cancel
Showing results for 
Search instead for 
Did you mean: 

Multi-tenancy and SSO (CAS+LDAP)

danilo_barone
Champ in-the-making
Champ in-the-making
Good morning all,
I have some questions, so I'm going to describe my situation:

In multi-tenancy structure, I have fore example 2 tenants.
-tenantdom1
-tenantdom2
So an user can login in alfresco by <username>@tenantdom1 or <username>@tenantdom2 (depending on wich tenant he is registered).

I configured SSO in Alfresco with CAS and LDAP. This configuration work, and LDAP users import work too, but I have a problem.
Although I read that there are issues about multi authentication on multi LDAP, this is not my problem: I have only one LDAP application.
Each tenant is identified in LDAP by an "organization unit". For example: o=tenantdom1 and o=tenantdom2. So each user of tenant1 will be under o=tenantdom1, and each user of tenant2 are under o=tenantdom2.

This is mi situation, and these are my questions:

1 - Do you have suggestions on how I can implement this architechture in Alfresco?
2 - I can import users from LDAP (using ldap.synchronisation.personSearchBase), but how I can import user from more dn?
3 - Do I need to implement a new "ldap-synchronisation-context"? How can I do?

Thank you all
Regards

Danilo
11 REPLIES 11

flopez
Champ in-the-making
Champ in-the-making
Any one? anything? …

shawn123
Champ in-the-making
Champ in-the-making
The RSA Archer eGRC Platform is a multi-tenant software platform, supporting the configuration of separate instances in provider-hosted environments. These individual instances support data segmentation as well as discrete user experiences and branding. Individual instances store their data in physically separate databases while using a common hardware environment and a single deployment of RSA Archer application code. Users identify their instance as part of a manual login process, although instance identification can be automated through DNS or single sign-on configuration.