cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1259
Views
10
Helpful
6
Replies

Cisco Secure ACS with UCP assistance and enable password

cisco24x7
Level 6
Level 6

I am running Cisco Secure ACS version 4.2 running on a

Standalone Windows 2003 Enterprise 2003with the lastest

windows service pack and update. Secure ACS is running

fine and I can authenticate with Cisco routers and

switches. The Windows 2003 server is also running Microsoft

IIS Server. In other words, the IIS server and Cisco

Secure ACS is running on the same windows 2003 server.

I am trying to get Cisco User-Changeable password to work

with Cisco Secure ACS. I followed the release notes lines

by lines and the work around provided below:

Also server require more privileges for the internal windows user that runs CSusercgi.exe.

The name of the windows user that runs UCP is IUSR_<machine_name>.

Workaround steps:

1) Install UCP 4 on a machine that runs IIS server.

2) Open IIS manager

3) Locate Default Web Site

4) Double click on the virtual name 'securecgi-bin'

5) Right click on CSusercgi.exe and choose Properties

6) Choose 'File Security' tab

7) Choose 'Edit' in 'Authentication and access control' area

8) Change username from IUSR_<machine_name> to 'Administrator' and enter his

password (make sure that 'Integrated Windows authentication' is checked)

I still can NOT get this to work. I got this error:

It says:

The page cannot be found

The page you are looking for might have been removed,

had its name changed, or is temporarily unavailable.

HTTP Error 404 - File or directory not found.

Internet Information Services (IIS)

I modified everything in the Windows 2003 to be "ALLOWED" by

EVERYONE. In other words, there are NO security on the windows 2003.

It is still NOT working.

The other question I have is that can Cisco UCP allow user

to change his/her enable password?

Can someone help? Thanks.

6 Replies 6

mehdiraza
Level 1
Level 1

Hello,

I've same issue as you stated above, if you find any answer/reply. please let me know too.

Thanks,

Mehdi Raza

Bastien Migette
Cisco Employee
Cisco Employee

You can have a look at this guide:

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a0080094e7b.shtml

Looks like you didn't defined the correct folders.

Thank you Bastein

Problem has been solved after re-installation of UCP and re-defining of the virtual directories.

Thanks again for your assistance and awesome co-operation/sharing.

Regards,

Mehdi Raza

Hello Mehdi,

I'm glad this work.


Please mark the thread as answered and/or rate the post that are useful.

Regards,

bastien.

Yes bastien,

Thank you.

But one thing more i want to know that in its Redundant AAA server, when i try to open IIS 6.0 window 2003; it prompts for Username and Password.
I've given it several time; also going through Administrator account with administrative credentials but it always failed.

Any suggestions/solution/?

This time many thanks in advance.

Regards

Mehdi Raza

Hello Mehdi,

Do you mean the password to modify IIS parameters ?

It seems related to windows IIS configuration, so I guess you would have better chances on a microsoft forum.


Sorry if I can't help you further on this part.