Author Topic: LDAP Integration  (Read 2089 times)

jeffs42885

  • Guest
LDAP Integration
« on: July 01, 2015, 05:40:38 AM »
I have a customer that is using the CMOD client to retrieve documents and they would like to use LDAP. I have never integrated/setup CMOD using LDAP, and I am just wondering if there is any point to using it when using the thick client, compared to if we were using ODWEK.

Thanks!

Justin Derrick

  • IBM Content Manager OnDemand Consultant
  • Administrator
  • Hero Member
  • *****
  • Posts: 2231
  • CMOD Guru for hire...
    • View Profile
    • Tenacious Consulting
Re: LDAP Integration
« Reply #1 on: July 01, 2015, 08:31:28 AM »
LDAP with CMOD is a bit of a mess.

The snag is that CMOD only uses LDAP for password authentication -- not any of the other things that LDAP is good for, like centrally maintaining group membership, and assigning permissions through those group memberships.  So you end up maintaining a list of CMOD Users & Groups, even if LDAP is enabled and working.

IBM Lab Services has some code that helps with LDAP (and SSO), so the best way forward is to work with them if you want to do anything over and above simple password authentication.

-JD.

IBM CMOD Professional Services: http://TenaciousConsulting.com
Call:  +1-866-533-7742  or  eMail:  jd@justinderrick.com
IBM CMOD Wiki:  https://CMOD.wiki/
FREE IBM CMOD Education & Webinars:  https://CMOD.Training/

Interests: #AIX #Linux #Multiplatforms #DB2 #TSM #SP #Performance #Security #Audits #Customizing #Availability #HA #DR

Alessandro Perucchi

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 1002
    • View Profile
Re: LDAP Integration
« Reply #2 on: July 07, 2015, 01:57:41 AM »
Personally I don't think the LDAP integration is a mess :-D but that's my own view :-D

But that's true, LDAP with CMOD is only used for password authentication and nothing more.
Meaning you can have the same password as any other system using the same LDAP server.

For the authorisation / group /... then CMOD needs to manage them, and LDAP is useless for that part.
Alessandro Perucchi

#Install #Migrations #Conversion #Educate #Repair #Upgrade #Migrate #Enhance #Optimize #AIX #Linux #Multiplatforms #DB2 #Windows #Oracle #TSM #Tivoli #Performance #Audits #Customizing #Availability #HA #DR #JavaApi #ContentNavigator #ICN #WEBi #ODWEK #Services #PDF #AFP #XML