<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Wilson, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976773#M38960</link>
    <description>&lt;P&gt;Hi Wilson,&lt;/P&gt;
&lt;P&gt;Please turn the ad_agent to DEBUG level and then look for this error message in the "show acs-logs filename ACSADAgent.log | in LW_ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS&lt;/P&gt;
&lt;P&gt;You can also share the AD agent logs with me.&lt;/P&gt;
&lt;P&gt;Let me know.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Jatin&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;~ Do rate helpful posts&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jul 2016 05:58:26 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2016-07-27T05:58:26Z</dc:date>
    <item>
      <title>ACS 5.8 unable to retrieve user group attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976772#M38959</link>
      <description>&lt;P&gt;I recently upgraded my ACS from 5.6 to 5.8 with the latest patch installed.&amp;nbsp; Since then, it's been unable to retrieve user group attributes from Windows AD, which effective breaks all my authorization policies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-The ACS-AD connector account belongs in both the "domain admins" and "domain users" group.&lt;/P&gt;
&lt;P&gt;-I have verified the AD connector account have sufficient permissions to read group attributes.&lt;/P&gt;
&lt;P&gt;-The ACS can retrieve group attributes from "domain admin" users, but not from the other groups.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have included a screenshot of the error log.&amp;nbsp; Is anyone else running into a similar issue or know how to fix it?&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976772#M38959</guid>
      <dc:creator>noticketnomas</dc:creator>
      <dc:date>2019-03-11T06:57:10Z</dc:date>
    </item>
    <item>
      <title>Hi Wilson,</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976773#M38960</link>
      <description>&lt;P&gt;Hi Wilson,&lt;/P&gt;
&lt;P&gt;Please turn the ad_agent to DEBUG level and then look for this error message in the "show acs-logs filename ACSADAgent.log | in LW_ERROR_TOKEN_GROUPS_INSUFFICIENT_PERMISSIONS&lt;/P&gt;
&lt;P&gt;You can also share the AD agent logs with me.&lt;/P&gt;
&lt;P&gt;Let me know.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Jatin&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;~ Do rate helpful posts&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 05:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976773#M38960</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-07-27T05:58:26Z</dc:date>
    </item>
    <item>
      <title>Thanks, Jatin.  Please let me</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976774#M38961</link>
      <description>&lt;P&gt;Thanks, Jatin. &amp;nbsp;Please let me know if I did this correctly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. went into acs-config. &amp;nbsp;ran "debug-adclient enable"&lt;/P&gt;
&lt;P&gt;2. show logging application ACSADAgent.log = no debug output&lt;/P&gt;
&lt;P&gt;3. show logging application ad_agent.log = a lot of debug output. &amp;nbsp;However, I don't see any error related to token groups. &amp;nbsp;I do see the following error when I manually query a domain user from the ACS:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695545640704,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmTransactAcquireCredentialsHandle()&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;,lsass/client/ntlm/clientipc.c:299&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695545640704,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmClientAcquireCredentialsHandle(),l&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;sass/client/ntlm/acquirecreds.c:84&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695545640704,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmServerAcquireCredentialsHandle(),l&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;sass/server/ntlm/acquirecreds.c:103&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695545640704,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmTransactAcquireCredentialsHandle()&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;,lsass/client/ntlm/clientipc.c:299&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695545640704,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmClientAcquireCredentialsHandle(),l&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;sass/client/ntlm/acquirecreds.c:84&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695545640704,Error code: 40506 (symbol: LW_ERROR_NO_CRED),ntlm_gss_init_sec_context(),lsass/inte&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;rop/gssntlm/gssntlm.c:891&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695514171136,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmServerAcquireCredentialsHandle(),l&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;sass/server/ntlm/acquirecreds.c:103&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695514171136,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmTransactAcquireCredentialsHandle()&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;,lsass/client/ntlm/clientipc.c:299&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695514171136,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmClientAcquireCredentialsHandle(),l&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;sass/client/ntlm/acquirecreds.c:84&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;27/07/2016 23:02:51,VERBOSE,139695514171136,Error code: 40506 (symbol: LW_ERROR_NO_CRED),NtlmServerAcquireCredentialsHandle(),l&lt;/P&gt;
&lt;P style="color: #212121; font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13px; font-variant: normal; letter-spacing: normal; line-height: 19.5px; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 1; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff;"&gt;sass/server/ntlm/acquirecreds.c:103&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;update: &amp;nbsp;from my last query, I was finally able to see the token groups error, though it's not consistently showing up. &amp;nbsp;let me try and generate the error again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;update 2: &amp;nbsp;before you ask - yes, I ran the dsacls command for the ACS connector machine account in AD, but that did not appear to help with the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 03:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976774#M38961</guid>
      <dc:creator>noticketnomas</dc:creator>
      <dc:date>2016-07-28T03:17:37Z</dc:date>
    </item>
    <item>
      <title>Glad that added the last 2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976775#M38962</link>
      <description>&lt;P&gt;Glad that added the last 2 updates. Can you explain how you ran the dsacls command on the DC.&lt;/P&gt;
&lt;P&gt;~ Jatin&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 15:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976775#M38962</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-07-28T15:19:26Z</dc:date>
    </item>
    <item>
      <title>This is what I used:</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976776#M38963</link>
      <description>&lt;P&gt;This is what I used:&lt;/P&gt;
&lt;P&gt;dsacls "OU=(company users),DC=(company domain),DC=local" /I:T /G (company domain)\(ACS account):RP;tokenGroups&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 22:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-8-unable-to-retrieve-user-group-attributes/m-p/2976776#M38963</guid>
      <dc:creator>noticketnomas</dc:creator>
      <dc:date>2016-12-15T22:33:57Z</dc:date>
    </item>
  </channel>
</rss>

