<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP Authentification and group membership in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241230#M357514</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to make this work. My LDAP authentification works ok, but I want it to test if the user is a member of a specific group or not. Well, if I test with any user, it says Successful wheter the user is a member of the group or not. And I want it to failed if the user is not a member of the group. I am using ASDM and test in the AAA Server Groups with the Test button and authentification test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap attribute-map CISCOMAP&lt;/P&gt;&lt;P&gt;&amp;nbsp; map-name&amp;nbsp; memberOf IETF-Radius-Service-Type&lt;/P&gt;&lt;P&gt;&amp;nbsp; map-value memberOf CN=ITVPN,CN=users,OU=Domain,DC=local 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server LDAP protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server LDAP (Inside) host 10.1.1.1&lt;/P&gt;&lt;P&gt; ldap-base-dn OU=MyOU,dc=Domain,dc=local&lt;/P&gt;&lt;P&gt; ldap-scope subtree&lt;/P&gt;&lt;P&gt; ldap-naming-attribute sAMAccountName&lt;/P&gt;&lt;P&gt; ldap-login-password Something&lt;/P&gt;&lt;P&gt; ldap-login-dn CN=UserAdmin,OU=Service,OU=MyOU,DC=Domain,DC=local&lt;/P&gt;&lt;P&gt; server-type microsoft&lt;/P&gt;&lt;P&gt; ldap-attribute-map CISCOMAP&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:48:38 GMT</pubDate>
    <dc:creator>Jean-Francois Gagnon</dc:creator>
    <dc:date>2019-03-12T01:48:38Z</dc:date>
    <item>
      <title>LDAP Authentification and group membership</title>
      <link>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241230#M357514</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to make this work. My LDAP authentification works ok, but I want it to test if the user is a member of a specific group or not. Well, if I test with any user, it says Successful wheter the user is a member of the group or not. And I want it to failed if the user is not a member of the group. I am using ASDM and test in the AAA Server Groups with the Test button and authentification test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap attribute-map CISCOMAP&lt;/P&gt;&lt;P&gt;&amp;nbsp; map-name&amp;nbsp; memberOf IETF-Radius-Service-Type&lt;/P&gt;&lt;P&gt;&amp;nbsp; map-value memberOf CN=ITVPN,CN=users,OU=Domain,DC=local 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server LDAP protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server LDAP (Inside) host 10.1.1.1&lt;/P&gt;&lt;P&gt; ldap-base-dn OU=MyOU,dc=Domain,dc=local&lt;/P&gt;&lt;P&gt; ldap-scope subtree&lt;/P&gt;&lt;P&gt; ldap-naming-attribute sAMAccountName&lt;/P&gt;&lt;P&gt; ldap-login-password Something&lt;/P&gt;&lt;P&gt; ldap-login-dn CN=UserAdmin,OU=Service,OU=MyOU,DC=Domain,DC=local&lt;/P&gt;&lt;P&gt; server-type microsoft&lt;/P&gt;&lt;P&gt; ldap-attribute-map CISCOMAP&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241230#M357514</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2019-03-12T01:48:38Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentification and group membership</title>
      <link>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241231#M357517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are we sure that when we run the tests, there's no paremeter that applies for the same users and puts them all in the same group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried this with a real user trying to authenticate?&lt;/P&gt;&lt;P&gt;Do you get any useful logs from the server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 19:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241231#M357517</guid>
      <dc:creator>Favaloro.</dc:creator>
      <dc:date>2013-05-28T19:04:44Z</dc:date>
    </item>
    <item>
      <title>LDAP Authentification and group membership</title>
      <link>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241232#M357519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What thype of ldap server are you using? Microsoft Windows 2012 or 2008. I got a problem with 2012 not give the groups back with some users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same problem as &lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3866327#3866327"&gt;https://supportforums.cisco.com/message/3866327#3866327&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug ldap 255 &lt;/P&gt;&lt;P&gt;shows correct value with one user that is workin:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[196] Authentication successful for Administrator to 192.168.20.80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[196] Retrieved User Attributes:&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; objectClass: value = top&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; objectClass: value = person&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; objectClass: value = organizationalPerson&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; objectClass: value = user&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; cn: value = Administrator&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; description: value = Vordefiniertes Konto f..r die Verwaltung des Computers bzw. der Dom..ne&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; distinguishedName: value = CN=Administrator,CN=Users,DC=xxxx,DC=local&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; instanceType: value = 4&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; whenCreated: value = 20081201134058.0Z&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; whenChanged: value = 20131126141559.0Z&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; displayName: value = Administrator&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp; uSNCreated: value = 12298&lt;/P&gt;&lt;P&gt;[196&lt;STRONG&gt;]&amp;nbsp;&amp;nbsp; memberOf: value = CN=G_SSLVPN,OU=Service,OU=Groups,OU=XXXXX,DC=XXXX,DC=local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mapped to Group-Policy: value = ssl_admin&lt;/P&gt;&lt;P&gt;[196]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mapped to LDAP-Class: value = ssl_admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One user that is not working:&lt;/P&gt;&lt;P&gt;no entries with memberOf in debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[190] Authentication successful for sdag to 192.168.20.80&lt;/P&gt;&lt;P&gt;[190] Retrieved User Attributes:&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; objectClass: value = top&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; objectClass: value = person&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; objectClass: value = organizationalPerson&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; objectClass: value = user&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; cn: value = sdag&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; distinguishedName: value = CN=sdag,OU=Lieferanten,OU=Users,OU=xxxx,DC=xxxxxx,DC=local&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; displayName: value = sdag&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; homeMTA: value = CN=Microsoft MTA,CN=SRVSBS01,CN=Servers,CN=erste administrative gruppe,CN=Admini&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; proxyAddresses: value = smtp:sdag@xxxx&lt;/P&gt;&lt;P&gt;[190]&amp;nbsp;&amp;nbsp; proxyAddresses: value = SMTP:sdag@xxxxx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 23:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ldap-authentification-and-group-membership/m-p/2241232#M357519</guid>
      <dc:creator>pf</dc:creator>
      <dc:date>2013-11-26T23:44:12Z</dc:date>
    </item>
  </channel>
</rss>

