zoukankan      html  css  js  c++  java
  • 『SharePoint 2010』Sharepoint 2010 Form 身份认证的实现(基于AD)

    一。进管理中心,创建一个应用程序,配置如下:

      

    二。填端口号,和选择form身份认证,以及填写成员和角色,其他都默认就可以了 

     

     三。使用SharePoint 2010 Management Shell在里面填写下面的代码

     $webApp = Get-SPWebApplication "http://cd-isbunet:82"
    $webApp.UseClaimsAuthentication = 1;
    $webApp.Update()
    $webApp.ProvisionGlobally()
    $webApp = Get-SPWebApplication "http://cd-isbunet:82"
    $webApp.MigrateUsers($True)

    http://cd-isbunet:82 是我刚才创建的应用程序,你需要改成你自己的

    四。最重要的一步,修改管理中心,我们创建的应用程序,还有Web服务里面的SecurityTokenServiceApplication(2007是不需要配置这个的)这个3个地方的web.config

    1.找到管理中心的<system.web></system.web>,配置如下:

    这里先解释下里面的代码,你只需要替换

    server="cd-isbunet.ncs.corp.int-ads"   //域控的地址
    userContainer="CN=Users,DC=ncs,DC=corp,DC=int-ads"   //Users不用换 DC为你域的信息

    groupContainer="DC=ncs,DC=corp,DC=int-ads"

    connectionUsername="XXX/jiangly"  //换成自己的域管理员
    connectionPassword="123456" />

    <membership defaultProvider="AspNetSqlMembershipProvider">

    <providers>

    <!-- ADMembership-->

    <add name="ADMembership"

    type="Microsoft.Office.Server.Security.LdapMembershipProvider, Microsoft.Office.Server, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"

    server="cd-isbunet.ncs.corp.int-ads"

    port="389"

    useSSL="false"

    userDNAttribute="distinguishedName"

    userNameAttribute="sAMAccountName"

    userContainer="CN=Users,DC=ncs,DC=corp,DC=int-ads"

    userObjectClass="person"

    userFilter="(&amp;(ObjectClass=person))"

    scope="Subtree"

    otherRequiredUserAttributes="sn,givenname,cn"

    connectionUsername="XXX/jiangly"

    connectionPassword="123456" />

    <!-- ADMembership-->

    </providers>

    </membership >

    <roleManager defaultProvider="AspNetWindowsTokenRoleProvider" enabled ="true">

    <providers>

    <add name="roleManager"

    type="Microsoft.Office.Server.Security.LdapRoleProvider, Microsoft.Office.Server, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"

    server="cd-isbunet.ncs.corp.int-ads"

    port="389"

    useSSL="false"

    groupContainer="DC=ncs,DC=corp,DC=int-ads"

    groupNameAttribute="cn"

    groupNameAlternateSearchAttribute="samAccountName"

    groupMemberAttribute="member"

    userNameAttribute="sAMAccountName"

    dnAttribute="distinguishedName"

    groupFilter="(&amp;(ObjectClass=group))"

    userFilter="(&amp;(ObjectClass=person))"

    scope="Subtree"

    connectionUsername="XXX/jiangly"

    connectionPassword="123456" />



    </providers>

    </roleManager>

    2.找到应用程序的<system.web></system.web>,配置如下:

    <machineKey validationKey="D35D48269B8B92E8A7D86FB64FBFCC4B2B4F1E3A0BFC43FB" decryptionKey="FEA7B512E6E390C18283E0D2E0542564F1E47E1F0A80F335" validation="SHA1" />
    <membership defaultProvider="i">

    <providers>

    <add name="i" type="Microsoft.SharePoint.Administration.Claims.SPClaimsAuthMembershipProvider, Microsoft.SharePoint, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c" />

    <!-- ADMembership-->

    <add name="ADMembership" type="Microsoft.Office.Server.Security.LdapMembershipProvider, Microsoft.Office.Server, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"

    server="cd-isbunet.ncs.corp.int-ads"

    port="389" useSSL="false"

    userDNAttribute="distinguishedName"

    userNameAttribute="sAMAccountName"

    userContainer="CN=Users,DC=ncs,DC=corp,DC=int-ads"

    userObjectClass="person"

    userFilter="(&amp;(ObjectClass=person))"

    scope="Subtree"

    otherRequiredUserAttributes="sn,givenname,cn"

    connectionUsername="XXX/jiangly"

    connectionPassword="123456" />

    <!-- ADMembership-->

    </providers>

    </membership>

    <roleManager defaultProvider="c" enabled="true" cacheRolesInCookie="false">

    <providers>

    <add name="c" type="Microsoft.SharePoint.Administration.Claims.SPClaimsAuthRoleProvider, Microsoft.SharePoint, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c" />

