VCS-E for VCS - C MOVI AUTHENTICATION WITH AD AUTHENTICATION

Hello

We have a VCS - C and VCS-E. We have movi users currently authenticated by the local Agent of MSDS database.

We are now in the treatment of the migration to Active Directory authentication.

We did it by selecting "Check for credentials" on VCS - C area (entry point for provisioned client) default and each user movi on internal network is getting authenticated with credentials of the AD. (User domain\username & domain password)

However, if a user of VCS - E attempts to authenticate the credentials of the AD, the connection fails with an invalid username and password.

If we try to use the username and password of MSDS agent, it works very well.

Proceed to the next step, we have activated the "Check for authentication" then the VCS - C road customer area to the VCS-E. Then authentication is fine with the AD credentials for users outside movi.

Now, I want to know, allowing the "Check for authentication" then the VCS - C course CLient area will affect the flow of calls between VCS - C and VCS-E or any service will be interrupted.

Best regards / / Rio

You have all the other things listed in the VCS-E? As endpoints, gateways? In brief

anything with the same fields that are set up on the SCV - C as well?

You register customers movi on the VCS-E or proxy list them on the VCS - C?

Outside calls does not at all, as the auth hits the same domain only.

What you might try is if your movi users can always successfully connect from the outside through the

the VCS-E to the devices registered in the VCS - C and also presence and directories.

These are the things that break likely tend to break, if there is something else wrong.

Not to mention that if you have configured correctly it should work correctly

Please take some time and go through this guide, they have fine examples in the annex,

so you can double check your configuration:

http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_Authenticating_Devices_Deployment_Guide_X7-0.PDF

Maybe, Andreas has something else to add.

Please note the answers! (click on the stars below messages)

Tags: Cisco Support

Similar Questions

  • MOVI authentication for VCS-TMSPE-AD?

    Hi, Expert

    Setup is X7.2 VCS, 13.2 TMSPE with MS active directory as the database of the user.

    The user account has been imported into TMSPE by system > Provisioning > users > Group XXX > import user > configure AD.

    And VCS has been integrated with TMSPE successfully.

    The problem here is how the authentication works? is the user/password full name was imported to TMSPE when importing and then go to VCS? or only modules imported to MSDS?

    I tried the connection, but he also inspired the name of username/password wrong, with logging below, but if I change the user password in TMSPE manully, then it works.

    2012 11-20 T 23: 58:18 + 08:00 VCSC tvcs: elements UTCTime = "2012-11-20 15:58:18, 406" Module ="network.http" Level = "DEBUG": Message = "Request" method = "POST", URL ="http://127.0.0.1:9998 / identification/name/lianzhao information" Ref = '0 x 3985970 '.

    2012 11-20 T 23: 58:18 + 08:00 VCSC tvcs: elements UTCTime = "2012-11-20 15:58:18, 411" Module = "network.http" Level = "DEBUG": Message = 'Response' Src - ip = "127.0.0.1" Src-port = "9998" Dst - ip = "127.0.0.1" Dst-port = '47550' response = "200 OK" ResponseTime = "0.003867' Ref = '0 x 3985970'

    2012 11-20 T 23: 58:18 + 08:00 VCSC tvcs: elements UTCTime = "2012-11-20 15:58:18, 411" Module = "network.ldap" Level = 'INFO': detail = "directory of identity authentication credentials: lianzhao"»

    2012 11-20 T 23: 58:18 + 08:00 VCSC tvcs: elements UTCTime = "2012-11-20 15:58:18, 411" Module = "developer.nomodule"Level = "NOTIFY" CodeLocation="ppcmains/sip/sipproxy/SipProxyAuthentication.cpp(453)" = thread of "SipProxyAuthentication::validateDigestAuthorisationCredentials" method = "0x7f7b9fffd700": calculated the answer does not match the answer provided, calculatedResponse = 6c510983415df744b9fc057cd5315133, answer = bfc97064a7d7e434f1a1d189e59d996e

    For authentication of device using NTLM in integrating MS AD, TMS import user account from the AD server (single user but account not password).

