Not logged in. · Lost password · Register
Forum: General Help and Support Installation and Configuration RSS
How do you configure local ACLs with AD?
Avatar
payner #1
User title: Rich
Member since Jun 2009 · 3 posts
Group memberships: Members
Show profile · Link to this post
Subject: How do you configure local ACLs with AD?
Hi,

I'm new to dokuwiki and while it works well enough I'm having problems setting up authentication. That is, I set up AD easily enough, but with AD enabled I can have the wiki either completely open (but allowing login) or completely colosed.

My requirements seem simple enough, AD for authentication (which is working), login required (working, sort of) and ACLs set locally. I don't have any permissions or access to the AD server, and am not likely to get it. But I need to set up the wiki so that users need to login and use ACLs assigned locally. The desired setup is for most users to have read access and a few admin access.

When I first set up AD the wiki was completely open, but the login feature worked fine with the AD username and password.

When I tried to set the ACLs, everything broke. I can still login, but I get

    Permission Denied
    Sorry, you don't have enough rights to continue. Perhaps you forgot to login?

This is before and after login.

I assume this is because group membership is set through AD only.

How can I set group membership locally with AD authentication?

Or am I going about this all wrong?
Avatar
payner #2
User title: Rich
Member since Jun 2009 · 3 posts
Group memberships: Members
Show profile · Link to this post
I've figured a partial workaround.

After polling the active directory server I found the base group name and set the acl.auth.php for read permissions for @ALL (1) and R/W permissions (8) for the AD group. I may set the @ALL group for 0.

Problem: if I set the @ALL permissions to 0, connecting to the wiki gives an error rather than a login screen. There were in the past (1997 or so) a few plugins that took users not logged in to the login screen but they are no longer available.

Problem: No admin account. I have no admin login and can't configure one.

There is no reason that AD logins need to be tied to the AD groups that I can see. In my case and many others this creates a difficult problem. There are many users on the net looking for a solution to this problem but I've not seen any answers posted.
Close Smaller – Larger + Reply to this post:
Verification code: VeriCode Please note the verification code from the picture into the text field next to it.
Smileys: :-) ;-) :-D :-p :blush: :cool: :rolleyes: :huh: :-/ <_< :-( :'( :#: :scared: 8-( :nuts: :-O
Special characters:
Go to forum
Imprint
This board is powered by the Unclassified NewsBoard software, 20090606-dev, © 2003-8 by Yves Goergen
Current time: 2010-03-21, 20:52:23 (UTC +01:00)
WikiForumIRCBugsGitXRefTranslate