<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Alfresco integration with Active Directory</title>
	<atom:link href="http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/</link>
	<description>my comments, my projects, my resources…</description>
	<lastBuildDate>Tue, 24 May 2011 12:55:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Ivan Pleština</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-8031</link>
		<dc:creator>Ivan Pleština</dc:creator>
		<pubDate>Fri, 25 Mar 2011 07:26:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-8031</guid>
		<description>I&#039;d rathet double-check the config. Empty groups usually indicate faulty LDAP query than version problems.</description>
		<content:encoded><![CDATA[<p>I&#8217;d rathet double-check the config. Empty groups usually indicate faulty LDAP query than version problems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brazen</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-8003</link>
		<dc:creator>Brazen</dc:creator>
		<pubDate>Thu, 24 Mar 2011 18:04:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-8003</guid>
		<description>I used this config for Alfresco 3.4d against a Windows 2008 R2 domain.  It works, but none of the imported groups have users added to them.  The users are members of the groups in Active Directory but when they are imported in to Alfresco, no users are members of any groups.

Do users get put in their groups with the import in Alfresco 3.3g?  I would go back to that version, if it would work correctly.</description>
		<content:encoded><![CDATA[<p>I used this config for Alfresco 3.4d against a Windows 2008 R2 domain.  It works, but none of the imported groups have users added to them.  The users are members of the groups in Active Directory but when they are imported in to Alfresco, no users are members of any groups.</p>
<p>Do users get put in their groups with the import in Alfresco 3.3g?  I would go back to that version, if it would work correctly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: niox</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-6473</link>
		<dc:creator>niox</dc:creator>
		<pubDate>Fri, 11 Feb 2011 18:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-6473</guid>
		<description>Hi guys,

Can i use this config for alfresco 3.4?
I need AD connection and ntlm.</description>
		<content:encoded><![CDATA[<p>Hi guys,</p>
<p>Can i use this config for alfresco 3.4?<br />
I need AD connection and ntlm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-3507</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Wed, 03 Nov 2010 14:19:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-3507</guid>
		<description>Ivan, thnx for the reply, and i want you to know, that the others guides aren&#039;t this helpful, i have changed the values, but the sync shows me this:

log4j:ERROR Failed to rename [alfresco.log] to [alfresco.log.2010-11-02].
00:00:00,617 User:System WARN  [security.sync.ChainingUserRegistrySynchronizer]
Full synchronization with user registry &#039;ldap1&#039;; some users and groups previousl
y created by synchronization with this user registry may be removed.
00:00:00,633 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
Retrieving all groups from user registry &#039;ldap1&#039;
00:00:00,648 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
ldap1 Group Analysis: Commencing batch of 0 entries
00:00:00,648 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
ldap1 Group Analysis: Completed batch of 0 entries
00:00:00,695 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
Retrieving all users from user registry &#039;ldap1&#039;
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
ldap1 User Creation and Association: Commencing batch of 0 entries
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
ldap1 User Creation and Association: Completed batch of 0 entries
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
ldap1 Authority Deletion: Commencing batch of 0 entries
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
ldap1 Authority Deletion: Completed batch of 0 entries
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
Finished synchronizing users and groups with user registry &#039;ldap1&#039;
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]
0 user(s) and 0 group(s) processed

i hope you can help me again.

regards.</description>
		<content:encoded><![CDATA[<p>Ivan, thnx for the reply, and i want you to know, that the others guides aren&#8217;t this helpful, i have changed the values, but the sync shows me this:</p>
<p>log4j:ERROR Failed to rename [alfresco.log] to [alfresco.log.2010-11-02].<br />
00:00:00,617 User:System WARN  [security.sync.ChainingUserRegistrySynchronizer]<br />
Full synchronization with user registry &#8216;ldap1&#8242;; some users and groups previousl<br />
y created by synchronization with this user registry may be removed.<br />
00:00:00,633 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
Retrieving all groups from user registry &#8216;ldap1&#8242;<br />
00:00:00,648 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
ldap1 Group Analysis: Commencing batch of 0 entries<br />
00:00:00,648 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
ldap1 Group Analysis: Completed batch of 0 entries<br />
00:00:00,695 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
Retrieving all users from user registry &#8216;ldap1&#8242;<br />
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
ldap1 User Creation and Association: Commencing batch of 0 entries<br />
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
ldap1 User Creation and Association: Completed batch of 0 entries<br />
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
ldap1 Authority Deletion: Commencing batch of 0 entries<br />
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
ldap1 Authority Deletion: Completed batch of 0 entries<br />
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
Finished synchronizing users and groups with user registry &#8216;ldap1&#8242;<br />
00:00:00,711 User:System INFO  [security.sync.ChainingUserRegistrySynchronizer]<br />
0 user(s) and 0 group(s) processed</p>
<p>i hope you can help me again.</p>
<p>regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan Pleština</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-3487</link>
		<dc:creator>Ivan Pleština</dc:creator>
		<pubDate>Tue, 02 Nov 2010 22:22:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-3487</guid>
		<description>Hi Steven, 

glad you find this guide helpful. You basically need to change above queries to match your organization. You query LDAP for users and groups that you want in Alfresco. How to write LDAP queries is really beyond this article and I&#039;m sure that there are great tutorials available on other sites which you could use, with my example queries, to write ones for your environment.