    This account information will export to VCS of TMS as provisioning user account (yet once does not include password).

    When VCS receive application for commissioning of Jabber client video, VCS will challenge ad server password.

    For traffic flow, please see the guide to deploy authentication https://supportforums.cisco.com/docs/DOC-25398 or peripheral.

  • VCS VCS - E, TMS, TMSPE, Jabber/Movi authentication

    Just trying to figure the best way to approach this.

    I have read the documentation and the best approach seems to get to the VCS VCS-E to Active Directory and the synchronization of the TMS with AD for user account creation. This would avoid the need to records movi proxy for control of VCS and would ensure that all (SIP and H323) registration for the VCS-E would be authenticated.

    I don't think that my client will allow the VCS-E talk to AD.

    So, what are my options?

    If I SIP proxy of VCS-E records the VCS control, how are they managing H323? I don't want just any point endpoint h323 register with the VCS-E. I need to authenticate them. The customer has exernal h323 endpoints that they would like to sign up for VCS - E. I know I could put registration rules to restrict only some URI SIP, H323 IDs etc but it's really just security by obscurity.

    The local on VCS and VCS-E database can be used for authentication Movi/SIP and H323 records? I know that I would have to duplicate accounts and passwords on both.

    What books commissioning and address through registration to the VCS-E? Would it still work?

    Any suggestions on the best way to handle this in the safest way possible without breaking things?

    If I go with the control of VCS and VCS Expressway with authentication Active Directory (directly) on the control method of the VCS as described in the guide of authentication devices, I'm looking for the reality that I will not be able to restrict who can register for the VCS-E? At this time should I just seek to restrict the search for rules to only authenticated users?

    Thank you

    Jon

    Hey Jon,

    MOVI/Jabber you won't have to worry about authenticating H323. With your endpoints however you can just use the database local to authenticate or H350 (more can be read about in the guide of the Provisioning device referred to as Tomo). You can create a different generic for all your endpoints (less secure if which is discovered). But by combining this feature with a political appeal will ensure better security.

    I highly doubt that your client will allow you to leave the talk VCSE in AD. For movi/jabber users, you can create another subfield and use a regex pattern for point movi/jabber users to authenticate it as. * (\.movi)@domain.com. In addition, you can refer to this fragment and others have used in the past.

    In a secure design, the VCS (control and Highway) would require identification for registration information.

    The Control of VCS would have Active Directory Service active and joins the Active Directory domain. For VCS authenticate the credentials of Movi/Jabber on Active Directory before the SUBSCRIPTION for the supply is sent to the service of commissioning, the default Zone would be set to verify the credentials. For requests for SUBSCRIPTION from the highway, the area on the VCS control would also to verify the credentials. It handles authentication for the provision.

    The next part is the record of the Movi/Jabber client. The subzone to which the customer will register must also be set to verify the credentials. Here's everything you need for internal records (registration to the VCS control).

    For the Highway, things get a little more complicated. For commissioning subscription, the SUBSCRIPTION is forwarded to the VCS control. With the area on the VCS game to check the credentials, you're all set. Now on registration to the highway. The subzone to which the customer will register to must be defined to check credentials. From the motorway VCS don't have direct access to Active Directory, we use local credentials on the highway. A set of credentials should be configured in VCS Configuration > authentication > devices > local database. You will create a single name and password all Movi/Jabber clients will use. The end user has NO need to know these credentials. The username and password is provided to the Movi/Jabber client via configuration data it has received. To set up these data, MSDS, you must configure a SIP of authentication user name and password for SIP authentication in the configuration of the commissioning. For these options to be available, you must ensure that you have downloaded the configuration template xml for the Movi/Jabber version you are using. The xml file is included in the zip package full of the client which can be downloaded on www.cisco.com. So, who will be recording from the highway. Now, this creates an interesting situation with VCS control. The internal Movi/Jabber client will receive the same provisioning configuration and will attempt to use those same credentials when you register for the control of VCS. The VCS control is already set to authenticate against Active Directory and Active Directory ONLY registration.

