[Dspace-tech] LDAP permssion

2013-06-20 Thread Webshet, Sisay (ILRI)

Hi All,

We are using dspace 3.1/xmlui version.
We implemented LDAP/SSL. Our e-people  doesn't have the same permission  as the 
normal dsapce/password login when they login through the LDAP.

Any hint on this









--
This SF.net email is sponsored by Windows:

Build for Windows Store.

http://p.sf.net/sfu/windows-dev2dev___
DSpace-tech mailing list
DSpace-tech@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/dspace-tech
List Etiquette: https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette

Re: [Dspace-tech] LDAP permssion

2013-06-20 Thread helix84
On Thu, Jun 20, 2013 at 9:47 AM, Webshet, Sisay (ILRI)
s.webs...@cgiar.org wrote:
 We implemented LDAP/SSL. Our e-people  doesn’t have the same permission  as
 the normal dsapce/password login when they login through the LDAP.

Use login.specialgroup and/or login.groupmap.* to assign LDAP users to
DSpace groups as described in
https://wiki.duraspace.org/display/DSDOC3x/Authentication+Plugins#AuthenticationPlugins-ConfiguringLDAPAuthentication

Keep in mind that LDAP groups are assigned dynamically, only for the
duration of the login session, so user's membership in such group
won't be visible to the administrator using the usual tools. You may,
however, check the effective group membership in the user's profile
while he's logged in.


Regards,
~~helix84

Compulsory reading: DSpace Mailing List Etiquette
https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette

--
This SF.net email is sponsored by Windows:

Build for Windows Store.

http://p.sf.net/sfu/windows-dev2dev
___
DSpace-tech mailing list
DSpace-tech@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/dspace-tech
List Etiquette: https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette

Re: [Dspace-tech] LDAP permssion

2013-06-20 Thread Alan Orth
Thanks, Helix.

In this case the problem was that this particular user had registered 
with an email address (long before we moved to LDAP) which didn't match 
that of the email address in LDAP; ie ao...@example.org instead of 
a.o...@example.org.  We added the user to the appropriate groups and 
all is well.

Cheers,

Alan

On 06/20/2013 11:14 AM, helix84 wrote:
 On Thu, Jun 20, 2013 at 9:47 AM, Webshet, Sisay (ILRI)
 s.webs...@cgiar.org wrote:
 We implemented LDAP/SSL. Our e-people  doesn’t have the same permission  as
 the normal dsapce/password login when they login through the LDAP.
 Use login.specialgroup and/or login.groupmap.* to assign LDAP users to
 DSpace groups as described in
 https://wiki.duraspace.org/display/DSDOC3x/Authentication+Plugins#AuthenticationPlugins-ConfiguringLDAPAuthentication

 Keep in mind that LDAP groups are assigned dynamically, only for the
 duration of the login session, so user's membership in such group
 won't be visible to the administrator using the usual tools. You may,
 however, check the effective group membership in the user's profile
 while he's logged in.


 Regards,
 ~~helix84

 Compulsory reading: DSpace Mailing List Etiquette
 https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette

 --
 This SF.net email is sponsored by Windows:

 Build for Windows Store.

 http://p.sf.net/sfu/windows-dev2dev
 ___
 DSpace-tech mailing list
 DSpace-tech@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/dspace-tech
 List Etiquette: 
 https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette

-- 
Alan Orth
alan.o...@gmail.com
http://alaninkenya.org
http://mjanja.co.ke
I have always wished for my computer to be as easy to use as my telephone; my 
wish has come true because I can no longer figure out how to use my telephone. 
-Bjarne Stroustrup, inventor of C++


--
This SF.net email is sponsored by Windows:

Build for Windows Store.

http://p.sf.net/sfu/windows-dev2dev
___
DSpace-tech mailing list
DSpace-tech@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/dspace-tech
List Etiquette: https://wiki.duraspace.org/display/DSPACE/Mailing+List+Etiquette