Difference between revisions of "Ldap-example2"

From OpenKM Documentation
Jump to: navigation, search
Line 1: Line 1:
 +
== Configuration parameters ==
 +
 +
<source lang="java">
 +
principal.adapter=com.openkm.principal.LdapPrincipalAdapter
 +
system.login.lowercase=true
 +
principal.ldap.referral=follow
 +
principal.ldap.security.credentials=*****
 +
principal.ldap.security.principal=CN=Administrator,OU=OPENKM,DC=company,DC=com
 +
principal.ldap.server=ldap://192.168.xxx.xxx:389
 +
 +
principal.ldap.mail.attribute=mail
 +
principal.ldap.mail.search.base=DC=company,DC=com
 +
principal.ldap.mail.search.filter=(&(objectclass=person)(sAMAccountName={0}))
 +
 +
principal.ldap.role.attribute=cn
 +
principal.ldap.role.search.base=DC=company,DC=com
 +
principal.ldap.role.search.filter=(objectclass=group)
 +
 +
principal.ldap.roles.by.user.attribute=memberOf
 +
principal.ldap.roles.by.user.search.base=DC=company,DC=com
 +
principal.ldap.roles.by.user.search.filter=(&(objectClass=person)(sAMAccountName={0}))
 +
 +
principal.ldap.user.attribute=sAMAccountName
 +
principal.ldap.user.search.base=DC=company,DC=com
 +
principal.ldap.user.search.filter=(&(objectClass=person)(memberOf=CN=ROLE_USER,OU=OPENKM,DC=company,DC=com))
 +
 +
principal.ldap.username.attribute=sAMAccountName
 +
principal.ldap.username.search.base=DC=company,DC=com
 +
principal.ldap.username.search.filter=(&(objectClass=person)(sAMAccountName={0}))
 +
 +
principal.ldap.users.by.role.attribute=sAMAccountName
 +
principal.ldap.users.by.role.search.base=DC=company,DC=com
 +
principal.ldap.users.by.role.search.filter=(&(objectClass=person)(memberOf=CN={0},OU=OPENKM,OU=TERCEROS,DC=company,DC=com))
 +
</source>
  
 
== OpenKM.xml ==
 
== OpenKM.xml ==
Line 8: Line 42:
 
    
 
    
 
   <beans:bean id="contextSource" class="org.springframework.security.ldap.DefaultSpringSecurityContextSource">
 
   <beans:bean id="contextSource" class="org.springframework.security.ldap.DefaultSpringSecurityContextSource">
     <beans:constructor-arg value="ldap://192.168.0.13:389"/>
+
     <beans:constructor-arg value="ldap://192.168.xxx.xxx:389"/>
 
     <beans:property name="userDn" value="CN=Administrator,OU=OPENKM,DC=company,DC=com"/>
 
     <beans:property name="userDn" value="CN=Administrator,OU=OPENKM,DC=company,DC=com"/>
 
     <beans:property name="password" value="****"/>
 
     <beans:property name="password" value="****"/>

Revision as of 21:34, 16 February 2013

Configuration parameters

 principal.adapter=com.openkm.principal.LdapPrincipalAdapter
 system.login.lowercase=true
 principal.ldap.referral=follow
 principal.ldap.security.credentials=*****
 principal.ldap.security.principal=CN=Administrator,OU=OPENKM,DC=company,DC=com
 principal.ldap.server=ldap://192.168.xxx.xxx:389

 principal.ldap.mail.attribute=mail
 principal.ldap.mail.search.base=DC=company,DC=com
 principal.ldap.mail.search.filter=(&(objectclass=person)(sAMAccountName={0}))

 principal.ldap.role.attribute=cn
 principal.ldap.role.search.base=DC=company,DC=com
 principal.ldap.role.search.filter=(objectclass=group)

 principal.ldap.roles.by.user.attribute=memberOf
 principal.ldap.roles.by.user.search.base=DC=company,DC=com
 principal.ldap.roles.by.user.search.filter=(&(objectClass=person)(sAMAccountName={0}))

 principal.ldap.user.attribute=sAMAccountName
 principal.ldap.user.search.base=DC=company,DC=com
 principal.ldap.user.search.filter=(&(objectClass=person)(memberOf=CN=ROLE_USER,OU=OPENKM,DC=company,DC=com))

 principal.ldap.username.attribute=sAMAccountName
 principal.ldap.username.search.base=DC=company,DC=com
 principal.ldap.username.search.filter=(&(objectClass=person)(sAMAccountName={0}))

 principal.ldap.users.by.role.attribute=sAMAccountName
 principal.ldap.users.by.role.search.base=DC=company,DC=com
 principal.ldap.users.by.role.search.filter=(&(objectClass=person)(memberOf=CN={0},OU=OPENKM,OU=TERCEROS,DC=company,DC=com))

OpenKM.xml

<!-- LDAP Complex -->
  <security:authentication-manager alias="authenticationManager">
    <security:authentication-provider ref="ldapAuthProvider" />
  </security:authentication-manager>
  
  <beans:bean id="contextSource" class="org.springframework.security.ldap.DefaultSpringSecurityContextSource">
    <beans:constructor-arg value="ldap://192.168.xxx.xxx:389"/>
    <beans:property name="userDn" value="CN=Administrator,OU=OPENKM,DC=company,DC=com"/>
    <beans:property name="password" value="****"/>
    <beans:property name="baseEnvironmentProperties">
      <beans:map>
        <beans:entry>
          <beans:key>
            <beans:value>java.naming.referral</beans:value>
          </beans:key>
          <beans:value>follow</beans:value>
        </beans:entry>
      </beans:map>
    </beans:property>
  </beans:bean>
 
  <beans:bean id="ldapAuthProvider" class="org.springframework.security.ldap.authentication.LdapAuthenticationProvider">
    <beans:constructor-arg>
      <beans:bean class="org.springframework.security.ldap.authentication.BindAuthenticator">
        <beans:constructor-arg ref="contextSource"/>
        <beans:property name="userSearch" ref="userSearch"/>
      </beans:bean>
    </beans:constructor-arg>
    <beans:constructor-arg>
      <beans:bean class="org.springframework.security.ldap.userdetails.DefaultLdapAuthoritiesPopulator">
        <beans:constructor-arg ref="contextSource"/>
        <beans:constructor-arg value="DC=company,DC=com"/>
        <beans:property name="groupSearchFilter" value="member={0}"/>
        <beans:property name="groupRoleAttribute" value="cn"/>
        <beans:property name="searchSubtree" value="true" />
        <beans:property name="convertToUpperCase" value="false" />
        <beans:property name="rolePrefix" value="" />
      </beans:bean>
    </beans:constructor-arg>
  </beans:bean>

  <beans:bean id="userSearch" class="org.springframework.security.ldap.search.FilterBasedLdapUserSearch">
    <beans:constructor-arg index="0" value="DC=company,DC=com" />
    <beans:constructor-arg index="1" value="sAMAccountName={0}" />
    <beans:constructor-arg index="2" ref="contextSource" />
    <beans:property name="searchSubtree" value="true" />
  </beans:bean>