    You will need to create an account in Active Directory corresponding to these credentials. The Active Directory account didn't need special access. It is used only for authentication purposes. A few things to keep in mind: SIP authentication user name and password for SIP authentication are stored in clear text configuration configuration. This means that the data is sent in clear text. To be sure that these data are not compromised on the wire, do not forget that you are using for your communication SIP Movi/Jabber TLS.

    With this directories will always work as jabber should be authenticated in order to receive directories. Your physical endpoint points will work differently with how they receive books and whether or not they are able to communicate with MSDS (unless you choose to configure endpoints also if those you are capable).

    It is in no way the design as safe as possible. It is to you to ensure that your environment is as secure as possible and therefore tested. The best way to fix everything is a well-defined appeal policy designed with your specific needs.

    The foregoing is in no way a recommendation but just a little more information to chew while looking to choose and implement what is best for you.

    Adam

  • Issues of authentication VCS/AD/MOVI

    Hey all,.

    Got a customer with X6.1 on its VCS-E & VCS - C.  MOVI worked perfectly well.  Then, we have added the VCS - C to the domain and activated the NTLM authentication.  MOVI still works using the new AD credentials, but we have problems (2).

    (1) the customer used MOVI v4.2 and everything works fine.  Client Jabber v4.4 downloads and they can no longer connect.  Looks like she does not query even the SCV - C, seems to pass directly to the VCS-E.

    (2) when MOVI v4.2 or Jabber v4.4 try to connect to the VCS-E they are unable to authenticate.  What are the policies of auth area required for the VCS-E & VCS - C when you use NTML authentication?

    Thank you

    Justin

    Hi Justin,

    Check the other threads on CCS. To answer your questions:

    case 1: If the Jabber is not able to get a response in the final timeperiod, then it will change to the motorway.

    case 2: check the links below

    https://supportforums.Cisco.com/message/3425760#3425760

    https://supportforums.Cisco.com/message/3599742#3599742

    Thank you

    Alok

  • I already bought the movie HD, 'V for Vendetta', before it came with "iTunes Extras" but my purchased copy does not come with the Extras. Is there a way to fix this without having to buy the movie again?

    I already bought the movie HD, 'V for Vendetta', before it came with "iTunes Extras" but my purchased copy does not come with the Extras. Is there a way to fix this without having to buy the movie again?

    I was told that movies in the iTunes Store can be changed to include "iTunes Extras" if originally it did not come with extras. But there is a catch you get just the extras if you buy just the issue for the first time. If you have already purchased it, your version may not have the extras. This means that if you want the extras, buy the movie again.

    If you now get the Extras will depend on what the movie studio did for example if they have updated the version you have purchased, or replaced by a new version (which will be treated as a separate purchase): buy and play movies with iTunes Extras - Apple Support

  • With the new update, I lost in front of the stage.  I used it all the time for the band movie trailers.

    I just upgraded to osxel capitan 10.11.1 and lost a program called the front of the stage.  Many of us he used and enjoyed.  It has been used for the bands movie trailers and was great.  Does anyone know why it isn't available any longer?

    It was abandoned 4 years ago. https://en.Wikipedia.org/wiki/Front_Row _ (software)

  • Disney movies anywhere with iTunes connect accounts

    I received this email, which sounds official, but anyone can verify that he is indeed a real e-mail from Apple?

    Dear [customer],

    The video Privacy Protection Act requires Apple to get your permission to share your Disney movies purchased from iTunes with Disney movies anywhere every two years.

    To meet the requirements of this Act, we disconnected your Disney movies anywhere account from your iTunes Store account. This change will not affect one of the Disney films currently in your iTunes account.

    To continue to use Disney movies anywhere with iTunes, you will need to reconnect to your accounts. For more information on Disney movies anywhere, visit our support page.

