<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP security role issue in Esri Geoportal Server Questions</title>
    <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307730#M379</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hmmm ... &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Are the uid and cn the same value or not?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Feb 2011 16:07:43 GMT</pubDate>
    <dc:creator>CliveReece</dc:creator>
    <dc:date>2011-02-17T16:07:43Z</dc:date>
    <item>
      <title>LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307725#M374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am using GPT 9.3.1 SP1 with Tomcat 5.5.17 and Java 5 R6. Followed the default installation taking the LDAP security mode with Apache Server Directory and Apache Server Studio. I am following the installation document's mentioned usernames and groups. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Although I can login as the administrator (gptadmin), I can't see the Administration and Repositories buttons. Which means I am being authenticated but not authorized. I am probably doing something wrong in the groups and metadataManagementGroup tags. I guess the metadataManagementGroup&amp;nbsp; is not required so I commented it. Here is the snippet from gpt.xml:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;groups&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; displayNameAttribute="cn"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamicMemberOfGroupsAttribute=""&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamicMembersAttribute=""&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; memberAttribute="uniquemember"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; memberSearchPattern="(&amp;amp;amp;(objectclass=groupOfUniqueNames)(uniquemember={0}))"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; searchDIT="ou=groups,ou=system"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!-- &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;metadataManagementGroup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name="gpt_publishers"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; groupDN="cn=gpt_publishers,ou=groups,ou=system"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;metadataManagementGroup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name="gpt_administrators"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; groupDN="cn=gpt_administrators,ou=groups,ou=system"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/groups&amp;gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jul 2010 18:15:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307725#M374</guid>
      <dc:creator>AamirSuleman</dc:creator>
      <dc:date>2010-07-29T18:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307726#M375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;You've probably already done this, but check (and recheck) all your &amp;lt;ldapAdapter&amp;gt; values in the gpt.xml file.&amp;nbsp; Pay close attention to the roles definition and make sure the groupDN is right:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;role&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key="gptAdministrator"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inherits="gptPublisher"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; groupDN="cn=gpt_admin,ou=Groups,ou=geoportal"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;good luck&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 14:12:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307726#M375</guid>
      <dc:creator>CliveReece</dc:creator>
      <dc:date>2010-10-01T14:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307727#M376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i have the same problem. Authentifiat is ok but no button Administration and Repository on web page.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In &amp;lt;roles authenticatedUserRequiresRole="true"&amp;gt; : groupDN="cn=gpt_admin,ou=Groups,ou=geoportal"/&amp;gt; is right for all groups.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For exemple: groupDN="cn=***,ou=Group,dc=***,dc=***,dc=**"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;user ID is "uid" and group "cn".&amp;nbsp;&amp;nbsp; The LDAP server is install on linux system&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The role or group is not recognize by GPT.10&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank for you help&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 08:52:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307727#M376</guid>
      <dc:creator>EQUIPEIS</dc:creator>
      <dc:date>2011-02-17T08:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307728#M377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;My sympathies since I know how frustrating it can be when you can't find the error in the config file.&amp;nbsp; But since you are authenicating but not getting the right authorization (role) picked up, this *most likely* points to a config problem, and not likely an ldap service issue. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below are the gpt.xml config file places to double-check.&amp;nbsp; Use Jxplorer or your favorite Ldap management tool to go to the right place in the ldap tree and make use of the "Copy DN" function to copy/paste the right ldap distinguished name into each needed location of the gpt.xml file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Use your own ldap values for the bold values below (don't use verbatum).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. &amp;lt;roles authenticatedUserRequiresRole="true"&amp;gt;&amp;lt;role key="gptRegisteredUser" groupDN="&lt;/SPAN&gt;&lt;STRONG&gt;cn=gpt_users,ou=groups,ou=system&lt;/STRONG&gt;&lt;SPAN&gt;"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. &amp;lt;role key="gptPublisher" ... groupDN="&lt;/SPAN&gt;&lt;STRONG&gt;cn=gpt_publishers,ou=groups,ou=system&lt;/STRONG&gt;&lt;SPAN&gt;"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. &amp;lt;role key="gptAdministrator" ... groupDN="&lt;/SPAN&gt;&lt;STRONG&gt;cn=gpt_administrators,ou=groups,ou=system&lt;/STRONG&gt;&lt;SPAN&gt;"/&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4. &amp;lt;users ... searchDIT="&lt;/SPAN&gt;&lt;STRONG&gt;ou=users,ou=system&lt;/STRONG&gt;&lt;SPAN&gt;"&amp;gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5. &amp;lt;groups ... searchDIT="&lt;/SPAN&gt;&lt;STRONG&gt;ou=groups,ou=system&lt;/STRONG&gt;&lt;SPAN&gt;"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;good luck !&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 12:53:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307728#M377</guid>
      <dc:creator>CliveReece</dc:creator>
      <dc:date>2011-02-17T12:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307729#M378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi, thanks&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In my gpt.xml, the Base DN is right for all. I use Jxplorer and "Copy DN", and paste in gpt.xml. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;My admin system says that my enterprise use a linux server for LDAP and POSIX configuration for user ID "uid" (it's like: name1 name2 name3)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;GPT 10 want to read probably: "uid=name1,ou=people, cn=***,cn=***" &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The value is not configurable in GPT10.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 16:01:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307729#M378</guid>
      <dc:creator>EQUIPEIS</dc:creator>
      <dc:date>2011-02-17T16:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307730#M379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hmmm ... &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Are the uid and cn the same value or not?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 16:07:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307730#M379</guid>
      <dc:creator>CliveReece</dc:creator>
