Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
LDAP authentication
eturock
Is there a way to completely authenticate a teamsite user (meaning uid, groups, TS roles) through LDAP alone (no uid files) using either the authenticate_by=ldap or authenticate_by=pam methods?
authenticate_by=ldap seems to allow authentication of uid and TS role only, without user group validation. Haven't been able to get authenticate_by=pam to work yet, but it seems that would definitely get me user and group authentication though not TS roles.
What is the proper way, if any, to use LDAP with Teamsite to retrieve all of the info.?
Find more posts tagged with
Comments
JonathonG
What OS and TeamSite version are you using?
When you say "group information", are you talking about groups for file permissions?
If so, and if you're on Solaris, I believe there's a way to set up LDAP as the authentication method for Solaris. TeamSite just asks the OS for group information, so if you're OS is set up to query LDAP, it should work.
If any of the assumptions I make above are untrue, please post detailed environment information and exactly what you are trying to accomplish.
Jonathon
Independent Interwoven Contractor
tlemke
There is a way to do this on Solaris, however we tried to set it up on 5.6 and it caused a core dump when we used LDAP to define roles. We took the roles piece out (i.e., went back to TS roles files) and it worked fine.
I don't know whether Interwoven ever fixed the bug, but it's something to be aware of if you try to set it up.
Tim Lemke
Convergys Corporation
Edited by tlemke on 12/15/03 08:24 AM (server time).
sunil_j
When you say OS to Querry LDAP ..what do you mean by that ? How can OS be setup to Querry LDAP ?
Regards
Sunil
Technical Consultant
Sydney (Australia)
JonathonG
That would be a question for your system administrator. I've never done it on Solaris, I just know it can be done. it's somewhat version dependent as well, if I remember correctly (OS version, not TS version). Sorry I'm not of more help. Maybe someone else here who has done this can give you some pointers.
Jonathon
Independent Interwoven Contractor
iwovGraduate
Are you using Solaris or Windows ? I assume you are using Solaris.
OS to Query LDAP -- meaning OS will use LDAP to authenticate users instead of (or in addition to) looking at files (/etc/passwd).
There are a lot of resources for setting up Native LDAP authentication for Solaris. I think the best starting point would be Tom Bialaski's book: Solaris and LDAP Naming Services.
Also you can check the Sun website for articles/white papers on LDAP/Solaris. Any articles by Tom Bialiasky - who seems to know everything there is to know about LDAP, should be a good resource.
Setting the TS user authentication with LDAP is relatively simple once you have configured Solaris for LDAP authentication. Managing file permissions with LDAP is **in my experience** a tricky thing, which I have never attempted. (that does not necessary imply that its impossible or difficult)
I believe there is a white paper on this. You should be able to find it if you search devnet. Also there are some KB articles on this.
If you are on Windows and need to use Microsoft Active Directory, IWOV has a very nice whitepaper on this. Search the KBs.
Hope that helps.
Migrateduser
Sure, just have multiple ldap_dnbas entries in the [authentication] section of iw.cfg. Each entry would be an LDAP path to where users and groups are contained.