Showing results for 
Search instead for 
Did you mean: 

Nuxeo LDAP groups not loading

Champ in-the-making
Champ in-the-making

I have deployed Nuxeo Platform 5.6 on a Windows Server from Tomcat bundle installation. I have configured the LDAP login accordin to the code below. Users are able to login but their groups are not loaded. Is there something I am missing?

<!-- Configuration of a server connection

  A single server declaration can point to a cluster of replicated
  servers (using OpenLDAP's slapd + sluprd for instance). To leverage
  such a cluster and improve availibility, please provide one
  <ldapUrl/> tag for each replica of the cluster.
<server name="default">

  <!-- Optional servers from the same cluster for failover
    and load balancing:


    "ldaps" means TLS/SSL connection.

  <!-- Credentials used by Nuxeo5 to browse the directory, create
    and modify entries.

    Only the authentication of users (bind) use the credentials entered
    through the login form if any.
  <bindDn>cn=IUSR_ldap_user,ou=Service Accounts,ou=SpecialUsers,ou=KEMRI-WTRP,dc=kwtrp,dc=org</bindDn>

<directory name="userDirectory">





  <!-- maximum number of cached entries before global invalidation -->


  <fieldMapping name="username">sAMAccountName</fieldMapping>
  <fieldMapping name="password">userPassword</fieldMapping>
  <fieldMapping name="firstName">givenName</fieldMapping>
  <fieldMapping name="lastName">sn</fieldMapping>
  <fieldMapping name="company">company</fieldMapping>
  <fieldMapping name="email">mail</fieldMapping>


    <inverseReference field="groups" directory="groupDirectory"
      dualReferenceField="members" />


<directory name="groupDirectory">
    <entryAdaptor class="">
        <parameter name="fieldName">dn</parameter>
        <parameter name="regexp">.*,ou=editable,OU=Groups,OU=KEMRI-WTRP,DC=kwtrp,DC=org</parameter>
    <fieldMapping name="groupname">cn</fieldMapping>
        <ldapReference directory="userDirectory"
            dynamicAttributeId="memberURL" field="members"
            staticAttributeId="uniqueMember" staticAttributeIdIsDn="true"/>
        <ldapReference directory="groupDirectory"
            dynamicAttributeId="memberURL" field="subGroups"
            forceDnConsistencyCheck="false" staticAttributeId="uniqueMember"/>
        <inverseReference directory="groupDirectory"
            dualReferenceField="subGroups" field="parentGroups"/>
        <ldapTreeReference directory="groupDirectory"
            field="children" scope="onelevel"/>
        <inverseReference directory="groupDirectory"
            dualReferenceField="children" field="parents"/>
colima members
Getting started

Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.