cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
663
Views
1
Helpful
6
Replies

Migrating from Oracle Directory Server to Microsoft Active Directory

rajeshpat
Level 1
Level 1

Hi All,

We are in the process of LDAP migration from Sun/Oracle Directory Service to Microsft Active Directory. As an initial step, I have uploaded the Root & Intermediate Certificates in CUCM which was generated from the Microsoft AD server. So the next process is to remove all the old LDAP entries (Entries of the Oracle LDAP server) and do the Microsft Active Directory configuration in CUCM and Unity. Now I need to know is there are any more steps I need to do or do I missed any process from the steps mentioned here. Kindly help me 

Regards,

Raj

6 Replies 6

Jaime Valencia
Cisco Employee
Cisco Employee

Yes, old user entries from Oracle will show as LDAP inactive and once you enable the LDAP sync you will get new users from it.

HTH

java

if this helps, please rate

rajeshpat
Level 1
Level 1

Thanks for the information. So what will be the correct steps like?

  1. The required certificate has to be uploaded in CUCM & Unity (Root & Intermediate certificate).
  2. Remove the old LDAP Entries (in my case Oracle LDAP directories). 
  3. Configure the LDAP system with "Microsoft Active Directories". 
  4. Configure LDAP Directories by mapping the Microsoft AD server details with port no: 636 and a new search base. 
  5. Then Configure the LDAP Authentication for authentication purposes. 
  6. Finally LDAP Custom Filters for filtering the users.

Apart from these steps, is there any changes or configuration has to be done from the Voice side?

Kindly help me in this...

If you just change the type of AD and everything else stays the same (e.g. the users), then you shouldn't need to do something else.

I assume that all of your devices are currently assigned to users? If so you’ll need to redo all that to assign the new users that will be created by the synchronisation with AD. Also all the user mapping in Unity need to be updated or redone depending on what is possible.



Response Signature


So Redo means... Do I need to unassign and re-assign the user's device? 

No need to unassign, but you you’ll need to assign to the new account that get created by the synchronisation with AD.



Response Signature