Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
external file user authentication
mick
hi
does anyone use the option of an 'external file' for authenticating users?
can anyone shed some light on how to deal with group membership for users authenticated using this method?
reason i'm asking is that we are planning an upgrade to 5.5.2, then to 6.0, and we'd like to change the way we authenticate users. we're currently using OS level authentication but the majority of our users don't need to be OS level users -- they don't need system level access to our TS server, all they do is log in through the TS interface.
if we could remove all our users from the OS we'd make our IT support guys very happy. it'd make us happy too, since we don't have direct access to our TS server to add/remove/reconfigure user access (each change requires a service desk request!). if we could control user access using an external file it'd solve a lot of problems.
however, i can't find any information about how to actually configure this external file (apart from the manual stating it has the same format as /etc/shadow) or how to associate users with groups or where the groups are configured.
can anyone help?
mick :-)
----
currently running TS 5.0.2 under Solaris with Apache web server
Find more posts tagged with
Comments
Adam Stoller
I'd suggest contacting Support. It's possible someone out here has dealt with this before, but it's actually just as likely that they haven't - and it's possible that the option, to which you refer, was created for an individual customer years ago and nobody's used it since and it may not even still be supported ...
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
Koen
Hi there,
we're using an ldap server (netscape) to define all the users. integration with the OS (solaris) is a bit tricky, but can be done by an experienced sys admin.
it allows the TS support guys to manitain TS users through the ldap administration interface.
we're also planning to integrate this with the corporate identity system, using dirxml to synchronise usernames
cheers,
Koen
mick
yeh, LDAP would be good ... unfortunately it's not an option for us at the moment. our IT guys don't want to set up an LDAP server just for us (our department is NT based and uses Active Directory for domain logons).
mick :-)
----
currently running TS 5.0.2 under Solaris with Apache web server
gzevin
Mick,
I am afraid that you can't do much from what Koen has just described. Actually, when using LDAP, the users will still have 'accounts' on the server, but this is done trasnaparently, without any need to access local files on the server....
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
Koen
Hi Greg,
when using LDAP authentication, you have two options:
1. only use LDAP for roles and TS login
2. use LDAP for fial access as well
for 2., there are no local acounts at all: TS users don't need to be defined in the local password file.
Also, as a side issue: SUN LDAP 4 is not compatible with OD 5.6
Koen
gzevin
Koen,
this is exactly what I meant.
Greg Zevin, Ph.D. Comp. Sc.
Independent Interwoven Consultant/Architect
Sydney, AU
St_Image.png
Output_Image.png