<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic acs 5.2 and non AD ldap in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820671#M198491</link>
    <description>&lt;P&gt;I must be stupid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an external LDAP server, (like openldap, but it is an old netscape one).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't authenticate against it.&amp;nbsp; I can anonymous bind against it. but that is it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want groups or any attributes.&amp;nbsp; I simply want to say User X password Y, authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any time I test anything, it seems to go out to lunch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have an example of this?&amp;nbsp; What I am actually doing&lt;/P&gt;&lt;P&gt;is to authenticate PEAP-GTC for a wireless network.&amp;nbsp; I can get the request to the correct&lt;/P&gt;&lt;P&gt;external user store, but from there it doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can probably translate an openldap example.&amp;nbsp; The ldap works fine against, say Apache&lt;/P&gt;&lt;P&gt;authentication, so it is not so weird.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:49:49 GMT</pubDate>
    <dc:creator>eugene.tsuno</dc:creator>
    <dc:date>2019-03-11T01:49:49Z</dc:date>
    <item>
      <title>acs 5.2 and non AD ldap</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820671#M198491</link>
      <description>&lt;P&gt;I must be stupid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an external LDAP server, (like openldap, but it is an old netscape one).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't authenticate against it.&amp;nbsp; I can anonymous bind against it. but that is it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want groups or any attributes.&amp;nbsp; I simply want to say User X password Y, authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any time I test anything, it seems to go out to lunch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have an example of this?&amp;nbsp; What I am actually doing&lt;/P&gt;&lt;P&gt;is to authenticate PEAP-GTC for a wireless network.&amp;nbsp; I can get the request to the correct&lt;/P&gt;&lt;P&gt;external user store, but from there it doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can probably translate an openldap example.&amp;nbsp; The ldap works fine against, say Apache&lt;/P&gt;&lt;P&gt;authentication, so it is not so weird.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820671#M198491</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2019-03-11T01:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: acs 5.2 and non AD ldap</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820672#M198510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good luck: http://linux.die.net/man/8/wpa_supplicant&lt;/P&gt;&lt;P&gt;I wish i could help, but i haven't got to the wireless part yet.  I just got the hardwire to wrk.  I used a certificate created by the ACS Certificate signing and had the cert created by our inhouse CA.  I'm still trying to understand how all this works, but did you look at the monitoring logs on your failed authentication attempts?  It should give you some details.  Is your ACS Even able to pass authentication back to the LDAP to verify the client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck: http://linux.die.net/man/8/wpa_supplicant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 03:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820672#M198510</guid>
      <dc:creator>michael mearlon</dc:creator>
      <dc:date>2012-02-16T03:27:42Z</dc:date>
    </item>
    <item>
      <title>acs 5.2 and non AD ldap</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820673#M198531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I got it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was either a CAcert was wrong, or a reboot that cleared the ldap connections.&amp;nbsp; Once I tested with &lt;/P&gt;&lt;P&gt;a simple 389 server and authenticated, I could see what is supposed to be returned and my settings&lt;/P&gt;&lt;P&gt;were correct.&amp;nbsp; I redid it with ldaps, and it worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was then able to get both authenticated and unauthenticated to work, and then the whole thing&lt;/P&gt;&lt;P&gt;to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 16:52:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820673#M198531</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2012-02-16T16:52:40Z</dc:date>
    </item>
    <item>
      <title>acs 5.2 and non AD ldap</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820674#M198549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So either it was ldap connection hung, or the Cert was wrong.&amp;nbsp; When I hit the test button, either should&lt;/P&gt;&lt;P&gt;have spit up some relevant debug stuff (Connection could not be started) or like (SSL connection&lt;/P&gt;&lt;P&gt;could not be initiated)&amp;nbsp; but it just went out to lunch.&amp;nbsp; So I believe something was hung up in the box itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 17:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-and-non-ad-ldap/m-p/1820674#M198549</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2012-02-16T17:53:36Z</dc:date>
    </item>
  </channel>
</rss>