    Kind regards

    The iTunes team

    I got a corresponding e-mail from Disney movies anywhere

    -----------

    Thank you to be a member of the family Disney movies anywhere! We hope that you're enjoying the opportunity to share your digital movies in all of our ecosystem digital providers, including iTunes, Amazon Video, VUDU, Google and Microsoft Movies & TV game.

    Periodically, we update the consent you gave when you joined Disney movies everywhere where you have to share your movies on your accounts in the Disney movies ecosystem anywhere.

    To do this, simply click on the button below or sign in Disney movies anywhere via the website (www.disneymoviesanywhere.com) or one of our applications to update your account.

    ----------

  • Connection of a drive motor for the FSP Yaskawa Sigma with UMI-7774 and PCI-7344

    Hello

    I have PCI-7344 and UMI-7774 I want to connect to this of Yaskawa Servo motor control.

    (1) how will I know if this drive is compatible with the pci-7344 and umi7774?

    for example: inside the UMI manual is written that the engine must support "Sinusoidal Commutation"

    I look at it the drive motor manual and I can't find anything about.

    It's link to the drive motor:

    http://www.Yaskawa.com/site/products.nsf/products/servo%20Amplifiers~fspsigma.html

    http://www.Yaskawa.com/site/products.nsf/products/servo%20Amplifiers~fspsigma.html?OpenDocument&seq=...

    (2) how to connect lines of control and feedback from the UMI to the engine?

    I enjoy all the help showing a link to a tutorial that allows to understand signals from the motor and encoder

    And also the umi-7344 (Phase A, Phase B, Hall sensor, inhibit, breakdowns, etc...)

    Some powerpoint or Pdf tutorial for National instruments will help as well.

    P.S. I read the manual of the UMI-7774 and pci7344 manual, but I'm not yet understand what I need to do

    in order to configure my system of movement:

    By car (Sigma FSP Yaskawa) PCI-7344, UMI-7774, motor, servo (Yaskawa)

    Thanks for any help.

    Kind regards

    Moti

    Dear Moti,

    At this point I recommend contacting National Instruments of support here.  You can send a request by e-mail and once a technical support representative has responded, you can attach to your document. Don't forget to categorize your request like vision or movement associated with, and I or one of the members of my group will be able to help.

    Best regards

    ~ Nate

  • I have two vista windows oem sctatch disk at home. You can download it for me, these two are with the product key to the House.

    I have two vista windows oem sctatch disk at home. You can download it for me, these two are with the product key to the House.
    It is upgraded, the other is an integer telling Windows Vista;
    and the little hard up and down, mouse from left to right,.
    or can you please sent a copy of a disc to my address, this is the right path for fixed my windows vista online.
    (try to contact technical support of the direct Vista operating system)
    How about upgrading to windows 7? Give me the vista on 'the base drive OEM' continues for facilities?
    ----------------

    Replacement OEM or software support of system manufacturer in most cases, you must contact the OEM (OEM) manufacturer or the manufacturer of the system directly to replace Microsoft software that was distributed by your computer. However, an exception is made for operating system service pack media *, for which you can contact us directly.

    • Contact information for the manufacturer of the computer, see the Microsoft Web site at the following address:

      http://support.Microsoft.com/default.aspx?pr=oemphone (http://support.microsoft.com/default.aspx?pr=oemphone)
    • If the product has been distributed by an OEM or a system integrator, the product ID contains the letters "OEM". Visit the Microsoft Web site at the following address, select the appropriate product family, and then follow the steps to find the product ID:
      http://support.Microsoft.com/default.aspx?PR=notsureoem (http://support.microsoft.com/default.aspx?pr=notsureoem)
    • For OEM software, the certificate of authenticity (COA) lists the name of the manufacturer of the computer under the software version name. For more information on the certificate of authenticity, see the Microsoft Web site at the following address:
      http://www.Microsoft.com/resources/howtotell/ww/FAQ.mspx#1 (http://www.microsoft.com/resources/howtotell/ww/faq.mspx#1)

      If you have System Builder software, the COA lists "OEM software" or "OEM product" under the software version name.

