Set up LDAP for Authentication Only¶
Use this procedure to set up LDAP to only authenticate users in VOSS-4-UC. Users may be added locally, or synced from Cisco Unified CM. Users who are LDAP synced in Cisco Unified CM and then synced into VOSS-4-UC will be LDAP authenticated by default. Users who are manually configured in Cisco Unified CM and then synced into VOSS-4-UC will not be LDAP authenticated by default. Users who are manually configured in VOSS-4-UC also will not be LDAP authenticated by default. The default behavior can be changed using the procedures described in View and Update LDAP Authentication Users.
Note
LDAP for Authentication Only is available at hierarchy nodes that have an LDAP server. Therefore, LDAP for Authentication Only is not available for users created at the site level.
Important
When LDAP Authentication Only is used (check box selected), then the CUCM LDAP Directory Name for the LDAP server must be filled in.
When more than one LDAP server sync is created and this is not filled in, no LDAP users will be created and a warning message will be seen in the transaction log.
Procedure¶
- Log in as provider, reseller, or customer administrator.
- Set the hierarchy path to the node where you have set up the LDAP server you want to use to authenticate users.
- Choose LDAP Management > LDAP User Sync.
- Click Add.
- On the Base tab, provide this information:
Field | Description |
---|---|
LDAP Server | Choose the LDAP Server you are authenticating users at. |
LDAP Authentication Only | Important: Select this check box to use the LDAP server only to authenticate users. Default = Cleared. When cleared, users are synced from the configured LDAP directory and their passwords are authenticated against the configured LDAP directory. When selected:
|
User Model Type | This read-only field identifies which LDAP object, defined in the configured LDAP server, is used to authenticate users. |
LDAP Authentication Attribute | Choose the LDAP Attribute to be used to authenticate users. This field is mandatory. Options are:
These are the same values Unified CM users for LDAP Attribute for User ID. Caveats (AD only) For the following types of users, do not select userPrincipalName, unless the userPrincipalName value was set as the Username when the user was created:
For users synced from LDAP into Unified CM and then into VOSS-4-UC: Caveats (AD and OpenLDAP) For users synced from LDAP into Unified CM and then into VOSS-4-UC:
If you sync users from LDAP into Unified CM using employeeNumber, choose employeeNumber for the LDAP Authentication Attribute. However, to get the LDAP Authentication to work properly, one of these conditions must be met:
|
- Click Save.
All users that have SyncToHierarchy set to the hierarchy of the LDAP server now use the LDAP server for authentication. The users are added to the LDAP Authentication Users list.