    <!-- ADMembership-->

    <add name="roleManager" type="Microsoft.Office.Server.Security.LdapRoleProvider, Microsoft.Office.Server, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"

    server="cd-isbunet.ncs.corp.int-ads"

    port="389"

    useSSL="false"

    groupContainer="DC=ncs,DC=corp,DC=int-ads"

    groupNameAttribute="cn"

    groupNameAlternateSearchAttribute="samAccountName"

    groupMemberAttribute="member"

    userNameAttribute="sAMAccountName"

    dnAttribute="distinguishedName"

    groupFilter="(&amp;(ObjectClass=group))"

    userFilter="(&amp;(ObjectClass=person))"

    scope="Subtree"

    connectionUsername="XXX/jiangly"

    connectionPassword="123456" />

    <!-- ADMembership-->

    </providers>

    </roleManager>

    3.找到SecurityTokenServiceApplication站台web.config,它里面没有<system.web></system.web>,你需要自己添加

    <system.web>
    <!-- ADMembership-->

    <membership>

    <providers>

    <!-- ADMembership-->

    <add name="ADMembership"

    type="Microsoft.Office.Server.Security.LdapMembershipProvider, Microsoft.Office.Server, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"

    server="cd-isbunet.ncs.corp.int-ads"

    port="389"

    useSSL="false"

    userDNAttribute="distinguishedName"

    userNameAttribute="sAMAccountName"

    userContainer="CN=Users,DC=ncs,DC=corp,DC=int-ads"

    userObjectClass="person"

    userFilter="(&amp;(ObjectClass=person))"

    scope="Subtree"

    otherRequiredUserAttributes="sn,givenname,cn"

    connectionUsername="XXX/jiangly"

    connectionPassword="123456" />

    <!-- ADMembership-->

    </providers>

    </membership>

    <roleManager enabled ="true" >

    <providers>

    <!-- ADMembership-->

    <add name="roleManager"

    type="Microsoft.Office.Server.Security.LdapRoleProvider, Microsoft.Office.Server, Version=14.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c"

    server="cd-isbunet.ncs.corp.int-ads"

    port="389"

    useSSL="false"

    groupContainer="DC=ncs,DC=corp,DC=int-ads"

    groupNameAttribute="cn"

    groupNameAlternateSearchAttribute="samAccountName"

    groupMemberAttribute="member"

    userNameAttribute="sAMAccountName"

    dnAttribute="distinguishedName"

    groupFilter="(&amp;(ObjectClass=group))"

    userFilter="(&amp;(ObjectClass=person))"

    scope="Subtree"

    connectionUsername="XXX/jiangly"

    connectionPassword="123456" />

    <!-- ADMembership-->

    </providers>

    </roleManager>

    </system.web>

    五。我们进管理中心-》应用程序管理-》打开用户策略-》添加域中的用户(如果没有找到,说明你的web.config里要修改的参数不对)

    六。创建网站集,然后打开站点登陆,如果一切正常就能进入站点了

    祝你成功!

    这里特别感谢foley!

    参考资料:

    (1)http://www.microsofttranslator.com/bv.aspx?ref=Internal&from=en&to=zh-CHS&a=http%3a%2f%2fblogs.msdn.com%2fb%2frussmax%2farchive%2f2009%2f12%2f31%2fconfiguring-forms-based-authentication-for-claims-based-web-applications.aspx

    (2)http://isharebook.com/forums/showthread.php/2649-Claims-Based-Identity-in-SharePoint-2010.html

    (3)http://blogs.technet.com/b/speschka/archive/2009/11/05/configuring-forms-based-authentication-in-sharepoint-2010.aspx

    (4)http://xiangzhangjun2006.blog.163.com/blog/static/44140966201061334818612/

    转自http://www.cnblogs.com/jlydboy/articles/1792112.html

  • 相关阅读:
    『PyTorch』第二弹_张量
    大数据技术之_12_Sqoop学习_Sqoop 简介+Sqoop 原理+Sqoop 安装+Sqoop 的简单使用案例+Sqoop 一些常用命令及参数
    HBase 构建 Scanner 体系图解
    HBase 默认刷写文件 flush_compact.xml 注释解析
    Vim 命令、操作、快捷键全集
    10个在UNIX或Linux终端上快速工作的建议
    如何三招帮你排查Linux中的硬件问题
    介绍一些有趣的MySQL pager命令
    MySQL数据库select语句的使用方法
    能够在Linux系统中运行的5款大型耐玩游戏
  • 原文地址:https://www.cnblogs.com/Areas/p/5006221.html
Copyright © 2011-2022 走看看