cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4692
Views
0
Helpful
4
Replies

unity connection, change to ldap integration

rogierboeken
Level 1
Level 1

hi

2 years ago we installed cisco unity connection and we are currently on version 8.6.2ES25.21900-25

the cisco integrator i used did not integrate the unity connection users with ldap, at the time i thought it was odd as our CUCM users are integrated with LDAP but did not query it.

we have now started to use cisco jabber and i have started to notice that i could really do with converting our (only 25 but high maintenance users) users to ldap integrated users (and authentication as well)

i found some documents which describe how to setup LDAP integration

http://www.cisco.com/en/US/docs/voice_ip_comm/connection/8x/user_mac/guide/8xcucmac105.html

  1. Changing the LDAP Integration Status of an Individual Connection User (Cisco Unity Connection 8.5 and Later Only)

    To Change the LDAP Integration Status of an Individual Connection User (Connection 8.5 and Later)

    Step 1 In Cisco Unity Connection Administration, click Users.
    Step 2 On the Search Users page, click the alias of the user account.

page5image29176

User Moves, Adds, and Changes Guide for Cisco Unity Connection Release 8.x


Chapter 12 Creating User Accounts from LDAP User Data or Changing LDAP Integration Status for Existing Users in Changing the LDAP Integration Status of Connection Users (Cisco Unity Connection 8.5 and Later Only)

page6image2280 page6image2440 page6image2600
page6image4832 page6image5152

Step 3

Note If the user does not appear in the search results table, set the applicable parameters in the search fields at the top of the page, and click Find.

On the Edit User Basics page, in LDAP Integration Status section, select the desired radio button:

  • Integrate with LDAP Directory—To integrate a Connection user account with an LDAP user account, select this option. The Connection alias must match the corresponding value in the LDAP directory. (On the System Settings > LDAP > LDAP Setup page, the LDAP Attribute for User ID list identifies the field in the LDAP directory for which the value must match the value of the Alias field in Connection.)

  • Do Not Integrate with LDAP Directory—To break the association between a Connection user account and an LDAP directory user account, select this option.

    If the user was created by importing from Cisco Unified Communications Manager, the LDAP Integration Status field is grayed out and you must use Bulk Administration Tool to integrate them with an LDAP user account. See “Integrating Existing Connection User Accounts with LDAP User Accounts Using Bulk Administration Tool (Cisco Unity Connection 8.5 and Later Only)” section on page 12-7.

    Click Save.

and

http://www.cisco.com/en/US/docs/voice_ip_comm/connection/8x/design/guide/8xcucdg040.html

all these users have existing jabber clients and also outlook viewmail plugins (with login credentials)

ideally i like to convert all 25 users one at at time (as they often have 2 or 3 different clients and it is just part of how we have to manage our users)

often their cisco unity connection web password is the same as their ldap password (windows active directory) so my question is as follows

1) is it possible to setup ldap integration and authentication without immediately importing ldap users or synching ldap users with existing  unity connection users (will this only start to work once you check integrate with ldap checkbox for an indivual user

2) set the LDAP integration and authentication one user by one (

(i think yes as per the above  changing ldap integration instructions)

3) would there have a been a good reason to not integrate unity connection users with LDAP, i cannot think of any, not even for 25 users.

many thanks

2 Accepted Solutions

Accepted Solutions

s.soporie
Level 1
Level 1

Question 1. Not possible.
Question 2. Yes you can do that.
Question 3. I am assuming single inbox so definitely should have been LDAP integrated.

Sent from Cisco Technical Support iPhone App

View solution in original post

The SSO feature of VMO is very poorly named. It does not require an SSO solution such as OpenAM nor does it pass the user credentials to CXN. CXN simply places an authentication token into the message headers (X-CiscoUnity-DbMessageId I thnk) which VMO includes in its API call. As long as CXN gets the correct value it processes the request.

Please remember to rate helpful responses and identify helpful or correct answers.

View solution in original post

4 Replies 4

s.soporie
Level 1
Level 1

Question 1. Not possible.
Question 2. Yes you can do that.
Question 3. I am assuming single inbox so definitely should have been LDAP integrated.

Sent from Cisco Technical Support iPhone App

thanks for the response

yes single inbox, still not quite sure why he did not configure, ah well

got a 4th question

for SSO to work for viewmail client in outlook 2010 do you require open am server or will it just pass on the windows login details as credentials (i believe this is the case and open am is only needed for web services such as ciscopca?

The SSO feature of VMO is very poorly named. It does not require an SSO solution such as OpenAM nor does it pass the user credentials to CXN. CXN simply places an authentication token into the message headers (X-CiscoUnity-DbMessageId I thnk) which VMO includes in its API call. As long as CXN gets the correct value it processes the request.

Please remember to rate helpful responses and identify helpful or correct answers.

thanks to you all

have now successfully converted half of my users to LDAP integrated users without a glitch!!.

will do the other half after they come back from their summer vacation when i get a chance to update their cisco viewmail plugin to version supporing the SSO feature.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: