[ome-users] ome-users Digest, Vol 51, Issue 2 -LDAP use case- LDAP groups synchronization

Cornelissen, Frans [PRDBE] FCORNELI at its.jnj.com
Wed Jun 3 08:14:58 BST 2009


Hi,

We have the same sort of request for LDAP:

-our users and groups will be defined in LDAP
-synchronize(pull) that user + GROUP info into the OMERO security system
on a regular (daily,hourly) basis

thanks,
best regards, frans

Message: 5
Date: Tue, 02 Jun 2009 13:52:52 +0100
From: Huw Lynes <lynesh at cardiff.ac.uk>
Subject: Re: [ome-users] Omero.Web Error: PermissionDeniedException
To: Zoltan Cseresnyes <zcseresn at gmail.com>
Cc: ome-users at lists.openmicroscopy.org.uk
Message-ID: <1243947172.3452.16.camel at w609.insrv.cf.ac.uk>
Content-Type: text/plain
. 

I'm now preparing to configure against LDAP. Our LDAP is pretty unusual
for example I have to set 

pam_password nds
tls_checkpeer no
tls_reqcert never
tls_cacertfile /path/to/my/rootcert.pem

Is there a list of all the available attributes that omero.ldap accepts
somewhere? Then I can try to translate my openldap client config to an
omero client config.

Cheers,
Huw

-- 
Huw Lynes                       | Advanced Research Computing
HEC Sysadmin                    | Cardiff University
                                | Redwood Building, 
Tel: +44 (0) 29208 70626        | King Edward VII Avenue, CF10 3NB

------------------------------

Message: 6
Date: Tue, 2 Jun 2009 17:28:10 +0100
From: Aleksandra Tarkowska <aleksandrat at lifesci.dundee.ac.uk>
Subject: Re: [ome-users] Omero.Web Error: PermissionDeniedException
To: Huw Lynes <lynesh at cardiff.ac.uk>
Cc: OME-users mailing list <ome-users at lists.openmicroscopy.org.uk>
Message-ID:
	<9B5340D6-43D0-44AF-A269-2699F2BA9E76 at lifesci.dundee.ac.uk>
Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes

Hi Huw

Basic configuration for LDAP plugin is available on our website
http://www.openmicroscopy.org.uk/site/support/omero4/server/install-ldap

If it does not match your criteria can you please send me in private  
more details about your LDAP and authentication? Your feedback would  
definitely be useful. It's not one of our testing system.

Thanks
Ola

On 2 Jun 2009, at 13:52, Huw Lynes wrote:

> I'm now preparing to configure against LDAP. Our LDAP is pretty  
> unusual
> for example I have to set
>
> pam_password nds
> tls_checkpeer no
> tls_reqcert never
> tls_cacertfile /path/to/my/rootcert.pem
>
> Is there a list of all the available attributes that omero.ldap  
> accepts
> somewhere? Then I can try to translate my openldap client config to an
> omero client config.

------------------------------
Message: 8
Date: Wed, 3 Jun 2009 11:31:38 +0800
From: Stephen Ogg <stephen.ogg at imb.a-star.edu.sg>
Subject: [ome-users] LDAP use case
To: <ome-users at lists.openmicroscopy.org.uk>
Message-ID: <52DE373E-BBB8-49C5-B952-C742BC0A28EC at imb.a-star.edu.sg>
Content-Type: text/plain; charset="US-ASCII"; format=flowed; delsp=yes

Hi Omero users-
I have an omero instantiation that I'd like to do more than just  
authenticate with LDAP. I have an LDAP server where I've created users  
and groups (about 150 users and maybe 15 groups) that I use to allow  
authentication and directory services for all of our microscope  
resources. I'd like to get this information into omero from the ldap  
server rather than recreate it within the omero administrative  
interface.
Anybody know whether this is possible? I checked out the install-ldap  
pages at the openmicroscopy website and I don't think that this is one  
of the use cases that is currently supported?

I do have omero currently configured to authenticate using our ldap  
server and that is working well, but users authenticate without  
bringing any group information with them.

I use the ldap to provide group information for users and to  
synchronise our users authentication credentials between unix/linux  
and windows machines.

Thanks for any suggestions -
Steve
_______________________________________________
End of ome-users Digest, Vol 51, Issue 2
****************************************



More information about the ome-users mailing list