<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication admin user with AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179125#M177056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry for any delay!&lt;/P&gt;&lt;P&gt;Well I did read user Auth fail on Authorization Policy when rule contain group with special character.&lt;/P&gt;&lt;P&gt;This problem exist in ACS 5.x as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Apr 2013 01:52:49 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-04-18T01:52:49Z</dc:date>
    <item>
      <title>Authentication admin user with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179120#M176773</link>
      <description>&lt;P&gt;hey!&lt;/P&gt;&lt;P&gt;Am having an issue with admin groups.&lt;/P&gt;&lt;P&gt;am trying to do en external authentication with AD users but fails with a : Authentication failure for user: Eric : No admin groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All seems fine, autorisation policy, Menu acces, Data access AD group binding with ISE Super Admin group&lt;/P&gt;&lt;P&gt;My user is ok on AD ( not locked, expired or anything )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone got that problem before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179120#M176773</guid>
      <dc:creator>eric.lessard</dc:creator>
      <dc:date>2019-03-11T03:17:38Z</dc:date>
    </item>
    <item>
      <title>Authentication admin user with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179121#M176815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possible defect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCud31796" target="_blank"&gt;CSCud31796&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ISE - External RBAC fails if user member of group containing apostrophe &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;RBAC utilizing an external identity store (AD, LDAP) group mapping fails for a user with the correct group(s) to gain access to the ISE GUI. The following message will be displayed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authentication failure for user: username : No admin groups"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;The user is a member of a group which contains the apostrophe character.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;No workaround exists within ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Rename all groups in the external identity store such that they do not contain apostrophes&lt;/P&gt;&lt;P&gt;2. Remove users participating in ISE administration from any external groups that contain apostrophes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 00:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179121#M176815</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-11T00:38:22Z</dc:date>
    </item>
    <item>
      <title>Authentication admin user with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179122#M176866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I'm having a similar issue, however my AD group doesn't have any apostrophe charachters.&amp;nbsp; The only 'non standard' characters it has is some spaces " " and a "&amp;amp;" symbol, could this cause the same problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 14:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179122#M176866</guid>
      <dc:creator>Zachary McGibbon</dc:creator>
      <dc:date>2013-04-12T14:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication admin user with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179123#M176937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Zach,&lt;/P&gt;&lt;P&gt;My groups didnt have an apostrophe but my OU did...&lt;/P&gt;&lt;P&gt;mydomain.local/admin groups/doesn't need auth/ISe_admin&amp;nbsp; ( kinda group )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i dont wanna replace Cisco TAC teams but:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Log into ISE using a working admin user and navigate to Administration &amp;gt; System &amp;gt; Logging &amp;gt; Debug Log Configuration&lt;/P&gt;&lt;P&gt;2. Select the admin node from the "Node list" on the right and click the "Edit" button&lt;/P&gt;&lt;P&gt;3. Turn up the&amp;nbsp; logging level of the "nfs" and "identity-store-AD" components (click on&amp;nbsp; the current log level and change it to TRACE)&lt;/P&gt;&lt;P&gt;4. Try to log in using the failing user.&lt;/P&gt;&lt;P&gt;5. Navigate to Operations &amp;gt; Troubleshoot &amp;gt; Download Logs and select your admin node&lt;/P&gt;&lt;P&gt;6. Click the "Debug Logs" item in the right pane&lt;/P&gt;&lt;P&gt;7. Download the file "ise-psc.log"&amp;nbsp; search for the last auth fail with yur user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thats how i did find my problematic groups.&lt;/P&gt;&lt;P&gt;I asked the tac engeneer to update the &lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCud31796" rel="nofollow" target="_blank"&gt;CSCud31796&lt;/A&gt; to include the OU names, not only groups&lt;/P&gt;&lt;P&gt;Hope that help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by the way:&lt;/P&gt;&lt;P&gt;1- will be fixed in release 1.2&lt;/P&gt;&lt;P&gt;2- the apostrophe actually stop the group membership comparaison&lt;/P&gt;&lt;P&gt;3- didnt test it yet but i suspect that any comparason rules, aka memberof in any policy.. wont work because of that&lt;/P&gt;&lt;P&gt;to fix that, in addition to Jatin Comments, you could put yur user in the TOP level groups lets say: mydomain.local/admin groups/1-admin_ise&lt;/P&gt;&lt;P&gt;this way, the appostrophe wont be hit before matching the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx to Jatin Also&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ce message a été modifié par: Eric Lessard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 17:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179123#M176937</guid>
      <dc:creator>eric.lessard</dc:creator>
      <dc:date>2013-04-12T17:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication admin user with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179124#M177001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx Jatin! &lt;/P&gt;&lt;P&gt;see my comment below... do you know if in fact it would also impact any policy rules based on membership ? or is it only affecting admin access?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 17:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179124#M177001</guid>
      <dc:creator>eric.lessard</dc:creator>
      <dc:date>2013-04-12T17:49:55Z</dc:date>
    </item>
    <item>
      <title>Authentication admin user with AD</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179125#M177056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry for any delay!&lt;/P&gt;&lt;P&gt;Well I did read user Auth fail on Authorization Policy when rule contain group with special character.&lt;/P&gt;&lt;P&gt;This problem exist in ACS 5.x as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 01:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-admin-user-with-ad/m-p/2179125#M177056</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-18T01:52:49Z</dc:date>
    </item>
  </channel>
</rss>