Regards</description>
		<content:encoded><![CDATA[<p>Hi Steven, </p>
<p>glad you find this guide helpful. You basically need to change above queries to match your organization. You query LDAP for users and groups that you want in Alfresco. How to write LDAP queries is really beyond this article and I&#8217;m sure that there are great tutorials available on other sites which you could use, with my example queries, to write ones for your environment.</p>
<p>Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-3479</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Tue, 02 Nov 2010 16:32:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-3479</guid>
		<description>Hi all

I want to thank you about this guide, it&#039;s helping me a lot,&#039;cause this is the first time that try to install alfresco, but i&#039;ve some doubts about this lines:

# The query to select all objects that represent the groups to import.
ldap.synchronization.groupQuery=(&amp;(objectclass\=group)(memberOf\=cn\=Alfresco Groups,ou\=user,dc\=domain,dc\=local))

# The query to select objects that represent the groups to import that have changed since a certain time.
ldap.synchronization.groupDifferentialQuery=(&amp;(objectclass\=group)(memberOf\=cn\=Alfresco Groups,ou\=user,dc\=domain,dc\=local)(!(modifyTimestamp&lt;\={0})))

# The query to select all objects that represent the users to import.
ldap.synchronization.personQuery=(&amp;(objectclass\=user)(&#124;(memberOf\=CN\=Developers,OU\=user,DC\=domain,DC\=local)(memberOf\=CN\=Sales,OU\=user,DC\=domain,DC\=local))(userAccountControl\:1.2.840.113556.1.4.803\:\=512))

# The query to select objects that represent the users to import that have changed since a certain time.
ldap.synchronization.personDifferentialQuery=(&amp;(objectclass\=user)(&#124;(memberOf\=CN\=Developers,OU\=user,DC\=domain,DC\=local)(memberOf\=CN\=Sales,OU\=user,DC\=domain,DC\=local))(userAccountControl\:1.2.840.113556.1.4.803\:\=512)(!(modifyTimestamp&lt;\={0})))

i really don get wich values do i have to change by mines, so i&#039;d apreciate the help
and i want to apologize (i know my english it&#039;s crappy).
thnx!</description>
		<content:encoded><![CDATA[<p>Hi all</p>
<p>I want to thank you about this guide, it&#8217;s helping me a lot,&#8217;cause this is the first time that try to install alfresco, but i&#8217;ve some doubts about this lines:</p>
<p># The query to select all objects that represent the groups to import.<br />
ldap.synchronization.groupQuery=(&amp;(objectclass\=group)(memberOf\=cn\=Alfresco Groups,ou\=user,dc\=domain,dc\=local))</p>
<p># The query to select objects that represent the groups to import that have changed since a certain time.<br />
ldap.synchronization.groupDifferentialQuery=(&amp;(objectclass\=group)(memberOf\=cn\=Alfresco Groups,ou\=user,dc\=domain,dc\=local)(!(modifyTimestamp&lt;\={0})))</p>
<p># The query to select all objects that represent the users to import.<br />
ldap.synchronization.personQuery=(&amp;(objectclass\=user)(|(memberOf\=CN\=Developers,OU\=user,DC\=domain,DC\=local)(memberOf\=CN\=Sales,OU\=user,DC\=domain,DC\=local))(userAccountControl\:1.2.840.113556.1.4.803\:\=512))</p>
<p># The query to select objects that represent the users to import that have changed since a certain time.<br />
ldap.synchronization.personDifferentialQuery=(&amp;(objectclass\=user)(|(memberOf\=CN\=Developers,OU\=user,DC\=domain,DC\=local)(memberOf\=CN\=Sales,OU\=user,DC\=domain,DC\=local))(userAccountControl\:1.2.840.113556.1.4.803\:\=512)(!(modifyTimestamp&lt;\={0})))</p>
<p>i really don get wich values do i have to change by mines, so i&#039;d apreciate the help<br />
and i want to apologize (i know my english it&#039;s crappy).<br />
thnx!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nondu</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-3323</link>
		<dc:creator>Nondu</dc:creator>
		<pubDate>Wed, 27 Oct 2010 13:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-3323</guid>
		<description>Hi Ivan

Hi Ivan
Thanks for the article. I followed the instruction I’m using alfresco 3.3.1 and it gave me this error “net.sf.acegisecurity.AuthenticationServiceException: Failed to open passthru auth session” can you please help me.</description>
		<content:encoded><![CDATA[<p>Hi Ivan</p>
<p>Hi Ivan<br />
Thanks for the article. I followed the instruction I’m using alfresco 3.3.1 and it gave me this error “net.sf.acegisecurity.AuthenticationServiceException: Failed to open passthru auth session” can you please help me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alfresco 3.3g integration with Active Directory and Google Docs &#124; Another Stranger Me</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-729</link>
		<dc:creator>Alfresco 3.3g integration with Active Directory and Google Docs &#124; Another Stranger Me</dc:creator>
		<pubDate>Sun, 20 Jun 2010 18:37:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-729</guid>
		<description>[...] last article on Alfresco integration with Active Directory brought up a lot of interest and what&#8217;s the most important positive feedback. That article is [...]</description>
		<content:encoded><![CDATA[<p>[...] last article on Alfresco integration with Active Directory brought up a lot of interest and what&#8217;s the most important positive feedback. That article is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan Pleština</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-701</link>
		<dc:creator>Ivan Pleština</dc:creator>
		<pubDate>Fri, 18 Jun 2010 21:50:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-701</guid>
		<description>Hi Curtis,
thanks for feedback.

