cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
476
Views
0
Helpful
2
Replies

ldap problem with UCSM2.1 to get roles

Hi,

I tried to configure an ldap authentification on UCSM2.1. My connexion is OK but I can't get the "role" of my user. To finish my role is Read-only.

When I test as :

     UCSM01-B(nxos)# test aaa server ldap  <ldapserver> <user> <password>

     user has been authenticated

... but i haven't an answer :

user has been authenticated

Attributes downloaded from remote server:

User Groups:

CN=ucsadmin,OU=CiscoUCS,DC=sampledesign,DC=com

Roles:

admin

Of course, i defined group maps.

Thank you for your help.

Stéphane               

2 Replies 2

Brian Morrissey
Cisco Employee
Cisco Employee

Hi Stéphane,

Make sure you have a group map defined and "Group Authorization" is enabled under the ldap provider settings.  Once these are both set you should see the roles when doing a test aaa server ldap.

Thank you Brian for your help.

Group maps are defined and Group Authorization is enabled.

But i just discover the "debug ldap all" command, and now i can see the exaclty DN is waiting,  in my complex org ldap enterprise.

My DN in group maps contained mistake, and now all is ok .

Thank you.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card