02-09-2015 04:48 AM - edited 03-17-2019 01:53 AM
As the EM, that would make the auth. from CM end users' PIN, which cannot sync with the LDAP. Is it possible to make the PIN auth. as LDAP?
Solved! Go to Solution.
02-09-2015 04:59 AM
Hi Chi Fai,
If i understand correctly you want to authenticate EM User's PIN via LDAP which is not possible because Enduser PIN Residences on CUCM Database and its not a standard attribute of LDAP Hence PIN cannot be authenticated by LDAP.
HTH,
Regards,
Mohammed Noor
02-09-2015 04:59 AM
Hi Chi Fai,
If i understand correctly you want to authenticate EM User's PIN via LDAP which is not possible because Enduser PIN Residences on CUCM Database and its not a standard attribute of LDAP Hence PIN cannot be authenticated by LDAP.
HTH,
Regards,
Mohammed Noor
02-09-2015 09:36 PM
So sad ... util now, the auth. still cannot be unified.
02-11-2015 05:52 PM
Just wondering, why would you prefer it to be authenticated against the LDAP database?
So far I have always loved it against the CCM, just because If something needs to be changed wrt PIN, I dont have to explain all the things to a Windows Admin ;-)
02-11-2015 05:59 PM
I can understand wanting it to auth against LDAP.
It's one less password for the customer to worry about.
02-11-2015 07:13 PM
Well, the PIN is supposedly to be entered by the user at the time of logging into the Phone, using EM Profile and it is Numeric, which makes it easier to be entered.
If the PIN also considered as Password for the CCM/user account, then it opens up for security flaw (imho)
And if the PIN also goes against the LDAP database, then everytime a user's phone has locked out, one will have to speak to the LDAP Admin / Windows Admin :-(
(Not very pleasant, imho)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide