working with /alfresco, only. not /share.
But I want to make it work without AJP…is that possible just with ProxyPass?