      <dc:date>2011-02-17T16:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307731#M380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;EQUIPE-IS,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I spoke with another colleague about this.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Since it sounds like your authentication is working but the configuration can't determine which groups a user belongs to, and because you're working on a POSIX setup we haven't encountered before, there may be several issues to resolve.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We determine group membership like this:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[INDENT]memberSearchPattern="(&amp;amp;amp;(objectclass=groupOfUniqueNames)(uniquemember={0}))"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;searchDIT="ou=groups,ou=system"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[/INDENT]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;This results in an LDAP query:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[INDENT]searchDIT="ou=groups,ou=system" ... (this starts the query from this LDAP node)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;objectclass=groupOfUniqueNames ... (this restricts the search to group objects only.&amp;nbsp; The name of the objectclass varies with the LDAP implementation)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;uniquemember={0} ... (further restricts the search to those groups that have a �??uniquemember�?� attribute equal to a value that we will substitute at {0}. The name of the attribute that holds the member values varies with the LDAP implementation.) [/INDENT]&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When determining the groups to which the user belongs, we substitute {0} with the active user�??s distinguished name (dn). This is very likely the issue with POSIX. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For POSIX the memberSearchPattern would probably look something like this:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[INDENT]memberSearchPattern="(&amp;amp;amp;(objectclass=posixGroup)(memberUid={0}))"[/INDENT]&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But we may need to substitute the user�??s �??uid�?� attribute at {0} rather than their distinguished name.&amp;nbsp; There may also be issues with recursion (groups that are members of groups).&amp;nbsp; We also list the members of a group (for instance, when a an admin transfers ownership), this would also need some work.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It's also likely that we won't solve all these issues through configuration only.&amp;nbsp; We would likely need to make a few changes on the back-end.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 12:24:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307731#M380</guid>
      <dc:creator>CliveReece</dc:creator>
      <dc:date>2011-02-18T12:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307732#M381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Ok thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i'll try with this exemple and if it doesn't work, i find another solution or wait the update version.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 14:31:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307732#M381</guid>
      <dc:creator>EQUIPEIS</dc:creator>
      <dc:date>2011-02-18T14:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307733#M382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;i work on this problem to connect geoportal to my group of ldap this week. And i don't find any issues.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Your comment is very good :"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;POSIX the memberSearchPattern would probably look something like this:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;memberSearchPattern="(&amp;amp;amp;(objectclass=posixGroup)(memberUid={0}))"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;But we may need to substitute the user�??s �??uid�?� attribute at {0} rather than their distinguished name. There may also be issues with recursion (groups that are members of groups). We also list the members of a group (for instance, when a an admin transfers ownership), this would also need some work"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Because objectclass is posix Group and attribute is memberUid in my Ldap.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; i try to find in this log the dn of the group but no result.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; displayNameAttribute="cn"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamicMemberOfGroupsAttribute=""&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamicMembersAttribute=""&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; memberAttribute="memberUid"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; memberSearchPattern="(&amp;amp;amp;(objectclass=posixGroup)(memberUid={0}))"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; searchDIT="ou=Group,dc=***,dc=***,dc=***"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also, i try to configure the SSO with tomcat and it's the same issue.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please do you have any suggestions ! and can i send you the log of access ldap to see if you find a solution ? thanks a lot&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2014 17:56:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307733#M382</guid>
      <dc:creator>EQUIPEIS</dc:creator>
      <dc:date>2014-04-10T17:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP security role issue</title>
      <link>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307734#M383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi, i post you my ldap log, do you have any comment, thank's a lot.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt; conn=1105064 fd=68 slot=68 connection from 10.*.*.* to 10.*.*.*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=0 BIND dn="uid=***,ou=people,dc=***,dc=***,dc=***" method=128 version=3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn="uid=***,ou=people,dc=***,dc=***,dc=***"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=1 SRCH base="uid=***,,dc=***,dc=***" scope=2 filter="(&amp;amp;(objectClass=person)(&lt;/SPAN&gt;&lt;STRONG&gt;uid=***&lt;/STRONG&gt;&lt;SPAN&gt;))" attrs=ALL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=1 RESULT err=0 tag=101 nentries=1 etime=0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105065 fd=69 slot=69 connection from 10.*.*.* to 10.*.*.*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105065 op=0 BIND dn="uid=***,ou=people,dc=***,dc=***,dc=***" method=128 version=3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105065 op=0 RESULT err=0 tag=97 nentries=0 etime=0 dn="uid=***,ou=people,dc=***,dc=***,dc=***"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105065 op=1 UNBIND&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105065 op=1 fd=69 closed - U1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=2 SRCH base="uid=***,ou=people,dc=***,dc=***,dc=***" scope=0 filter="(objectClass=*)" attrs=ALL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=2 RESULT err=0 tag=101 nentries=1 etime=0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=3 SRCH base=",ou=group,dc=***,dc=***,dc=***" scope=2 filter="(&amp;amp;(objectClass=posixgroup)(memberUid=&lt;/SPAN&gt;&lt;STRONG&gt;uid=***,ou=people,dc=***,dc=***,dc=***&lt;/STRONG&gt;&lt;SPAN&gt;))" attrs="cn"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=3 RESULT err=0 tag=101 nentries=0 etime=0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=4 UNBIND&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[11/Apr/2014:09:17:22 +0200] conn=1105064 op=4 fd=68 closed - U1&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 06:23:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-geoportal-server-questions/ldap-security-role-issue/m-p/307734#M383</guid>
      <dc:creator>EQUIPEIS</dc:creator>
      <dc:date>2014-04-11T06:23:20Z</dc:date>
    </item>
  </channel>
</rss>

