06-08-2012 03:26 AM - edited 03-10-2019 07:10 PM
Any help on this subject would be great
I use ACS 5.1, connect with LDAP.
Test bind to server succeded.
Result of testing this configuration is as follows:
Primary Server:
Number of Subjects: 14
Number of Groups: 19
but user login is failed.
In monitor show error "22056 Subject not found in the applicable identity store(s)."
capture for our LDAP configuration on attact file.
Regard
BW
Solved! Go to Solution.
06-09-2012 06:40 AM
Hi there,
LDAP as any other protocol has some limitations, and this is one of them. LDAP doesn't support PEAP Mschapv2, take a look to the compatibility chart below:
Here is one of the documents that metions this compatibility issue just in case you need it:
Let me know if this answers your questions.
Rate if it helps!
06-08-2012 06:55 AM
Which authentication protocol are you using?
06-08-2012 07:39 PM
Thanks for your response,
authenticaiton that we use is PEAP - EAP-MS-CHAPv2.
Our Protocol Configuration on ACS 5.1
Our PC configuration
Thx
BW
06-09-2012 06:40 AM
Hi there,
LDAP as any other protocol has some limitations, and this is one of them. LDAP doesn't support PEAP Mschapv2, take a look to the compatibility chart below:
Here is one of the documents that metions this compatibility issue just in case you need it:
Let me know if this answers your questions.
Rate if it helps!
06-13-2012 03:52 AM
Thanks for answers,
Because LDAP doesn't support PEAP Mschapv2, so what can we do if we have acs 5.1 server connect to LDAP and we have user windows 7?
Please give us suggest.
Thx
BW
06-13-2012 03:58 AM
Peap Mschapv2 only works with Active Directory, if we can change database from LDAP to windows AD then it will be supported. On the ACS 5, you need to select AD1 as a identiy store.
Regards,
Jatin
Do rate helpful posts-
06-13-2012 04:07 AM
Regards,
Jatin
Do rate helpful posts-
06-13-2012 05:24 AM
Hi there,
Basically you have 2 options:
1. Connect the ACS 5.x to Active Directory instead of LDAP (AD doesn't have the PEAP limitation.). This will be the easier option as the ACS 5.x - AD integration is pretty straigh forward, you only need the following:
-Domain name
-AD account with role "Account Operator"
-Configure ACS clock and time zone same as your AD servers
or
2. Change the connection protocol from PEAP to EAP-TLS for example, however this will take a lot more time and work as you will need to create and assign unique certificates for each user. From the chart above you can confirm that EAP-TLS is supported by LDAP.
Let me know if you need more information.
Rate if it helps!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: