[Zope] Previos post - help with windows authentication

Greg Greg" <beavis@comwww.net
Sun, 2 Jun 2002 17:34:20 -0700


This is a multi-part message in MIME format.

------=_NextPart_000_001B_01C20A5B.BA884670
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Below is a post from a user who needs very similar things I do.  I feel =
I am exactly in the same boat he is.  I want to use Zope to develop an =
Intranet.  Our network is Win 2000 based and it's easy to develop with =
IIS/ASP and then integrate the authentication of your windows users.  =
Since I found Zope, I have fallen in love with it.  It's just way to =
cool!  BUT...  I cant get the authentication to work with anything but =
the built in user folders. =20

Right now, my users can simply open a link on our Intranet sites, and my =
ASP scripts can determine who they are.  I then can use this username to =
insert into a database or other functions, like printing it on the web =
page.  With Zope, I have to maintain another set of users AND they have =
to enter a username and password to do the same thing I can do in =
IIS/ASP.

I have tried the same things Sean has.  I can see the users, but the =
authentication wont work.  I have tried setting up pcgi through IIS, and =
letting IIS authenticate me.  This would be wonderful if it worked.  I =
can see the initial index_html under the server root.  But anything else =
cannot be retrieved.

So, if anyone has any help or could point me(and Sean) in the right =
direction, please do so!=20
I appreciate any you may have. Thanks!

Greg=20


POST from Sean Kelley below =
------------------------------------------------

Kelley, Sean SKelley@ci.santa-rosa.ca.us=20
Tue, 14 May 2002 16:13:03 -0700=20

Hi,
I have posted a few messages about windows domain level security and =
zope.
I have gotten maybe one no-so-helpful response.  I don't know if people
don't know or I am forming my question wrong.  Here goes another try.

background:
I am somewhat familiar with basic zope use and canned product installs =
with
good docs but no guru and not familiar with python

I want to:
build  a zope intranet which checks to see what windows group someone
belongs to before they can do certain things- aka only my department =
users
can view and add stuff. =20
be able to allow my department users to use intranet without joining =
(CMF
requires one to join for some things) while blocking other departments- =
this
can be differentiated with windows group memberships

What I have done so far:
installed jcNTUserFolder-0.2.2=20
but all I could list was the users on local machine that Zope was =
installed
on (not the domain users or groups)
I also tried another product which worked with jcNTUserFolder and that
claimed to get NT groups also but it broke my basic zope security =
because it
was replacing files at the root zope level (I guess it hacked the main =
zope
security files)=20

I am running:
windows 2000 (with some NT users)
zope 2.5.1
CMF 1.3b (i may chuck this though if I cannot get the authentication to =
work
well)


Any help would be GREATLY appreciated.  Products, how-tos, code =
examples...

Sean=20


------=_NextPart_000_001B_01C20A5B.BA884670
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2712.300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#fffefe>
<DIV><FONT face=3DArial size=3D2>Below is a post from a user who =
needs&nbsp;very=20
similar&nbsp;things I do.&nbsp; I feel I am exactly in the same boat he=20
is.&nbsp; I want to use Zope to develop an Intranet.&nbsp; Our network =
is Win=20
2000 based and it's easy to develop with IIS/ASP and then integrate the=20
authentication of your windows users.&nbsp; Since I found Zope, I=20
have&nbsp;fallen in love with it.&nbsp; It's just way to cool!&nbsp;=20
BUT...&nbsp; I cant get the authentication to work with anything but the =
built=20
in user folders.&nbsp; </FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Right now, my users can simply open a =
link on our=20
Intranet sites, and my ASP scripts can determine who they are.&nbsp; I =
then can=20
use this username to insert into a database or other functions, like =
printing it=20
on the web page.&nbsp; With Zope, I have to maintain another set of =
users AND=20
they have to enter a username and password to do the same thing I can do =
in=20
IIS/ASP.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>I have tried the same things Sean has. =
&nbsp;I can=20
see the users, but the authentication wont work.&nbsp; I have tried =
setting up=20
pcgi through IIS, and letting IIS authenticate me.&nbsp; This would be =
wonderful=20
if it worked.&nbsp; I can see the initial index_html under the server=20
root.&nbsp; But anything else cannot be retrieved.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>So, if anyone has any help or could =
point me(and=20
Sean) in the right direction, please do so!&nbsp;</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>I appreciate any you may have. =
Thanks!</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Greg </FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>POST from Sean Kelley below=20
------------------------------------------------</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><STRONG>Kelley, Sean </STRONG><A=20
title=3D"[Zope] Help- windows authentication advice needed"=20
href=3D"mailto:SKelley@ci.santa-rosa.ca.us">SKelley@ci.santa-rosa.ca.us=20
</A><BR><I>Tue, 14 May 2002 16:13:03 -0700</I> </DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Hi,<BR>I have posted a few messages =
about windows=20
domain level security and zope.<BR>I have gotten maybe one no-so-helpful =

response.&nbsp; I don't know if people<BR>don't know or I am forming my =
question=20
wrong.&nbsp; Here goes another try.<BR><BR>background:<BR>I am somewhat =
familiar=20
with basic zope use and canned product installs with<BR>good docs but no =
guru=20
and not familiar with python<BR><BR>I want to:<BR>build&nbsp; a zope =
intranet=20
which checks to see what windows group someone<BR>belongs to before they =
can do=20
certain things- aka only my department users<BR>can view and add =
stuff.&nbsp;=20
<BR>be able to allow my department users to use intranet without joining =

(CMF<BR>requires one to join for some things) while blocking other =
departments-=20
this<BR>can be differentiated with windows group memberships<BR><BR>What =
I have=20
done so far:<BR>installed jcNTUserFolder-0.2.2 <BR>but all I could list =
was the=20
users on local machine that Zope was installed<BR>on (not the domain =
users or=20
groups)<BR>I also tried another product which worked with jcNTUserFolder =
and=20
that<BR>claimed to get NT groups also but it broke my basic zope =
security=20
because it<BR>was replacing files at the root zope level (I guess it =
hacked the=20
main zope<BR>security files) <BR><BR>I am running:<BR>windows 2000 (with =
some NT=20
users)<BR>zope 2.5.1<BR>CMF 1.3b (i may chuck this though if I cannot =
get the=20
authentication to work<BR>well)<BR><BR><BR>Any help would be GREATLY=20
appreciated.&nbsp; Products, how-tos, code examples...<BR><BR>Sean=20
<BR></DIV></FONT></BODY></HTML>

------=_NextPart_000_001B_01C20A5B.BA884670--