Can't share files to a LDAP user

Install LDAP and connect to Active Directory

When I type the LDAP user account in the sharing filed, the user name should be showed up.

When I type the LDAP user account in the sharing filed,
1.If the LDAP filter of Groups is "(&(|(objectclass=group)))", I can't find any users in sharing filed.
2.If the LDAP filter of Groups is "(&(|(objectclass=top)))", I can see the users in the sharing filed. But there's an (GROUP) beside the username, eg. owncloluduser (Group). If I login the owncloud with this user "ownclouduser", I can't see any sharing folder for this account.

ubuntu 16.04 LTS

apache2 2.4.18

MariaDB 10.0.31

PHP 7.0.22

fresh install

No errors have been found.

Hi all,
I'm new to ubuntu and owncloud. After the LDAP application installed and setup, I can see there are more than 1000 users found in the Users tab and 700 groups found in the Groups tab. While I'm going to share the file and type the username, there're no any LDAP username showed up. but gruops. If I check "Top" class in the Group, I can see LDAP show up in the sharing fieild, but there's "(group)" beside the username. If the ldap username is "clouduser" and I logon the owncloud by this user, I can't see any sharing folder from others. I don't know what the problem is.
Could anyone help me? Many thanks.

1.More than 1000 users

2. 700 Groups

3. Can't find any LDAP users

4. Check the top class

5. The LDAP user show up with "(group)"

Hi, can you show the expert Tab configuration?

Hello, here's the expert tab configuration.

I don't know how Active Directory works, but usually I'd expect something like inetOrgPerson on the Users tab and groupOfNames on the Groups tab. Also check what the Directory Settings are on the Advanced tab (User Display Name Field and Group Display Name Field).

I'm really frustrated with AD users searching. Changing some syntax and it didn't work. I just still can search the users with "(group)', even I built another testing AD and get the same answer. :frowning:

Try entering samaccountname in the first field and clearing the tables

Hi, you mean entering saaccountname here and clearing the tables here? I've tried but didn't work.

No, I mean the second screenshot, where the buttons are for clearing, you have to put samaccountname in the top space.

Internal Username Attribute

Sorry for the late response. I put the samaccountname in the top sapce but still no luck. I put all the settings again and could you help me see if there's something wrong? Many thnaks.








Hi, I use owncloud with AD, and it works for me..
My differences...
I've checked "Manually enter LDAP filters (recommended for large directories) " on first screen (server configuration)

On user tab:
GRP-Owncloud is a group for users that can acces owncloud, inside Usuaris group, our own group of users

login tab:

group tab:

connection settings:
same except time to live much bigger, 600

directory settings:
base user tree: not ou, only dc=domain, dc=coop
base group tree: same, not ou, only dc=domain,dc=coop
nested groups unchecked

I can search users, and groups

One question, when you go with an administrator user to users section, you see there all users¿?
Maybe you need to import them before from AD, or they must log on before... This have changed between previous versions...

To import them, run

sudo -u www-data ./occ user:sync "OCA\User_LDAP\User_Proxy"

to obtain users from AD directory. Manual says that this task must be put on cron to achieve the changes made to AD. There is no longer automatic update from the whole ldap...

Hi, I don't see all the user in the users tab. If the user logged in, I see him then. I need to install occ command first. Does "OCA\User_LDAP\User_Proxy" mean anything? Or I just run sudo -u www-data ./occ user:sync "OCA\User_LDAP\User_Proxy" after installing occ command? Should I modify any syntax to meet my domain? Many thanks.

the user:sync commands gets the users from your ldap server or database and lists them in your users tab

Hi Soda and Dmitry, thank you guys very much. I can search LDAP users and groups now. The root cause is I don't import the users from Active Directory. Do I need schedule the sync command in the cron job or do it manually if I add new accounts? Many thanks.

You'll need to rerun the user:sync command from time to time. It's up to you if you want to setup a cron job to run the command daily or you want to do it on demand when the AD changes.

Hi, I found the command from the administration manual and I schedule the command in cron job, it seem didn't work. Whatever I add or delete a user, it won't sync the correct status from AD to owncloud.

Syncing via cron job

crontab -e -u www-data
* */6 * * * /usr/bin/php /var/www/owncloud/occ user:sync -vvv --missing-account-action="disable" -n "OCA\User_LDAP\User_Proxy"

Try dumping the output to a file to know what's happening:

* */6 * * * /usr/bin/php /var/www/owncloud/occ user:sync -vvv --missing-account-action="disable" -n "OCA\User_LDAP\User_Proxy" >> /tmp/sync.output

In addition, check the logs for any possible errors

Hi, the interesting thing is I added the output string and got nothing in the /tmp direcotry, it seemed the job never ran...:frowning:

Maybe, in fact, the job never run.

I'm not sure about the requirements, but maybe crontab needs an active account for the www-data user in your linux machine and that account is disabled. At least my machine has the www-data account disabled by default.

You can try to set up the job in the root account and switch to the www-data via sudo:

* */6 * * * /usr/bin/sudo -u www-data /usr/bin/php /var/www/owncloud/occ user:sync -vvv --missing-account-action="disable" -n "OCA\User_LDAP\User_Proxy" >> /tmp/sync.output

Hi, I tried to set up the job in the root account, and the log file showed up which owner is www-data, but the log showed

No unknown users have been detected.
Insert new and update existing users ...

If I paste the command in root account, the accounts can be synced from AD. But the log still keeps show no unknown users have been detected.

I want to schedule this crontab just in case I changed the AD users/groups and forget to sync them from AD manually.

root@ycmcloud:/tmp# /usr/bin/sudo -u www-data /usr/bin/php /var/www/owncloud/occ user:sync -vvv --missing-account-action="disable" -n "OCA\User_LDAP\User_Proxy" >> /tmp/sync.output