<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authenticating Users via LDAP (Active Directory) in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148834#M18627</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can use LDAP with no RADIUS. However you should be aware of restrictions when using LDAP backend atabase authentication against LDAP. For instance, you will have to reconfigure your AD to return clear-text password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Feb 2009 05:59:31 GMT</pubDate>
    <dc:creator>r.roudi</dc:creator>
    <dc:date>2009-02-03T05:59:31Z</dc:date>
    <item>
      <title>Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148831#M18624</link>
      <description>&lt;P&gt;I am attempting to secure our 'enterprise' WLAN with EAP security and would like it to check user's credentials via LDAP against our Active Directory database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If using LDAP to authenticate, is there any reason to have a RADIUS server at all?  If so, please elaborate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your guidance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lucas&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 23:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148831#M18624</guid>
      <dc:creator>Lucas Phelps</dc:creator>
      <dc:date>2021-07-03T23:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148832#M18625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If any RADIUS servers are configured on the controller, the controller tries to authenticate the wireless clients using the RADIUS servers first. Local EAP is attempted only if no RADIUS servers are found, either because the RADIUS servers timed out or no RADIUS servers were configured. If four RADIUS servers are configured, the controller attempts to authenticate the client with the first RADIUS server, then the second RADIUS server, and then local EAP. If the client attempts to then reauthenticate manually, the controller tries the third RADIUS server, then the fourth RADIUS server, and then local EAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the furter assistance following URL may help you&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a008093f1b9.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a008093f1b9.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jan 2009 03:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148832#M18625</guid>
      <dc:creator>amritpatek</dc:creator>
      <dc:date>2009-01-19T03:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148833#M18626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I'm still left wondering whether I can just go into the LDAP configuration on the WLC and type the server info of my Active Directory server or whether I am required to have a RADIUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS is an older, less secure method, and I'd rather have secure authentication directly to our LDAP AD server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Feb 2009 15:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148833#M18626</guid>
      <dc:creator>Lucas Phelps</dc:creator>
      <dc:date>2009-02-02T15:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148834#M18627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can use LDAP with no RADIUS. However you should be aware of restrictions when using LDAP backend atabase authentication against LDAP. For instance, you will have to reconfigure your AD to return clear-text password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 05:59:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148834#M18627</guid>
      <dc:creator>r.roudi</dc:creator>
      <dc:date>2009-02-03T05:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148835#M18628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But even with a RADIUS server, doesn't the password have to be clear-text? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to figure out what the benefit is of having the required RADIUS server if I can hook the WLC directly up to LDAP on our Domain controllers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 14:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148835#M18628</guid>
      <dc:creator>Lucas Phelps</dc:creator>
      <dc:date>2009-02-03T14:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148836#M18629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need radius server, because you looking for protocol support such as PEAP, LEAP, EAP-TLS &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2009 22:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148836#M18629</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2009-03-06T22:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148837#M18630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Enable IAS (microsfot's RADIUS) on one of your windows servers and set it to authenticate against AD. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Mar 2009 15:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148837#M18630</guid>
      <dc:creator>venom43212</dc:creator>
      <dc:date>2009-03-10T15:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating Users via LDAP (Active Directory)</title>
      <link>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148838#M18631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RADIUS communications are hashed with the Shared Secret, which is a poor excuse for encryption, but it keeps user credentials from rolling around in clear text format.  Seems like you ought to be able to use IPSec to tighten up the comm between the controller and the RADIUS box.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2009 20:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authenticating-users-via-ldap-active-directory/m-p/1148838#M18631</guid>
      <dc:creator>Robert.N.Barrett_2</dc:creator>
      <dc:date>2009-04-02T20:30:41Z</dc:date>
    </item>
  </channel>
</rss>

