You do not want too much now do you ? I hope you have a *really* good TS guy on site. You can add different authentication methods to TS easily. That will allow you to start using AD instead of LDAP. Same login/passwd ? Well that depends on if AD and LDAP use the same DB, we do not know. You *may* need to use idmap to map the ID and permissions from the LDAP to AD if they are different.TS roles are per server (DEV, UAT, PROD) so you do not need to worry about giving out too much on DEV. MB, no clue. LS should not be effected, OD could be, depending on how you use it (if people log into the OD GUI).
Thank you so much for your response ..i really like DevNet pplActually i am gonna do that on a new server windows 2003 R2 instead of doing manually adding users and roles as you said, Is there a way like copying the roles.xml and iwusers.xml in existing server to new server and using them?And if we we are managing user like this using admin Tab do we need to use in user_database.xml? Thank you.
TS always relied on the external Authentication mechanisms, be it OS, DAS, LDAP, Kerberos and whatnot.To configure LDAP Authentication you absolutely must use user_database.xml. Internal User managementis for the Authorization only (directly and through Groups/FlexRoles)
authenticate_by=ldap ldap_server=ldap-server ldap_port=ldap-port ldap_dnbase=search-base-location ldap_key=key
[authentication]ldapcache_thread_delay=1440log_ldap_sync=yesldap_sync_retry=12
I don't know if you still need the LDAP changes in iw.cfg, I think the user_database.xml supersedes it. RE: roles, you can put the roles in LDAP and manage things that way with respect to choice #3. I tend to do #1, but then I have had installs with 100-200 users and ones that do not change quite often.
Compatibility and Limitations of LDAP Authentication:- Perl presentation templates do not support non-OS users. You must use XSLT presentation templates.- External tasks written in Perl do not support non-OS users. You must use Java for your external tasks
These are strictly speaking some limitations for the non-OS users, not LDAP per se.With LDAP, you can configure OS Users, non-OS Users or a mix.
So, Mix means u r saying both OS and non-OS user in same DB? My assumption is we can configure Two different LDAP servers where we use one for OS and one for Non OS .Correct me if i am wrong.Question:I am killing the existing AD and configuring user_databse.xml to support LDAP which have non-OS Users only. And plan is to create freshly all users, roles and groups using ADMIN TAB as we have very less number of users and groups.Will this create new tsuser.xml , roles.xml and tsgroups? If so what about the existing files. Do i have to delete them? or iwreset.exe will overwrite the existing files?My another concern is we are using OD GUI how this new LDAP configuration will effect OD? I also want his Up and running.Thanks in advance.
Ok. I did get answer for my other questions I am killing the existing AD and configuring user_databse.xml to support LDAP which have non-OS Users only. And plan is to create freshly all users, roles and groups using ADMIN TAB as we have very less number of users and groups.Will this create new tsuser.xml , roles.xml and tsgroups? If so what about the existing files. Do i have to delete them? or iwreset.exe will overwrite the existing files?My another concern is we are using OD GUI how this new LDAP configuration will effect OD? I also want his Up and running.Thanks in advance.
Hi all,we want to change our authentication from AD to LDAP. Where our current users should be able to use same Id and PW to login to teamsite by selecting a different domain. Security will need to be changed from a model based on OS users and groups to a model based on non-OS users and groups.Questions :1.What are the steps that i need to follow to migrate authorization and users (current users and groups) from current domain to LDAP?2.What are the side effects we use the same LDAP attribute to store Authorization settings for DEV, UAT and PROD. Does this means a user with master rights on DEV also gets master rights on PROD ?3. If above one is true .Then what i have to do if we want to have different Authorization settings for DEV, UAT and PROD ?5. We are using Mediabin and ecm connector 2.0 also what changes do i need to make ecm connector connection settings?4. Will there be any side effects on OpenDeploy and LiveSite ?ENV: TS:6.7.2OD:6.2LS:3.1MB:4.6.2ecm:2.0Awaiting for response ..Thanks in advance.
The Support Article #: 60790 mentions the step required to move Mediabin from AD to LDAP and LDAP to AD.