<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Kommentare zu: AD Integration Roadmap [Updated]</title>
	<atom:link href="http://blog.ecw.de/archives/55/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.ecw.de/archives/55</link>
	<description>The home of problems nobody else has.</description>
	<lastBuildDate>Wed, 21 Dec 2011 10:57:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>Von: Amol C</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-885</link>
		<dc:creator>Amol C</dc:creator>
		<pubDate>Tue, 13 Dec 2011 04:56:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-885</guid>
		<description>Hello,

Thanks for the wonderful AD module, it has worked very easily and was the only module which got connected to my AD server without any issue. 

Please can you plan a similar module for drupal.</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Thanks for the wonderful AD module, it has worked very easily and was the only module which got connected to my AD server without any issue. </p>
<p>Please can you plan a similar module for drupal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: cst</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-884</link>
		<dc:creator>cst</dc:creator>
		<pubDate>Tue, 06 Dec 2011 12:05:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-884</guid>
		<description>Hello Mike,
I don&#039;t know how you organize your posts and groups/roles, but it is as you suspect. In WordPress every user has ONE (1) role and ADI maps the first matching AD group (from left to right) to the corresponding WordPress role. There is no way (as far as I know) to let users have more than one role in WordPress.</description>
		<content:encoded><![CDATA[<p>Hello Mike,<br />
I don&#8217;t know how you organize your posts and groups/roles, but it is as you suspect. In WordPress every user has ONE (1) role and ADI maps the first matching AD group (from left to right) to the corresponding WordPress role. There is no way (as far as I know) to let users have more than one role in WordPress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Mike</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-883</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Fri, 02 Dec 2011 22:05:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-883</guid>
		<description>If a person is in two groups in active directory and i have content based on groups will a person see the content from both groups or just the first group in order left to right?

Thanks

Mike</description>
		<content:encoded><![CDATA[<p>If a person is in two groups in active directory and i have content based on groups will a person see the content from both groups or just the first group in order left to right?</p>
<p>Thanks</p>
<p>Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: cst</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-882</link>
		<dc:creator>cst</dc:creator>
		<pubDate>Mon, 28 Nov 2011 18:13:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-882</guid>
		<description>Do you think you have set the right base_dn? www.olot.local looks very unusual. Have you tried base_dn = dc=olot,dc=local</description>
		<content:encoded><![CDATA[<p>Do you think you have set the right base_dn? <a href="http://www.olot.local" rel="nofollow">http://www.olot.local</a> looks very unusual. Have you tried base_dn = dc=olot,dc=local</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: cst</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-881</link>
		<dc:creator>cst</dc:creator>
		<pubDate>Mon, 28 Nov 2011 18:08:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-881</guid>
		<description>Hi Nick,
if you have an urgent need for this feature, I should implement it soon.

I think you&#039;re from germany, so let&#039;s talk german. Sende mir einfach eine E-Mail an cst@ecw.de und beschreibe mal, wie genau ihr euch die Umsetzung vorstellt, welche Anforderungen ihr habt.</description>
		<content:encoded><![CDATA[<p>Hi Nick,<br />
if you have an urgent need for this feature, I should implement it soon.</p>
<p>I think you&#8217;re from germany, so let&#8217;s talk german. Sende mir einfach eine E-Mail an <a href="mailto:cst@ecw.de">cst@ecw.de</a> und beschreibe mal, wie genau ihr euch die Umsetzung vorstellt, welche Anforderungen ihr habt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: nickb</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-880</link>
		<dc:creator>nickb</dc:creator>
		<pubDate>Mon, 28 Nov 2011 16:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-880</guid>
		<description>Hi Christoph,
do you have any plans to implement the &quot;authenticate against multiple domains&quot;-TODO-Point? This option sounds really great and of course, our government agency really needs that functionaltiy to authenticate users e.g. from domains like domain1.gov and domain2.gov through our wordpress server. Or do you know any other plugins / solutions for that prob.?
Thanks in advance and best wishes,
nick</description>
		<content:encoded><![CDATA[<p>Hi Christoph,<br />
do you have any plans to implement the &#8220;authenticate against multiple domains&#8221;-TODO-Point? This option sounds really great and of course, our government agency really needs that functionaltiy to authenticate users e.g. from domains like domain1.gov and domain2.gov through our wordpress server. Or do you know any other plugins / solutions for that prob.?<br />
Thanks in advance and best wishes,<br />
nick</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Wil</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-879</link>
		<dc:creator>Wil</dc:creator>
		<pubDate>Tue, 25 Oct 2011 13:06:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-879</guid>
		<description>I have a new install with wordpress 3.2.1 (not multisite) and ADI 1.1.1 and afterI trying some versions of ADI and wordpress I could&#039;nt make it work fine. This is my log in wp 3.2.1 and ADI 1.1.1:
openLDAP installed
[INFO] method authenticate() called
[INFO] ------------------------------------------
PHP version: 5.2.4-2ubuntu5.18
WP version: 3.2.1
ADI version: 1.1.1
OS Info : Linux AJ03WEB 2.6.24-28-virtual #1 SMP Fri Jun 18 13:25:12 UTC 2010 i686
Web Server : apache2handler
adLDAP ver.: 3.3.2 Extended (201104081456)
------------------------------------------
[NOTICE] username: johnny
[NOTICE] password: **not shown**
[INFO] Options for adLDAP connection:
- account_suffix: @olot.local
- base_dn: dc=www,dc=olot,dc=local
- domain_controllers: X.X.X.X
- ad_port: 389
- use_tls: 0
- network timeout: 0
[NOTICE] adLDAP object created.
[INFO] max_login_attempts: 3
[INFO] users failed logins: 0
[NOTICE] trying account suffix &quot;@olot.local&quot;
[ERROR] Authentication failed
[WARN] storing failed login for user &quot;johnny&quot;

