<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE : Active Directory integration long usernames sAMAccountname in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4428182#M568319</link>
    <description>&lt;P data-unlink="true"&gt;See&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-unlink="true"&gt;CSCvf21978&amp;nbsp;&lt;SPAN style="font-family: inherit;"&gt;ISE failing to resolve ambiguity for AD accounts&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-unlink="true"&gt;&lt;SPAN style="font-family: inherit;"&gt;CSCvc86398&amp;nbsp;ISE 2.1 patch 2 some certificate authentications fail&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 05 Jul 2021 16:35:14 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2021-07-05T16:35:14Z</dc:date>
    <item>
      <title>ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/2321595#M103133</link>
      <description>&lt;P&gt;Have a customer deploying ISE for wireless authentication using PEAP-MSCHAPv2.&amp;nbsp; They've encountered an issue where some users with long usernames are failing authentication to ISE.&amp;nbsp; ISE logs that the user is not found in the user database (Active Directory).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upon further review, it appears that ISE is using the sAMAccountname as the username token to authenticate against. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sAMAccountname is limited to 20 characters.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is running a full Windows 2008 domain and users login to the domain using their User Principal Name (no 20 character limit).&amp;nbsp; Therefore, when the user creates a wireless connection and passes his Windows credentials to PEAP, it fails because the username is too long and ISE does not find user in AD database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to point ISE to use a different username token instead of sAMAccountname?&amp;nbsp; or is this a known issue?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/2321595#M103133</guid>
      <dc:creator>tbostrom</dc:creator>
      <dc:date>2019-03-11T03:49:24Z</dc:date>
    </item>
    <item>
      <title>ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/2321596#M103165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think there is any way to increase the limit of 20 characters. You have to create to user name with 20 characters limit.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 02:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/2321596#M103165</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-08-28T02:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4423782#M568106</link>
      <description>&lt;P&gt;I ave the same issue with one of my clients.&lt;/P&gt;&lt;P&gt;Any chance this has been fixed in the last 7 years or someone found a workaround ?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 12:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4423782#M568106</guid>
      <dc:creator>tom.barat@dimensiondata.com</dc:creator>
      <dc:date>2021-06-25T12:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4426141#M568237</link>
      <description>&lt;P&gt;Any update on this limitation ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 14:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4426141#M568237</guid>
      <dc:creator>victor.jaouen</dc:creator>
      <dc:date>2021-06-30T14:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4428182#M568319</link>
      <description>&lt;P data-unlink="true"&gt;See&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-unlink="true"&gt;CSCvf21978&amp;nbsp;&lt;SPAN style="font-family: inherit;"&gt;ISE failing to resolve ambiguity for AD accounts&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-unlink="true"&gt;&lt;SPAN style="font-family: inherit;"&gt;CSCvc86398&amp;nbsp;ISE 2.1 patch 2 some certificate authentications fail&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4428182#M568319</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-07-05T16:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4428474#M568342</link>
      <description>&lt;P&gt;Thank you for sharing these bugs.&lt;/P&gt;&lt;P&gt;They don't match exactly our issue (bugs mention issues for short usernames, we have issues with long ones) but it might help the TAC find the issue faster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 10:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4428474#M568342</guid>
      <dc:creator>tom.barat@dimensiondata.com</dc:creator>
      <dc:date>2021-07-06T10:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4434972#M568522</link>
      <description>&lt;P&gt;Hi Tom&lt;/P&gt;&lt;P&gt;do u have any conclusions on the case with TAC? i'd highly appreciate.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jul 2021 09:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4434972#M568522</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-07-18T09:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4435514#M568542</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, i wanted to collect logs before opening the TAC case but the users running into this issue are on vacation currently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll be sure to update once this is solved in our environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice day,&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 17:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/4435514#M568542</guid>
      <dc:creator>tom.barat@dimensiondata.com</dc:creator>
      <dc:date>2021-07-19T17:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE : Active Directory integration long usernames sAMAccountname</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/5202387#M592137</link>
      <description>&lt;P&gt;Hi, any news about this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 14:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-directory-integration-long-usernames-samaccountname/m-p/5202387#M592137</guid>
      <dc:creator>CiscoU9834</dc:creator>
      <dc:date>2024-10-02T14:15:59Z</dc:date>
    </item>
  </channel>
</rss>

