Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Intelligence (Analytics)
Windows Ad_User management settings
actuser9
<p>Hi BIRT Gurus, </p>
<p> </p>
<p>We have set up our iHub3.1 environment with Windows Ad user management setting, and it works well for users and the privileges on ihub3. Based on the groups base DN, the security groups are being shown in the ihub3 sever but the when the folders are shared with the groups, the users under the groups are not able to view the folder or reports.</p>
<p> </p>
<p>Is this an existing issue? Is there any possible workaround for this issue?</p>
<p> </p>
<p>Thank you!</p>
Find more posts tagged with
Comments
Clement Wong
<p>I have an iHub 3.1 integrated with Active Directory and have groups working. Here are my settings as seen from System Console:</p>
<p> </p>
<p><span style="font-family:'courier new', courier, monospace;">*Group Base DN: DC=somewhere,DC=com<br>
Group Description Attribute: displayname<br>
*Group Object: group<br>
Group Search Filter:</span></p>
<p> </p>
<p> </p>
<p>Have you contacted the Support team yet? They should be able to assist you in troubleshooting the issue, and they will want to know the Group definitions you have defined from System Console.</p>
jar
<p>When you select a user in the ihub administration and look at the assigned usergroups are they there...?</p>
<p> </p>
<p>We had an issue that the groups where visible in iHub administration and when selecting the group the users where visible but from the user the groups where not. This was caused by our configuration in LDAP. We had sub-folders in the people tree and iHub seems to expect the users in the root of the USER Base DN.</p>
<p> </p>
<p>It might work when all sub-folders are configured in sysconsole but we had 120+ sub-folders so that was not an option. We opted to remove the sub-folder structure (had the sub-folder name added as an attribute for each user). So we have all users in the root of our people tree.</p>
<p> </p>
<p>Might be related to your problem...</p>
<p> </p>
<p>Jeroen</p>
actuser9
<p>Hi Clement, </p>
<p> </p>
<p>Yes, we were going back on forth on this for more than 2 months now. And finally the issue seems to be the same as explained by Jeroen below.</p>
<p> </p>
<p>Hi Jeroen,</p>
<p> </p>
<blockquote class="ipsBlockquote" data-author="jar" data-cid="142108" data-time="1454559447">
<div>
<p>When you select a user in the ihub administration and look at the assigned usergroups are they there...?</p>
<p> </p>
</div>
</blockquote>
<p>Yes.</p>
<p> </p>
<blockquote class="ipsBlockquote">
<p>We had an issue that the groups where visible in iHub administration and when selecting the group the users where visible but from the user the groups where not. This was caused by our configuration in LDAP. We had sub-folders in the people tree and iHub seems to expect the users in the root of the USER Base DN.</p>
<div>
<p> </p>
<p>It might work when all sub-folders are configured in sysconsole but we had 120+ sub-folders so that was not an option. We opted to remove the sub-folder structure (had the sub-folder name added as an attribute for each user). So we have all users in the root of our people tree.</p>
<p> </p>
<p>Might be related to your problem...</p>
</div>
</blockquote>
<p>That is exactly the scenario we are having, thanks a bunch for responding. </p>
<p> </p>
<p>Our SA's would not want to make any changes to the users sub-folders, so I have tested with giving sub-folders user base DN configured in system console. I tested it and that works. The down side is when new OU are created I will have to follow up and add these to the system console config. :mellow: Hope this will be fixed in future releases.</p>
camuneke
<p>Hi my name is Chika and I would like to interject into this conversation. JIRA IHUB-565 has been filed and will be reviewed in the development process. At this time we do not know if this would be in a future release. To summarize the work around are as follows:</p>
<p> </p>
<p>1. Make a linear active directory structure where users and groups are all in the same folder</p>
<p>2. Specify each individual subfolder in your LDAP properties (2000 Character limit)</p>
<p>3. Write your own custom RSSE</p>