Rethinking the Active Directory integration
We're looking at a series of bug reports related to the Active Directory integration in FotoWeb, and will start work on improving this feature with the goal of closing it for good. We're making the following assumptions based on the communication we've had with you:
- It is sufficient to update an account and group memberships during log in, hence the background synchronization is not needed
- Groups in Groups are used for giving access to FotoWeb, so we must support group hierarchies
The following features will disappear:
- Import of users; users will only be imported/synced when logging in
- Treating Organizational Units (OUs) as groups
- Support for Novell as very, very few are using it
Setting up Active Directory integration will follow the steps outlined below:
- Create rights groups in Active Directory for the roles you want defined in FotoWeb, e.g. 'FotoWeb Archive Administrators', 'FotoWeb Users with Upload', 'FotoWeb Read Only Users' and add the groups/users you want into these groups.
- Set up the integration in FotoWeb and select the groups created in the step above.
- Set up your archives and access lists using these groups
- Log in using your AD username and password (or Single-Sign-On). The account will be created in FotoWeb and all groups will be updated. Note that only selected groups from step 2 will be synced, all intermediate groups will only exist in Active Directory.
We're planning to start this work in a couple of weeks time, and look forward to your comments or questions so that we are sure to move in the right direction.