cogAuthenticate users against an Active Directory server (LDAP). Note that this a paying application.
Recommended
TypeXAR
CategoryApplication
Developed by

XWiki SAS

Rating
Rate!
1 Votes
LicenseGNU Lesser General Public License 2.1
Installable with the Extension Manager

Description

The Active Directory application is designed to be used for synchronization of the users and groups from XWiki and Active Directory server. With this application, users will be able to authenticate on XWiki using the credentials from Active Directory server instead of creating new XWiki accounts. 

UI Administration page

In order to access the Active Directory UI, go to Administration and look in the Application category.

administerWiki.png

applicationsCategory.png

Connection settings

The Check connection button helps to check in real time that the authentication credentials are correct.

connectionSettings.png

FieldDescriptionDefault 
Active Directory server addressThe address of the Active Directory server127.0.0.1
Active Directory server portThe port of the Active Directory server389
Active Directory server login matchingThe full Distinguish Name (dn) of the Active Directory user. E.g: cn=Admin,cn=Users,dc=localN/A
Active Directory password matchingThe password of the login matchingN/A

Configuration

The Active Directory application comes with a set of default values configured, so the user only needs to specify the Base DN and the setup is done.

configuration.png

FieldDescriptionDefault 
Active Directory Base DNThe Base DN is the root of the tree where the server performs the search. E.g: dc=localN/A

Advanced

In order to provide a custom configuration to the application, click on Show Advanced Configuration and start exploring all the available options.

advanced.png

advanced1.png

FieldDescriptionDefault
Enable the Active Directory authentificationIf enabled and configured properly, a local user will be created whenever an Active Directory user visit this wiki for the first timeYes
Active Directory UID attribute nameSpecifies the Active Directory attribute containing the identifier to be used as the XWiki user name.sAMAccountName
Active Directory user fields mappingSpecifies the Active Directory attribute that contains the photo image. last_name=sn,first_name=givenName,email=mail,company=company,comment=comment,phone=mobile
Active Directory groups mappingMap an Active Directory group to a XWiki group. E.g: XWiki.XWikiAdminGroup->cn=Admin,ou=Groups,dc=localN/A

advanced2.png

FieldDescriptionDefault
Restrict to groupOnly the members of the following Active Directory group can authenticate. If you leave empty, all the users from the Base DN will be verified. E.g: cn=Devs,ou=Grups,dc=localN/A
Active Directory group to excludeThe users that are member of the following group can't authenticate. E.g: cn=Designers,ou=Grups,dc=localN/A
Try local loginIf Active Directory authentication fails for any reason, try XWiki DB authentication with the same credentialsYes
Update user from Active Directory after loginIf 'Yes', update the mapped attributes from Active Directory to XWiki on every login, else the mapping will be updated only when the user is created.Yes
Update user photo from LDAPIf 'Yes', the XWiki avatar will be synchronized with the Active Directory on every login, else the photo will not be updated.No
Active Directory groups cache expirationTime in seconds after which the list of members in a group is refreshed from Active Directory.21600 (6 hours)
When to synchronize the Active Directory groupsSynchronize groups at creation or always (at each authentication of a user).Always

Price

This application costs 99 euros/year and you get the following:

  • 1 year license: By purchasing an XWiki Application License, you'll benefit from it during one year.
  • Free updates: You benefit from all the application updates during one year. You are always up to date.
  • Support included: If you are facing an issue, you can reach the XWiki support. Our team is always available to help.

Regarding VAT:

  • If you are in the EU and have a VAT number there is no VAT to add to the price
  • If you are in the EU and don't have a VAT number there is the VAT of your country to add to the price
  • If you are outside the EU there is no VAT to add to the price

Support

If you're having a problem installing or using this application please send a mail to the support.

Prerequisites & Installation Instructions

We recommend using the Extension Manager to install this extension (Make sure that the text "Installable with the Extension Manager" is displayed at the top right location on this page to know if this extension can be installed with the Extension Manager).

You can also use the following manual method, which is useful if this extension cannot be installed with the Extension Manager or if you're using an old version of XWiki that doesn't have the Extension Manager:

  1. Log in the wiki with a user having Administration rights
  2. Go to the Administration page and select the Import category
  3. Follow the on-screen instructions to upload the downloaded XAR
  4. Click on the uploaded XAR and follow the instructions

This is a Paying extension and it requires a license to become usable. In order to get a trial or a full license, got to the Administration > Applications > Licenses section in your wiki instance.

Installing in subwikis

Each (sub)wiki can have its own UI for configuring LDAP and thus it's possible to have different settings per wiki. The only restriction is that the Active Directory application must be installed first in the main wiki before it can be installed in other subwikis.

Release Notes

v1.2

  • Provide default values for existing properties
  • Mark in the UI the default values that will be used
  • Set the sAMAccountName as default uid attribute name
  • Map by default all the AD attributes that are matching an XWiki user property
  • Simplify the UI by splitting the Configuration into simple and advanced
  • The following translations have been updated:
    • English
    • French

v1.1

  • Introduced the Check connection button for live validation of authentication credentials.
  • Enable the AD Authenticator automatically and without editing xwiki.cfg
  • Enable local users by default when AD is active

Dependencies

  • com.xwiki.activedirectory:application-activedirectory-main 1.2
  • org.xwiki.rendering:xwiki-rendering-macro-message 8.4
  • org.xwiki.platform:xwiki-platform-rendering-macro-include 8.4
  • org.xwiki.platform:xwiki-platform-rendering-macro-velocity 8.4
Tags:
Created by Administrator on 2016/09/28 15:11