What can I change in ADI? 
Thanks CST!!</description>
		<content:encoded><![CDATA[<p>I have a new install with wordpress 3.2.1 (not multisite) and ADI 1.1.1 and afterI trying some versions of ADI and wordpress I could&#8217;nt make it work fine. This is my log in wp 3.2.1 and ADI 1.1.1:<br />
openLDAP installed<br />
[INFO] method authenticate() called<br />
[INFO] &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
PHP version: 5.2.4-2ubuntu5.18<br />
WP version: 3.2.1<br />
ADI version: 1.1.1<br />
OS Info : Linux AJ03WEB 2.6.24-28-virtual #1 SMP Fri Jun 18 13:25:12 UTC 2010 i686<br />
Web Server : apache2handler<br />
adLDAP ver.: 3.3.2 Extended (201104081456)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
[NOTICE] username: johnny<br />
[NOTICE] password: **not shown**<br />
[INFO] Options for adLDAP connection:<br />
- account_suffix: @olot.local<br />
- base_dn: dc=www,dc=olot,dc=local<br />
- domain_controllers: X.X.X.X<br />
- ad_port: 389<br />
- use_tls: 0<br />
- network timeout: 0<br />
[NOTICE] adLDAP object created.<br />
[INFO] max_login_attempts: 3<br />
[INFO] users failed logins: 0<br />
[NOTICE] trying account suffix &#8220;@olot.local&#8221;<br />
[ERROR] Authentication failed<br />
[WARN] storing failed login for user &#8220;johnny&#8221;</p>
<p>What can I change in ADI?<br />
Thanks CST!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Carsten</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-874</link>
		<dc:creator>Carsten</dc:creator>
		<pubDate>Mon, 08 Aug 2011 14:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-874</guid>
		<description>Hi Christoph

I was not getting my user meta data filled in wordpress. 
The reason was I was choosing &quot;displayName&quot; as the &quot;Display name&quot;, thinking it would co-relate to wordpress&#039; &quot;Display name publicly as&quot;.

This had the effect that I coukld authenticate, but none of my user meta data was transferred from LDAP/AD to WP.

Going back to sAMAccountName did the job, but that now makes ma surname (login name) appear in al posts instead of the full name that I desire.

Goal: How can I make the display name within WP automatically be the displayName of Active Directory ? I don&#039;t wnat any manual job to be done here.

many thanks!

Carsten</description>
		<content:encoded><![CDATA[<p>Hi Christoph</p>
<p>I was not getting my user meta data filled in wordpress.<br />
The reason was I was choosing &#8220;displayName&#8221; as the &#8220;Display name&#8221;, thinking it would co-relate to wordpress&#8217; &#8220;Display name publicly as&#8221;.</p>
<p>This had the effect that I coukld authenticate, but none of my user meta data was transferred from LDAP/AD to WP.</p>
<p>Going back to sAMAccountName did the job, but that now makes ma surname (login name) appear in al posts instead of the full name that I desire.</p>
<p>Goal: How can I make the display name within WP automatically be the displayName of Active Directory ? I don&#8217;t wnat any manual job to be done here.</p>
<p>many thanks!</p>
<p>Carsten</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: cst</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-873</link>
		<dc:creator>cst</dc:creator>
		<pubDate>Fri, 05 Aug 2011 09:34:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-873</guid>
		<description>Hi Eduardo,
I can reproduce this behavior but this is what I&#039;ve expected. &quot;It&#039;s not a bug, it&#039;s a feature.&quot;

And I don&#039;t know any workaround. When you logon from a Windows Workstation the hostname is passed the along with the credentials to AD. But when you use LDAP (like ADI does) there is no LDAP attribute for the hostname to be sent. As a result the AD can not know from where (host) you want to logon. It won&#039;t work, even if you enter the hostname of your web server to the list of allowed workstations.

Sorry
Christoph</description>
		<content:encoded><![CDATA[<p>Hi Eduardo,<br />
I can reproduce this behavior but this is what I&#8217;ve expected. &#8220;It&#8217;s not a bug, it&#8217;s a feature.&#8221;</p>
<p>And I don&#8217;t know any workaround. When you logon from a Windows Workstation the hostname is passed the along with the credentials to AD. But when you use LDAP (like ADI does) there is no LDAP attribute for the hostname to be sent. As a result the AD can not know from where (host) you want to logon. It won&#8217;t work, even if you enter the hostname of your web server to the list of allowed workstations.</p>
<p>Sorry<br />
Christoph</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Eduardo</title>
		<link>http://blog.ecw.de/archives/55/comment-page-2#comment-872</link>
		<dc:creator>Eduardo</dc:creator>
		<pubDate>Thu, 04 Aug 2011 17:17:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ecw.de/?p=55#comment-872</guid>
		<description>Hello,

 We are using 1.1.1 version and we&#039;ve found a little problem whem de user acount has defined to logon on especified workstation.
 If the user has defined the workstations to logon, they can&#039;t logon on the Active Directory Integration, but if we desactive this option the user can logon succesfully.
This option is located on: User Properties &gt;&gt; Accont ?? Logon Workstations.

There is some away to work in this type of environment?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p> We are using 1.1.1 version and we&#8217;ve found a little problem whem de user acount has defined to logon on especified workstation.<br />
 If the user has defined the workstations to logon, they can&#8217;t logon on the Active Directory Integration, but if we desactive this option the user can logon succesfully.<br />
This option is located on: User Properties &gt;&gt; Accont ?? Logon Workstations.</p>
<p>There is some away to work in this type of environment?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

