02-01-2011 02:59 AM - edited 03-16-2019 03:11 AM
Hi
It’s possible in Cisco CallManager make the ldap authentication in two different Active Directory's? My CallManager version is 7.x
Thanks
Solved! Go to Solution.
02-01-2011 06:52 AM
Additional Considerations for Microsoft Active Directory
The use of Global Catalog for authentication becomes even more efficient if the users synchronized from Microsoft AD belong to multiple domains, because it allows Unified CM to authenticate users immediately without having to follow referrals. For these cases, point Unified CM to a Global Catalog server and set the LDAP User Search Base to the top of the root domain.
In the case of a Microsoft AD forest that encompasses multiple trees, some additional considerations apply. Because a single LDAP search base cannot cover multiple namespaces, Unified CM must use a different mechanism to authenticate users across these discontiguous namespaces.
As mentioned in the section on LDAP Synchronization, in order to support synchronization with an AD forest that has multiple trees, the UserPrincipalName (UPN) attribute must be used as the user ID within Unified CM. When the user ID is the UPN, the LDAP authentication configuration page within Unified CM Administration does not allow you to enter the LDAP Search Base field, but instead it displays the note, "LDAP user search base is formed using userid information."
In fact, the user search base is derived from the UPN suffix for each user, as shown in Figure 17-14. In this example, a Microsoft Active Directory forest consists of two trees, avvid.info and vse.lab. Because the same user name may appear in both trees, Unified CM has been configured to use the UPN to uniquely identify users in its database during the synchronization and authentication processes.
http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/srnd/7x/directry.html#wp1045381
HTH
java
If this helps, please rate
www.cisco.com/go/pdihelpdesk
02-01-2011 06:52 AM
Additional Considerations for Microsoft Active Directory
The use of Global Catalog for authentication becomes even more efficient if the users synchronized from Microsoft AD belong to multiple domains, because it allows Unified CM to authenticate users immediately without having to follow referrals. For these cases, point Unified CM to a Global Catalog server and set the LDAP User Search Base to the top of the root domain.
In the case of a Microsoft AD forest that encompasses multiple trees, some additional considerations apply. Because a single LDAP search base cannot cover multiple namespaces, Unified CM must use a different mechanism to authenticate users across these discontiguous namespaces.
As mentioned in the section on LDAP Synchronization, in order to support synchronization with an AD forest that has multiple trees, the UserPrincipalName (UPN) attribute must be used as the user ID within Unified CM. When the user ID is the UPN, the LDAP authentication configuration page within Unified CM Administration does not allow you to enter the LDAP Search Base field, but instead it displays the note, "LDAP user search base is formed using userid information."
In fact, the user search base is derived from the UPN suffix for each user, as shown in Figure 17-14. In this example, a Microsoft Active Directory forest consists of two trees, avvid.info and vse.lab. Because the same user name may appear in both trees, Unified CM has been configured to use the UPN to uniquely identify users in its database during the synchronization and authentication processes.
http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/srnd/7x/directry.html#wp1045381
HTH
java
If this helps, please rate
www.cisco.com/go/pdihelpdesk
02-01-2011 07:31 AM
Practically speaking, I am not sure you can do that. The reason is that you can only configure one user search base which obviously can only point to one domain. That is why I think you can point CUCM to two different domain.
02-03-2011 08:39 AM
Thanks for the help.
you're right I only can create one user, I think this works in domains in the same forest, but In my case my two domains are independent. I have a problem
02-09-2011 06:27 AM
this link may help people with the same problem
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide