04-12-2017 09:26 AM
Buenos dias, he presentado problemas con la sincronizacion del directorio activo, estas son las propiedades que tengo en el alfresco-global.properties. Ya tengo la autenticacion, pero aun no me aparecen los usuarios en Alfresco.
ldap.synchronization.active=true
ldap.synchronization.java.naming.security.principal=Aqui coloco mis datos
ldap.synchronization.java.naming.security.credentials= Aqui coloco mi contraseña
ldap.synchronization.groupSearchBase=Aqui coloco mis datos
ldap.synchronization.userSearchBase=Aqui coloco mis datos
ldap.synchronization.groupQuery=(objectclass\=groupOfUniqueNames)
ldap.synchronization.groupDifferentialQuery=(&(objectclass\=groupOfNames)(!(modifyTimestamp<\={0})))
ldap.synchronization.personQuery=(objectclass\=inetOrgPerson)
ldap.synchronization.personDifferentialQuery=(&(objectclass\=groupOfNames)(!(modifyTimestamp<\={0})))
ldap.synchronization.userIdAttributeName=sAMAccountName
ldap.synchronization.userFirstNameAttributeName=cn
ldap.synchronization.userLastNameAttributeName=sn
ldap.synchronization.userEmailAttributeName=mail
ldap.synchronization.userOrganizationalIdAttributeName=ou
ldap.synchronization.defaultHomeFolderProvider=userHomesHomeFolderProvider
ldap.synchronisation.defaultHomeFolderProvider=personalHomeFolderProvider
ldap.synchronization.groupIdAttributeName=cn
ldap.synchronization.groupType=groupOfUniqueNames
ldap.synchronization.personType=inetOrgPerson
synchronization.synchronizeChangesOnly=true
synchronization.import.cron=0 0/5 * * * ?
synchronization.workerThreads=2
ldap.synchronization.enableProgressEstimation=true
ldap.synchronization.groupMemberAttributeName=member
En alfresco.log me sale la siguiente información:
2017-04-12 08:16:30,895 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronizing users and groups with user registry 'ldap1'
2017-04-12 08:16:30,946 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Retrieving all groups from user registry 'ldap1'
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronization,Category=directory,id1=ldap1,id2=1 Group Analysis: Commencing batch of 0 entries
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronization,Category=directory,id1=ldap1,id2=1 Group Analysis: Completed batch of 0 entries
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Retrieving all users from user registry 'ldap1'
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronization,Category=directory,id1=ldap1,id2=6 User Creation and Association: Commencing batch of 0 entries
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Synchronization,Category=directory,id1=ldap1,id2=6 User Creation and Association: Completed batch of 0 entries
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] Finished synchronizing users and groups with user registry 'ldap1'
2017-04-12 08:16:31,008 INFO [org.alfresco.repo.security.sync.ChainingUserRegistrySynchronizer] [localhost-startStop-1] 0 usuarios y 0 grupos procesados
2017-04-12 08:16:31,040 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Synchronization' subsystem, ID: [Synchronization, default] complete
espero que me puedan ayudar, GRACIAS
04-17-2017 02:28 AM
Parece que el userSearchBase o el groupSearchBase no están bien configurados. Quizá deberías intentar hacer esa query LDAP en una herramienta externa para asegurarte de que recupera los datos de usuario necesarios.
04-17-2017 02:12 PM
Yo utilizo el Apache Directory Studio para comprobar las queries, por si sirve de ayuda. Multiplataforma y con notación y queries LDAP. Muy útil para gestionar un openLDAP o un AD.
Saludos.
--C.
Tags
Find what you came for
We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.