    * Note Service pack support only includes what is associated with the service pack itself.

    More information: http://support.microsoft.com/kb/326246

    Regarding Windows 7 - frequently asked questions - Upgrade Options
    http://www.Microsoft.com/Australia/Windows/buy/offers/upgrade-FAQ.aspx TaurArian [MVP] 2005-2010 - Update Services

  • I want to be able to move freely photos on a Windows Word page, but the photos keep snapping it back in place on the margins. Is it an alignment etc. function that I can disable so I can move photos with the cursor?

    I want to be able to move freely photos on a Windows Word page, but the photos keep snapping it back in place on the margins. Is it an alignment etc. function that I can disable so I can move photos with the cursor?

    I want to be able to move freely photos on a Windows Word page, but the photos keep snapping it back in place on the margins. Is it an alignment etc. function that I can disable so I can move photos with the cursor?

    =================================
    Change the text wrapping...

    In Word 2007... I'm going to... Format / dressing / thanks to...

    Then I can use the arrow 4 positions to drag photos anywhere
    I chose.

    If you want to drag the photos on the page...
    I don't know how to do this. John Inzer - MS - MVP - Digital Media Experience - Notice_This is not tech support_I'm volunteer - Solutions that work for me may not work for you - to proceed at your own risk

  • How to access the old movie effect for Windows Live Movie Maker

    How can old age for Windows Live Movie Maker movie effect - I get?

    Hello

    It would be really nice if someone could answer my question very soon! I need to do a presentation for the 80th birthday of my Nan :)

    In the old Windows Movie Maker, I think it is XP, there has been an effect called the 'Age of the Film' effect, old He gave the video/photo a grainy effect, old movie. Personally, I liked using it, and now in Windows Live Movie Maker, he never saw. Is there a way I can download, or something?

    S ' PLEASE help us!

    Ask for more details if necessary =]

    Thankyouuu

    Hi Lexx6,

    We do not have the same Visual effects available in Windows Live Movie Maker. There are various other effects black and white available with different shades. Follow the link for more information.

    http://windowslive.com/desktop/MovieMaker

    Alternatively, you can leave your comments in the below given link

    https://connect.Microsoft.com/?WA=wsignin1.0

    Hope this information is useful.

    Amrita M

    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Why can't I just move on with windows7 starter to windows 8, my computer is only 9 months since purchest?

    Why can't I just move on with windows7 starter to windows 8, my computer is only 9 months since purchest?

    So it will not uninstall then install my programs, or what, then another question is the offer for $14.99, that's what I was watching and I filled a free upgrade and probably has not been fully tested for this upgrade, he said I would be able to get the upgrade, but there is no decrease in my emails guess still in work. While {s it improves just $ 40 million that I should wait for a version pro or ultimate?

    And what will happen to my saved files?

    and I'll be able to restore to the factory with warranty setting and I can use my series to my computer for the upgrade?

    NOW please if you don't know it please tell me I would like to know some facts and since there is so much development, in my view, the pro version is yet to come, so...

    Windows 7 Starter is not eligible for the offer of $14.99.  Only Windows 7 Home Basic, Home Premium, Professional and Ultimate. If you must upgrade to Windows 8, then you have to wait on the upgrade $ 39.99 for Windows 8 Pro that will become available October 26, 2012.

    The upgrade will allow you to keep your applications, personal files and settings.

    Yes, it should be able to restore the factory State, but always backup before making changes on your computer like installing an operating system:

    http://www.notebooks.com/2009/10/24/how-to-backup-your-installation-of-Windows-7/

  • How to configure NAT for Hyper-V on laptop with wifi, wired and vpn connectivity

    Me, as I suspect a lot of people, I have a laptop with WiFi connection, cable connection and VPN connection (Cisco AnyConnect), which

    also uses a virtual adapter (activated when active). I searched for some time a way to be able to move to

    Hyper-V in VirtualBox. Blocker full for me is the need for a lot of my virtual machines to be able to connect to the

    Internet through 'the connection active' in the way that VirtualBox and VMWare Workstation/Player through their NAT feature.

