Set up LDAP for Authentication Only¶
This procedure sets up LDAP for authentication-only, in VOSS Automate.
Note
Users can be added locally or synced from Cisco Unified CM (CUCM):
LDAP authenticated, by default |
|
By default, not LDAP authenticated |
|
You can change the default behavior, as described in View and Update LDAP Authentication Users.
LDAP for Authentication Only is available at hierarchy nodes that have an LDAP server; thus, it is not available for users created at the site level. When enabled, you must fill out the CUCM LDAP Directory Name for the LDAP server. If two or more LDAP server syncs have been created and you don’t provide this detail, no LDAP users are created, and the transaction log displays a warning message.
To set up LDAP for authentication-only:
Log in as provider, reseller, or customer administrator.
Set the hierarchy path to the node where you have set up the LDAP server you want to use to authenticate users.
Choose LDAP Management > LDAP User Sync.
Click Add.
Fill out the relevant details:
Field |
Description |
---|---|
LDAP Server |
Choose the LDAP Server where you are authenticating users. |
LDAP Authentication Only |
Disabled by default. When disabled, users are synced from the configured LDAP directory and their passwords are authenticated against the configured LDAP directory. When enabled, the LDAP server is used only to authenticate users. When selected:
|
User Model Type |
Read-only. Identifies the LDAP object (defined in the configured LDAP server), used to authenticate users. |
LDAP Authentication Attribute |
Choose the LDAP Attribute to be used to authenticate users. This field is mandatory. Options are:
These are the same values Unified CM users for LDAP Attribute for User ID. AD (Active Directory) only: For the following types of users, do not select userPrincipalName, unless the userPrincipalName value was set as the Username when the user was created:
For users synced from LDAP into Unified CM and then into VOSS Automate: Caveats (AD and OpenLDAP) For users synced from LDAP into Unified CM and then into VOSS Automate:
If you sync users from LDAP into CUCM using employeeNumber, choose employeeNumber for the LDAP Authentication Attribute. However, to get the LDAP Authentication to work properly, one of these conditions must be met:
|
Click Save.
All users that have
SyncToHierarchy
set to the hierarchy of the LDAP server now use the LDAP server for authentication. The users are added to the LDAP Authentication Users list.