• Do not register here on develop.twiki.org, login with your twiki.org account.
• Use View topic Item7848 for generic doc work for TWiki-6.1.1. Use View topic Item7851 for doc work on extensions that are not part of a release. More... Close
• Anything you create or change in standard webs (Main, TWiki, Sandbox etc) will be automatically reverted on every SVN update.
Does this site look broken?. Use the LitterTray web for test cases.

When you register on a TWiki with user ID and LDAP authentication setup for the apache you still get a password stored in a local .htpasswd file.

And this password is actually use by TWiki in some cases. For example when you change email address.

This is a show stopper issue for a corporate installation. LDAP authentication is LDAP authentication. There should be no local passwords.

Once the user has changed his global password many times he has no clue what it was when he registered.

This actually worked well in Cairo and is now totally broken.

KJL

OK. This is not entirely true.

But we still have an issue.

To work on a corporate Intranet with LDAP you need to

  • Configure: Set the Login Manager to TWiki::Client::ApacheLogin
  • Configure: Set the PasswordManager to None
  • Set up httpd.conf / .htaccess so the .../bin scripts gets authenticated. Not all. Just the ones that must be authenticated. viewauth in particular.

I think we still have an action to document this on Twiki.org. When I have all working I will try and write a TwikiOnLDAP topic.

We also still have the issue that email addresses in this case is not stored in the user topic.

I will close this bug and open a new so we do not forget this.

KJL

In SVN 8475 the 'none' password manager stores emails in the user topic.

CC

ItemTemplate
Summary With a LDAP authenticated TWiki on an Intranet TWiki still uses Apache password file
ReportedBy TWiki:Main.KennethLavrsen
Codebase

SVN Range Sun, 22 Jan 2006 build 8439
AppliesTo Engine
Component

Priority Urgent
CurrentState Closed
WaitingFor

Checkins 8475 8486
Edit | Attach | Watch | Print version | History: r5 < r4 < r3 < r2 < r1 | Backlinks | Raw View |  Raw edit | More topic actions
Topic revision: r5 - 2006-01-24 - CrawfordCurrie
 
This site is powered by the TWiki collaboration platform Powered by PerlCopyright © 2008-2023 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback