<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>LDAP authentication vs. local authentication</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=122527847" />
  <subtitle>LDAP authentication vs. local authentication</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=122527847</id>
  <updated>2026-04-06T19:50:35Z</updated>
  <dc:date>2026-04-06T19:50:35Z</dc:date>
  <entry>
    <title>RE: LDAP authentication vs. local authentication</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122540136" />
    <author>
      <name>Zsigmond Rab</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122540136</id>
    <updated>2024-04-12T08:22:42Z</updated>
    <published>2024-04-12T08:22:41Z</published>
    <summary type="html">&lt;p&gt;Hi Ovidiu,&lt;/p&gt;
&lt;p&gt;The behaviour may differ depending on how the LDAP is configured. Is
  both the import and export enabled? Being able to authenticate with an
  old password can happen when the export is enabled. With export, when
  a user is updated in the portal, updates immediately go to the LDAP
  side, but not always the other way around. The import from the LDAP
  side happens with different trigger points and your case may occur
  sometimes. Even if the &amp;quot;LDAP required&amp;quot; is enabled. it may be
  different also if the import is enabled or not beside the export.&lt;/p&gt;
&lt;p&gt;A workaround may be to enable 'Autogenerate User Password on
  Import' which should prevent use of stale passwords.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br&gt; Zsigmond&lt;/p&gt;</summary>
    <dc:creator>Zsigmond Rab</dc:creator>
    <dc:date>2024-04-12T08:22:41Z</dc:date>
  </entry>
  <entry>
    <title>LDAP authentication vs. local authentication</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122527846" />
    <author>
      <name>Ovidiu Moldovan</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122527846</id>
    <updated>2024-04-11T13:01:37Z</updated>
    <published>2024-04-08T13:22:45Z</published>
    <summary type="html">&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;We use Liferay 7.4 GA 106 with LDAP integration to manage internal
  users login to Liferay from the organization.&lt;/p&gt;
&lt;p&gt;All it's fine, authentication works well with small execeptions.&lt;/p&gt;
&lt;p&gt;Issue is that when a user is changing the password in LDAP then he
  can still authenticate with the old password in Liferay and password
  syncronization is happening at some point but I did not find the
  actual rule. I also tried to select &amp;quot;LDAP required&amp;quot; and
  &amp;quot;Use LDAP server policy&amp;quot; but still the user can login with
  old password sometime and new password is not entering into force.&lt;/p&gt;
&lt;p&gt;Also, I noticed that locally created accounts can still login even
  the &amp;quot;LDAP required&amp;quot; is enabled, shall this force the user to
  be authenticated only with LDAP server?&lt;/p&gt;
&lt;p&gt;Has anyone have similar situations or is there some material to
  explain how this shall work?&lt;/p&gt;
&lt;p&gt;Thank you,&lt;br&gt; Ova&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;</summary>
    <dc:creator>Ovidiu Moldovan</dc:creator>
    <dc:date>2024-04-08T13:22:45Z</dc:date>
  </entry>
</feed>