    I'm not a networking wait, but after looking around, can't seem to find something that is simple enough for me to configure,

    with a minimum of resources, which allows me to connect a Hyper-V virtual network via a simple NAT device adapter

    all three potential network connections - most seem to not assume that one connection out of the machine, which of course does not

    me what I want.

    Three questions:

    1. is there a Windows application available that an adapter (like loopback) internal which acts as a real NAT device to one of the surfaces

    external access via the active network connections and through the Windows Firewall and any other antivirus, components etc. for

    the road to (i.e. behaves like a "normal app" inside Windows for internet access)? It would be the best option, because it would be

    "always there" when I run virtual machines

    2. display of my lack of knowledge around this feature, don't RRAS (and I know that this is not an option "minimum contact") allow you to

    Connect an internal network adapter to several external network adapters?

    3. on the Linux/OpenBSD various base/NAT routers, are everything that allow several external adapters and who are

    relatively easy to set up (by an independent expert of the network)?

    Really, we could do with this feature for Hyper-V on the desktop, but willing to work around him, if there is a way to at least the

    use virtual machines, once it is easy to install.

    Hello

    The question is more suited in the TechNet forums. So I would say you mention the link and send the request in this forum for better support.

    http://social.technet.Microsoft.com/forums/en-us/w8itpronetworking/threads

    For any information related to Windows, feel free to get back to us. We will be happy to help you.

  • All my objects in Indesign are locked. I can move objects with the help of the arrow keys on my keyboard, but not with the mouse. I must have done an order by mistake. Any suggestions?

    All my objects in Indesign are locked. I can move objects with the help of the arrow keys on my keyboard, but not with the mouse. I must have done an order by mistake. Any suggestions?

    Thanks for your help. I work again InDesign brokedown and after a reboot, everything works perfectly fine.

  • Impossible to move anything with the mouse in Photoshop CC 2015 running on Win 8.1

    Hello world

    I can't move anything with the mouse in Photoshop CC 2015 running on Win 8.1. I can't even move/resize the cropping frame when activated.

    However, I am able to move any layer with the help of the keys on my keyboard. (it happened also in Indesign)

    How can I fix this?, please, it drives me crazy!

    Thanks for your help!

    Hi crazyfoo,

    You run Photoshop CC 2015 (latest version) with a Tablet Wacom (drivers day)?

    If this isn't the case, so it could be other drivers of conflicting devices. See the mouse, hand tool works do not at all!

    What is your operating system and the computer specs?

    Kind regards

    Assani

Maybe you are looking for

  • Preferences of Safari does not work

    Hello I have read several replies to other posts on how to set a homepage in Safari.  I have Safari 9.0.1.     iOS El Capitan 10.11.1 Safari-Preferences translates no response at all.  The Preferences dialog box does not come to the top.  Nothing. An

  • Satellite Pro M30: connection problem!

    Hello After I connect to the Internet via modem, the machine (specifically, the status bar) freezes. In addition, could not start the MSN (6.2). After about 10 minutes, the system works normally and very well. Help, please! Data sheet:Satellite Pro M

  • Pavillion DV6: DV6 restart when stop

    Help! I'm a COMPUTER tech and have never known a subject as frustrating as this. If I have laptop DV6 of off windows startmenu and application downtime everything fits well and looks at the stop, but there is a break of about 2 or 3 seconds where all

  • Configuring sound card not open?

    Hello I'm working on the tutorial of 3 h of the NC and accessed at page 50 of the dokumnet. Exercise 3.2. Alternative C. Anyone know how I can find the reason of the problem and the solution, see the following error message: error 4803 bei Audioaufna

  • Detection of the ethernet on a XP operating system card

    I have a SG3730IL. Recently, I went from Vista to XP. I was able to solve all the problems related to the drivers (including the SMBus Controller) except detect the network card. I'm unable to find the suitable driver for the same. I think that even