Cisco TelePresence Administrator's Manual page 121

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Device authentication
Configuring the LDAP server settings
1. Go to
Configuration > Authentication > Devices > H.350 directory
2. Configure the fields as follows:
Field
Description
H.350 device
Enables or disables the use of an H.350
authentication
directory for device authentication.
Source of
Determines how aliases are checked and
aliases for
registered.
registration
Server
The IP address or FQDN (or server address,
address
if a DNS Domain name has also been
configured) of the LDAP server.
FQDN
Defines how the LDAP Server address is
address
resolved if it is specified as an FQDN.
resolution
Address record: DNS A or AAAA record
lookup.
SRV record: DNS SRV record lookup.
The default is Address record.
Port
The IP port of the LDAP server.
Encryption
Determines whether the connection to the
LDAP server is encrypted using Transport
Layer Security (TLS).
TLS: uses TLS encryption for the connection
to the LDAP server.
Off: no encryption is used.
The default is TLS.
Bind DN
The user distinguished name used by the
VCS when binding to the LDAP server.
Bind
The password used by the VCS when binding
password
to the LDAP server.
Cisco VCS Administrator Guide (X8.1.1)
About device authentication
service.
Usage tips
The H.350 directory can be used in
combination with other authentication
mechanisms.
See
H.350 directory authentication and
registration process
above for a
description of each setting.
When Source of aliases for registration is
H.350 directory, MCUs are treated as a
special case. They register with the
presented aliases and ignore any aliases in
the H.350 directory. (This is to allow MCUs
to additively register aliases for
conferences.)
The LDAP server must have the H.350
schemas installed.
DNS SRV lookups enable the VCS to
authenticate devices against multiple
remote H.350 directory servers. This
provides a seamless redundancy
mechanism in the event of reachability
problems to an H.350 directory server.
The SRV lookup is for either _ldap._tcp or _
ldap._tls records, depending on whether
Encryption is enabled. If multiple servers
are returned, the priority and weight of each
SRV record determines the order in which
the servers are used.
Typically, non-secure connections use 389
and secure connections use 636.
When TLS is enabled, the LDAP server's
certificate must be signed by an authority
within the VCS's trusted CA certificates file.
Click
Upload a CA certificate file for TLS
(in the
Related tasks
section) to go to the
Managing the trusted CA certificate list
[p.285]
page.
For example, uid=admin, ou=system
Page 121 of 507

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x8.1.1

Table of Contents