<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest Single Sign-on with LDAP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3878818#M472075</link>
    <description>I reached out to engineering, did you get a tac case opened?&lt;BR /&gt;</description>
    <pubDate>Mon, 24 Jun 2019 20:53:51 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-06-24T20:53:51Z</dc:date>
    <item>
      <title>Guest Single Click with LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3877460#M472073</link>
      <description>&lt;P&gt;I am doing a guest install where the guest PSNs are not joined to AD and we are using LDAP.&amp;nbsp; We have an group mapped into to the sponsor role and the users can log into the sponsor portal without an issue using their account name (JDoe4567 as an example).&amp;nbsp;&amp;nbsp; The user's email address is jdoe@customer.com.&amp;nbsp; Because they are doing O365 they have changed all their UPNs to jdoe4567@customer.com.&amp;nbsp; The only LDAP attribute that has the email address in it is the Mail attribute.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the guest enters jdoe@customer.com in as the person they are visiting the sponsor receives an email but has to sign into the portal which means the single click process didn't work.&amp;nbsp; We set this up in a lab as well and changed the UPN to jdoe@customer.com and single clicked worked perfectly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is ISE only looking up the UPN attribute when it does the single click look-up based on the email address?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 15:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3877460#M472073</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-06-21T15:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Single Sign-on with LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3877489#M472074</link>
      <description>&lt;P&gt;An update, we turned on some debugs and we can see in the guest.log that the email lookup is working against LDAP but it says no groups are received.&amp;nbsp; The same account though works when we sign into the sponsor portal so LDAP groups are working there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 15:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3877489#M472074</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-06-21T15:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Single Sign-on with LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3878818#M472075</link>
      <description>I reached out to engineering, did you get a tac case opened?&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Jun 2019 20:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3878818#M472075</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-24T20:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Single Sign-on with LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3878820#M472077</link>
      <description>Not yet.  We did some more debugging on the issue and can't get consistent results.  We tried both LDAP group membership and using LDAP attributes to assign sponsor roles.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We will be opening a TAC case this week.  The single click approval is a nice to have for the customer.  We are working through other issues so we can start a pilot.  We can do the pilot without single click working.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Jun 2019 20:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3878820#M472077</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-06-24T20:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Single Sign-on with LDAP</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3881563#M472079</link>
      <description>they said need logs go through tac please</description>
      <pubDate>Fri, 28 Jun 2019 15:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-single-click-with-ldap/m-p/3881563#M472079</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-28T15:33:58Z</dc:date>
    </item>
  </channel>
</rss>

