cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
606
Views
0
Helpful
2
Replies

Disable LDAP integration

j.huizinga
Level 6
Level 6

Hi,

I have a configuration with CM 7.1 and AD integration.

What will happen if I remove the LDAP integration?

Will the users become normal endusers?

Or will they be deleted?

Just wondering.

Thanks,

Jan

1 Accepted Solution

Accepted Solutions

gmendivi
Cisco Employee
Cisco Employee

Hello Jan,

When the LDAP sync agreement is removed, all the end users that it pulled in will be marked inactive. Later on, when DirSync garbage collection takes place (normally on a daily basis) then all the inactive users are removed. The passwords are definitely not stored in the CUCM database; only the hashes are stored in AD, and the authentication agreement just attempts a bind to see if the passwords match.

I think you can keep the users from being deleted from CUCM by disabling the DirSync service so that garbage collection doesn't happen. However, there's no way if you disable the authentication agreement for CUCM to have the correct password for those users.

I hope it clarifies your question,

German

View solution in original post

2 Replies 2

gmendivi
Cisco Employee
Cisco Employee

Hello Jan,

When the LDAP sync agreement is removed, all the end users that it pulled in will be marked inactive. Later on, when DirSync garbage collection takes place (normally on a daily basis) then all the inactive users are removed. The passwords are definitely not stored in the CUCM database; only the hashes are stored in AD, and the authentication agreement just attempts a bind to see if the passwords match.

I think you can keep the users from being deleted from CUCM by disabling the DirSync service so that garbage collection doesn't happen. However, there's no way if you disable the authentication agreement for CUCM to have the correct password for those users.

I hope it clarifies your question,

German

Hello German,

Thanks for the clarification.

I just wanted to be sure about this,

Bye,

Jan