01-18-2024 12:01 AM
Hi Community,
i have a problem with a new CML 2.6.1 installation with LDAP authentication. The Authentication via LDAP is working with/without NTLM and users/admins can login to CML. The problem is: The users/admins are not displayed in the User Database on WebUI. It looks like, the creation of AD authentication users with that "non-local" flag written in the documentation is not working. I don´t find anything in the Logs.
Do you have an idea for this? Thanks!
BR,
Christian
01-18-2024 12:25 AM
Update: Users which have logged in yesterday are now present in WebUI User Administration. But new users from today are again not visible.
01-18-2024 01:22 AM
When you enable LDAP - When the CML server is configured to use LDAP, the local user lookup is disabled
Note that if you configure CML to use LDAP, and the LDAP settings are incorrect or there was a change in the LDAP server, you may find that no one can log into the CML server. Once CML is configured to use the LDAP Authentication Method, all login attempts are authenticated via LDAP. Therefore, even the local admin user will be unable to log into the CML server. If CML can reach the LDAP servers over the network, it will not fall back to local authentication even if it fails to bind to the LDAP servers.
01-18-2024 01:50 AM - edited 01-18-2024 01:51 AM
Hi, thanks for reply.
Yes, that is written in the documentation. The local user lookup is disabled, that´s true, but that´s not the problem here. The AD users from yesterday are present now. It seems like there is a hidden LDAP search cronjob to update the user database via LDAP search in the night or something similar on the application or underlying ubuntu, but i cannot find it in the linux config.
01-19-2024 05:49 AM
Hi @Chmiene , That is expected behavior, A user will be seen in the Web UI only after he logs in to CML. A user who never logged into CML will not be displayed in CML Web UI.
01-21-2024 09:06 AM
Hi rkochery,
thanks for your reply. Yes, that´s an expected behaviour. But in my case , the users logged in, they are missing in WebUI and after the next night, they are present. I have reproduced that issue now three times.
01-31-2024 09:09 AM
Is there a guide to configure LDAP authentication with CML. I could not find one and unable to determine what attributes are required to configure CML with LDAP authentication.
01-31-2024 12:47 PM
Hi varma,
yes, there is a guide: Configuring LDAP Authentication - Cisco Modeling Labs v2.6 - Cisco DevNet
01-31-2024 09:52 PM
Hi @varma10 , Please try open the User Administration page in CML and refresh the page, it should show the new users.
02-13-2024 12:32 PM
Hi rkochery,
that´s exactly the problem, the Admin page shows the users only after a night. Last week at Cisco Live EMEA i have asked that too, but nobody knows the problem. Maybe my installation is broken somewhere. Let´s wait for a new Version and i will have a look on it after the update. Thanks!
02-13-2024 01:15 PM
Hi @Chmiene , As i mentioned in my previous comment, you just need to refresh the User Administration page, you do not need to wait overnight.
02-13-2024 01:24 PM
I did that multiple times! A new user logged in the first time and i refreshed that page multiple times, restarted CML..... After the next night, the user is in the user administration page.
Is there a hidden Refresh button i didn´t find until now?
02-16-2024 02:24 PM
I have reinstalled the application and the problem is solved. I don´t know what´s happened in the first installation. Thread can be closed, thanks for all answers!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide