Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Content Management (Extended ECM)
API, SDK, REST and Web Services
Authenticating Livelink against an external domain
George_Rathbun
Has anyone re-written the Livelink Authentication so that it authenticates against something other than the Livelink database. We have a daemon service that allows us to authenticate web users against our NT, Unix and database domains. I would like to be able to call this service from within Livelink to insure all Livelink access utilizes this authentication method. Any help is appreciated.
Find more posts tagged with
Comments
Paul_Eddie_(PEddie_(Delete)_801545)
There are some solutions such as checking the browser environment variable in netscape to see if the user is authenticated by the netscape ldap server. If you are happy with browser environment variable, then it is possible to have livelink authenticated by an external source. If you need more info contact me, ateddie@opentext.comCheers,Paul
George_Rathbun
Eddie,I can appreciate your response and have spoken with a number of folks at Opentext regarding my request. I have 2 issues with respect to using ldap and the browser value remote_user. One, we don't have an ldap which we can authenticate against and the last thing I want to do is put another username password domain online. The second, I want to insure that my ODMA clients also authenticate properly not just web clients. As I understand it, allowing web to access Livelink based on the value of remote_user requires us to disable passwords for users in Livelink. This would be dangerous. A user can then access Livelink using an ODMA client and simply providing a username value.I would much rather be able to overide the authentication piece in Livelink by calling a C client that we have which in turn would access our daemon to check authentication. This would insure that any access to Livelink would be authenticated properly.
Bill_Morton
>As I understand it, allowing web to access Livelink based>on the value of remote_user requires us to disable>passwords for users in Livelink. This would be dangerous.>A user can then access Livelink using an ODMA client and>simply providing a username value.The Livelink Directory Services module provides authentication for both web- and LAPI access. The web access is authenticated by the HTTP server and Livelink uses the REMOTE_USER variable with a "hidden" password. The LAPI access is by username/password which is authenticated by Livelink against the external service (configurable as LDAP or NTLM).If your daemon has (or can be modified to have) an LDAP interface, then the Directory Services stuff should work with it. Otherwise, it should be possible to customize the Directory Services module to work with your daemon. -Bill
insystems_rnd_insystems_rnd
Is it possible to figure out the "hidden" password? We have a problem regarding this issue. Our product integrates with LiveLink including custom OScripts. In our OScript component, we capture user/password and send back to the browser and the browser invokes another component that uses LAPI. So user/password is abusoltely necessary in this case without login twice. However when we use NTLM, our OScript component can not capture password for our LAPI component so we have to login twice (one for web-access and another for LAPI-access). How can we solve this problem?Thanks-jhuang@insystems.com
eLink User
Message from Simone Oettinger via eLinkPerhaps you can capture the cookie and login to LAPI using the cookie.Simone-----Original Message-----From: knowledge@opentext.com [mailto:knowledge@opentext.com]On Behalf OfeLink Discussion: Development DiscussionSent: Monday, April 02, 2001 3:27 PMTo: eLink RecipientSubject: Is it possible to figure out the "hidden" password?Is it possible to figure out the "hidden" password?Posted by insysrnd on 04/02/2001 04:23 PMIs it possible to figure out the "hidden" password?We have a problem regarding this issue. Our product integrates with LiveLinkincluding custom OScripts. In our OScript component, we captureuser/password and send back to the browser and the browser invokes anothercomponent that uses LAPI. So user/password is abusoltely necessary in thiscase without login twice. However when we use NTLM, our OScript componentcan not capture password for our LAPI component so we have to login twice(one for web-access and another for LAPI-access).How can we solve this problem?Thanks-jhuang@insystems.com[To reply to this thread, use your normal e-mail reply function.]============================================================Topic: Authenticating Livelink against an external domain
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=2130761&objAction=viewDiscussion
: Development Discussion
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=786303&objAction=viewLivelink
Server:
https://knowledge.opentext.com/knowledge/livelink.exe
eLink User
Message from Sean M Alderman via eLinkWe tracked down the oscript that generates the cookie for a custom login function for part of our system. Would you like me to dig up where it's at for you?At 04:47 PM 04/02/2001 -0400, you (eLink Discussion: Development Discussion) wrote:>RE Is it possible to figure out the "hidden" password? >Posted by eLink on 04/02/2001 04:47 PM>>Message from Simone Oettinger via eLink>>Perhaps you can capture the cookie and login to LAPI using the cookie.>Simone>>-----Original Message----->From: knowledge@opentext.com [mailto:knowledge@opentext.com]On Behalf Of>eLink Discussion: Development Discussion>Sent: Monday, April 02, 2001 3:27 PM>To: eLink Recipient>Subject: Is it possible to figure out the "hidden" password?>>>Is it possible to figure out the "hidden" password?>Posted by insysrnd on 04/02/2001 04:23 PM>>Is it possible to figure out the "hidden" password?>We have a problem regarding this issue. Our product integrates with LiveLink>including custom OScripts. In our OScript component, we capture>user/password and send back to the browser and the browser invokes another>component that uses LAPI. So user/password is abusoltely necessary in this>case without login twice. However when we use NTLM, our OScript component>can not capture password for our LAPI component so we have to login twice>(one for web-access and another for LAPI-access).>How can we solve this problem?>>Thanks>-jhuang@insystems.com>>[To reply to this thread, use your normal e-mail reply function.]>>============================================================>>Topic: Authenticating Livelink against an external domain>
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=2130761&>objAction=view>>Discussion
: Development Discussion>
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=786303&o>bjAction=view>>Livelink
Server:>
https://knowledge.opentext.com/knowledge/livelink.exe>>[To
reply to this thread, use your normal e-mail reply function.]>>============================================================>>Topic: Authenticating Livelink against an external domain>
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=2130761&objAction=view>>Discussion
: Development Discussion>
https://knowledge.opentext.com/knowledge/livelink.exe?func=ll&objId=786303&objAction=view>>Livelink
Server:>
https://knowledge.opentext.com/knowledge/livelink.exe-
Sean M. AldermanITRACK Systems AnalystPACE/NCI - NASA Glenn Research Center(216) 433-2795