I&#039;m preparing a new guide for version 3.3g and I&#039;ll try to highlight those custom sections. New article will be more up to date and also simplify some stuff and have some corrections.

As for now, I can give you a quick list:
passthru.authentication.servers=DOMAIN\\192.168.0.1,192.168.0.1
passthru.authentication.defaultAdministratorUserNames=AD_usernames

ldap.authentication.java.naming.provider.url=ldap://domain.local:389
ldap.synchronization.java.naming.security.principal=user@domain.local
ldap.synchronization.java.naming.security.credentials=YourPass
ldap.synchronization.groupQuery=
ldap.synchronization.groupDifferentialQuery=
ldap.synchronization.personQuery=
ldap.synchronization.personDifferentialQuery=
ldap.synchronization.groupSearchBase=dc\=domain,dc\=local
ldap.synchronization.userSearchBase=dc\=domain,dc\=local

filesystem.domainMappings=DOMAIN
filesystem.domainMappings.value.DOMAIN.rangeFrom=192.168.0.0
filesystem.domainMappings.value.DOMAIN.rangeTo=192.168.0.255

cifs.localname=HOSTNAME
cifs.domain=DOMAIN
cifs.urlfile.prefix=http://hostname:8080/alfresco/

cifs.broadcast=192.168.0.255
cifs.bindto=192.168.0.123

I hope this helps!</description>
		<content:encoded><![CDATA[<p>Hi Curtis,<br />
thanks for feedback.</p>
<p>I&#8217;m preparing a new guide for version 3.3g and I&#8217;ll try to highlight those custom sections. New article will be more up to date and also simplify some stuff and have some corrections.</p>
<p>As for now, I can give you a quick list:<br />
passthru.authentication.servers=DOMAIN\\192.168.0.1,192.168.0.1<br />
passthru.authentication.defaultAdministratorUserNames=AD_usernames</p>
<p>ldap.authentication.java.naming.provider.url=ldap://domain.local:389<br />
ldap.synchronization.java.naming.security.principal=user@domain.local<br />
ldap.synchronization.java.naming.security.credentials=YourPass<br />
ldap.synchronization.groupQuery=<br />
ldap.synchronization.groupDifferentialQuery=<br />
ldap.synchronization.personQuery=<br />
ldap.synchronization.personDifferentialQuery=<br />
ldap.synchronization.groupSearchBase=dc\=domain,dc\=local<br />
ldap.synchronization.userSearchBase=dc\=domain,dc\=local</p>
<p>filesystem.domainMappings=DOMAIN<br />
filesystem.domainMappings.value.DOMAIN.rangeFrom=192.168.0.0<br />
filesystem.domainMappings.value.DOMAIN.rangeTo=192.168.0.255</p>
<p>cifs.localname=HOSTNAME<br />
cifs.domain=DOMAIN<br />
cifs.urlfile.prefix=http://hostname:8080/alfresco/</p>
<p>cifs.broadcast=192.168.0.255<br />
cifs.bindto=192.168.0.123</p>
<p>I hope this helps!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Curtis</title>
		<link>http://www.anotherstrangerme.com/alfresco-integration-with-active-directory/comment-page-2/#comment-680</link>
		<dc:creator>Curtis</dc:creator>
		<pubDate>Thu, 17 Jun 2010 21:11:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.anotherstrangerme.com/?p=11#comment-680</guid>
		<description>Ivan, I appreciate your documentation too.  Thanks.  I&#039;m running CE3.3 and so far this is the best explanation I&#039;ve seen.

In the examples you&#039;ve provided above it would be helpful if I knew which settings needed to be set specifically for my domain.  It&#039;s obvious that some of the entries must be changed (IP addresses, etc.) but I&#039;m uncertain about some of the others.

Can you give us (newbies) a little more info on the settings that are site-specific?  Thanks in advance!</description>
		<content:encoded><![CDATA[<p>Ivan, I appreciate your documentation too.  Thanks.  I&#8217;m running CE3.3 and so far this is the best explanation I&#8217;ve seen.</p>
<p>In the examples you&#8217;ve provided above it would be helpful if I knew which settings needed to be set specifically for my domain.  It&#8217;s obvious that some of the entries must be changed (IP addresses, etc.) but I&#8217;m uncertain about some of the others.</p>
<p>Can you give us (newbies) a little more info on the settings that are site-specific?  Thanks in advance!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

