07-25-2012 05:06 PM - edited 03-17-2019 11:31 PM
Can anyone point me in the right direction to get documents that cover how VCSc device auth and TMSPE work together to provision and auth Jabber users.
I have the TMSPE guide and the VCS auth guide but I am looking for clarity on how users that have been auth'd with AD via VCS get provisioned by TMSPE when those users are not in TMSPE right now?
Thanks in advance
Tim
Sent from Cisco Technical Support iPad App
Solved! Go to Solution.
07-25-2012 06:09 PM
Hi Tim,
For successful provisioning you need to import those AD users in TMSPE.
Initial authentication for jabber user would be done via VCS to AD but after the authentication part for a successfull provisioning the user has to be in the TMSPE database.
If user is not present then you will get a error message.
For TMSPE set the default zone to check credentials only.
Thanks
Alok
07-25-2012 05:41 PM
Are you saying that your users are being authenticated despite not being in TMSPE? You might have the relevant zone or subzone set to "treat as authenticated" rather than "check credentials".
If you are saying that they can't authenticate because they are not in TMSPE, then you probably want to import the users from AD into TMSPE.
07-25-2012 06:09 PM
Hi Tim,
For successful provisioning you need to import those AD users in TMSPE.
Initial authentication for jabber user would be done via VCS to AD but after the authentication part for a successfull provisioning the user has to be in the TMSPE database.
If user is not present then you will get a error message.
For TMSPE set the default zone to check credentials only.
Thanks
Alok
07-26-2012 01:17 PM
I have the orginal problem now working, thanks for making that last connection between TMSPE and VCS.
I know have a problem where all the users that we imported into TMSPE for provisioning are now showing up in the Provisioning Phonebook source. The problem is that only 100 of the 500 users imported into TMSPE will ever use Jabber and the provisioning source is showing all the inported users on C-Series endpoints. This is not good, i would like to limit the phonebook to only users entries of AD users that have logged into Jabber at sometime.
Thanks in Advance
07-27-2012 05:28 PM
Hi Tim,
Once you import the users by default it will show all those users in the provisioning phone book source.
if you do not want that then create manual phone book source and have only those entries which are going to sign in to Jabber .
Thanks
Alok
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide