11-13-2015 12:13 PM - edited 03-17-2019 04:54 AM
Hi all.
I have cucm and expressway installed for mra. All work fine. I want to enable sso just on cucm and don't want enable it on expressway. Is it supported configuration or i need enable sso on cucm ande expressway at the same time ?
11-14-2015 01:27 AM
SSO is enabled cluster wide on CUCM. You can't enable or disable it on expressway. Once your cluster is enabled for SSO, jabber will automatically discover it through expressway.
11-14-2015 06:29 AM
I can enable and disable sso on expressway. See documentation for that product http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-5/Mobile-Remote-Access-via-Expressway-Deployment-Guide-X8-5.pdf
11-16-2015 01:12 PM
Deleted
11-16-2015 01:12 PM
Hi Ayodeji
If SSO is enable on CUCM but not enable on expressway, users still be able to log in over Expressway MRA?
11-16-2015 01:31 PM
Yes definitely, SSO just wont be available and jabber will default to normal sign in.
11-16-2015 09:17 PM
HI Ayodeji.
How users will be able to login over MRA if they will not be ablle to acces to IdP server ?
11-25-2015 11:23 AM
They will not
02-27-2017 01:11 PM
02-28-2017 02:11 AM
Pasha,
No you need to enable SSO on both CUCM and expressway-c/e for SSO to work over MRA. This is because once the client has been asserted at the edge by the expresway, CUCM still needs to verify from IdP server that the client is authroized for the request.
Please refer here for more details
http://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/admin_guide/Cisco-Expressway-Administrator-Guide-X8-5-1.pdf
02-28-2017 09:37 AM
Thanks Deji,
I read the doc, i did notice it said IdP & CUCM should exchange SAML metadata, it just didn't explicitly say SSO should be active on CUCM. I understand it was implicit, i was just hoping that someone had different experience :)
Thanks again.
11-25-2015 11:22 AM
Test it. If SSO is enable on the CUCM cluster,it needs to be enable on MRA or user will not be able to log on.and will get message SSO access denied.
11-26-2015 03:25 AM
Yes, this is correct. SSO needs to be enabled on all infrastructure for Jabber to work
12-04-2015 06:53 AM
Looks like my testing procedure was not really good after all :)
YES, it is possible to have SSO enable on CUCM/Unity and not-SSO enable on Express. Then your initial comment was right!.
12-04-2015 07:21 AM
Thank you for the update. I have learnt a lot from interacting with you, so thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide