cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1861
Views
5
Helpful
7
Replies

Problem with ACS 5.1 connect to LDAP

Any help on this subject would be great

I use ACS 5.1, connect with LDAP.

Test bind to server succeded.

Result of testing this configuration is as follows:

Primary Server:

   Number of Subjects: 14

   Number of Groups: 19

but user login is failed.

In monitor show error "22056 Subject not found in the applicable identity store(s)."

capture for our LDAP configuration on attact file.

Regard

BW

1 Accepted Solution

Accepted Solutions

Hi there,

LDAP as any other protocol has some limitations, and this is one of them. LDAP doesn't support PEAP Mschapv2, take a look to the compatibility chart below:

Here is one of the documents that metions this compatibility issue just in case you need it:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/Overvw.html#wp824718

Let me know if this answers your questions.

Rate if it helps!

View solution in original post

7 Replies 7

jrabinow
Level 7
Level 7

Which authentication protocol are you using?

Thanks for your response,

authenticaiton that we use is PEAP - EAP-MS-CHAPv2.

Our Protocol Configuration on ACS 5.1

Our PC configuration

Thx

BW

Hi there,

LDAP as any other protocol has some limitations, and this is one of them. LDAP doesn't support PEAP Mschapv2, take a look to the compatibility chart below:

Here is one of the documents that metions this compatibility issue just in case you need it:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/Overvw.html#wp824718

Let me know if this answers your questions.

Rate if it helps!

Thanks for answers,

Because LDAP doesn't support PEAP Mschapv2, so what can we do if we have acs 5.1 server connect to LDAP and we have user windows 7?

Please give us suggest.

Thx

BW

Peap Mschapv2 only works with Active Directory, if we can change  database from LDAP to windows AD then it will be supported. On the ACS  5, you need to select AD1 as a identiy store.

Regards,

Jatin

Do rate helpful posts-

~Jatin

Hi there,

Basically you have 2 options:

1. Connect the ACS 5.x to Active Directory instead of LDAP (AD doesn't have the PEAP limitation.). This will be the easier option as the ACS 5.x - AD integration is pretty straigh forward, you only need the following:

-Domain name

-AD account with role "Account Operator"

-Configure ACS clock and time zone same as your AD servers

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/users_id_stores.html#wp1171071

or

2. Change the connection protocol from PEAP to EAP-TLS for example, however this will take a lot more time and work as you will need to create and assign unique certificates for each user. From the chart above you can confirm that EAP-TLS is supported by LDAP.

http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/common_scenarios.html#wp1052872

Let me know if you need more information.

Rate if it helps!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: