cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1378
Views
0
Helpful
6
Replies

Cisco Jabber - VCS LDAP Login

Patrick Sparkman
VIP Alumni
VIP Alumni

How can I setup our VCS to allow Cisco Jabber users to login via LDAP (username without domain), not to be confused with AD (Direct).  I have both LDAP and AD (Direct) both setup and enabled in our VCS due to testing both some time ago, but I'm not sure if it's okay to run both at the same time.  When I test it, I get authentication failed.

Thanks!

6 Replies 6

Patrick Sparkman
VIP Alumni
VIP Alumni

..forgot to mention that I have looked over the VCS Authentication documention, but just want to clarify on how it's done, since its not working for me.

In short, you have to have a proper h.350 directory reflecting the provisioning directory, LDAP as the

database type and proper zone auth settings.

To prevent Movi/Jabber to use NTLM set "NTLM protocol challenges" to "off".

That shall do the trick.

Please remember to rate helpful responses and identify

Maybe Movi/Jabber need to TMS provide user authentication.

I must complete TMS agent function.add user on TMS-->system-->provision-->direction.VCS can provide user's authentication.

Hi Patrick,

Any need for running both at same time??

Jabber can utilize AD direct or H.350  for authentication purpose. I love AD direct mechanism thats fairly simple to implement and straight forward.

For H.350 you should have all the LDAP information and  schemas to be uploaded in AD.

Thanks

Alok

No reason, I was simply doing a test of each and never disabled them afterward.  I was able to get AD working, but having the domain as part of the username would mean all of our users would need to adjust their logins, something that could be confusing and troublesome for some.  That is why I was trying LDAP, from my knowledge, they wouldn't need the domain correct?  I think what I'm missing is the LDAP schemeas, I'll have to ask our network administrator of the possibility about them being installed, something I didn't know of until now.

Hi Patrick,

Yes, thats required when you used the H.350 directory services lookup from LDAP.

http://www.cisco.com/en/US/docs/telepresence/infrastructure/vcs/config_guide/Cisco_VCS_Authenticating_Devices_Deployment_Guide_X7-1.pdf

check the page 15.

Thanks

Alok