WebEX meeting server authentication question

Hi all

We have configured the LDAP authentication integration in WebEx. We want to avoid the brute force attack and to minimize the use of the password of the internet domain, are there other methods of authentication?

If we help to use stand-alone account WebEx, any policy password as complexity, duration and expiration date in WebEx?

Thank you!!

Danny

Hey Danny,

If you have activated the LDAP authentication and integration with CWMS (via CUCM), then your users profile directory using LDAP credentials to authenticate on CWMS. It is not possible to disable the requirement for active profile users authentication.

There are two other user accounts on CWMS management methods:

1. LDAP via SAML 2.0 integration (Single Sign-On), but that you have IIP provider accessible from the internet, would require that authentication would be on this end. You can read more here:

http://www.Cisco.com/c/en/us/TD/docs/collaboration/CWMS/2_7/Planning_Guide/cwms_b_cwms-planning-system-requirements-2-7/cwms_b_cwms-planning-system-requirements-2-7_chapter_0111.html

http://www.Cisco.com/c/en/us/TD/docs/collaboration/CWMS/2_7/Administration_Guide/cwms_b_cwms-administration-2-7/cwms_b_cwms-administration-2-7_chapter_01110.html#id_13124

2. using local profiles CWMS. With local user profiles, user accounts are created manually or by importing of CUCM (you can still have the integration Directory to import profiles of CUCM, but requiring users to use created locally passwords on CWMS (do not enable LDAP authentication)), and passwords are created manually by end users locally on CWMS. Regarding the strengthening of password, you can consult this document:

http://www.cisco.com/c/en/us/td/docs/collaboration/CWMS/2_7/Administration_Guide/cwms_b_cwms-administration-2-7/cwms_b_cwms-administration-2-7_chapter_01110.html#concept_E2AC8672B23C487887A8AFFAE6C1EBDB

I hope this helps.

-Dejan

Tags: Cisco Support

Similar Questions

  • Cisco Webex meeting server usually ask Q & A - CWMS

    At a query concerning Cisco Webex meeting server below to the questions from customers,

    Appreciate if anyone has the answer please reply and help, thanks in advance.

    --------------------

    Q1.  We can block a current mtg (possible venue) where
    We cannot arrest anyone joining after the session started
    If a participant who was invited to the meeting trying to reach the end?

    Q2.  Slide the CWMS running 6 virtual machines inside.  For 50 simultaneous
    user-systems, is only 1 VM - the VM admin who also makes the web and
    functions of the media?  Also, in the superior user-concurrent systems numbering, make virtual machines
    Break-in of the separate machines for ESXi?

    Q3.  If you add users to the CWMS, only two modes are available:
    the hosts or administrators. Please correct me if I'm wrong - hosts are those who can
    program / participate / host the meetings. How to differentiate and control a crowd
    only attend but not host meetings?  If all users are added in an organization
    as hosts in the CWMS, control the use of the licenses will be difficult, no?

    Q4.  Can deploy us CWMS on VBlock?

    Q5.   How invite us someone to a meeting if it is not a user on the
    CWMS (as external consultant)?

    Q6.  Referring to the Q5, how would someone outside of the Organization
    (i.e.  stakeholders) be validated and authorized to participate in a meeting, especially
    If it does not use Ms Outlook?

    Q7.  Referring to Q6, are we supposed to create an external person accounts
    on the CWMS?

    Hello

    Q1: I m unaware of such a feature

    Q2: For 50 users non-system you only have one virtual machine if you do not have PRI. It's a complex answer on the second part of the question let me provide you with a document for you to review.

    http://www.Cisco.com/en/us/docs/collaboration/CWMS/b_planningGuide.PDF

    Search for planing guide.

    Q3: You understand the basic concept of admin/host, but I'd sugguest you were talking to your account team regarding licensing as it should not be a problem for current users "System.*" actually how many users are there.

    Q4: Let me re - search a little more here and get back to you

    Q5: Can you invite by email adresss and he can join form outdoors if you have for IRP in configuration as well.

    Q6: They will be invited by email and can join through PC customer /mobile etc..

    Q7: No, it is not necessary

    If you need help me please do not hesitate to send me an email.

    Thank you

    Srdjan

  • WebEx meeting Server 2.0 - setting up the smtp server

    Configuration of SMTP server for the Webex Server 2.0 meeting, the manual States:

    Possibly to enable authentication of mail server, select the server authentication enabled.

    If you enable authentication, enter credentials user name and password required for the system access to the e-mail server of the company.

    System emails are sent by admin @. Make sure that the mail server can recognize this user.

    -What exactly does "ensure that the mail server can recognize this user"?

    • I have to configure the admin @ account on the SMTP server? (customer can configure only e-mail as account [email protected] / * /)
    • Or admin @ is the property of «of» the mail and SMTP server should accept this property 'from'?

    -What happens if the user name and password are not specified?

    Thank you

    Here you have two options:

    (1) either use authentication: you must create a user account in exchange.

    (2) do not use authentication: let disabled authentication and configure exchange to relay emails from CWMS.

    "-What exactly does 'To ensure that the mail server can recognize this user'"?".

    "- What happens if the user name and password are not specified?"

    This means that if you enable authentication - create a user account for CWMS in Exchange. If this isn't the case, then have the exchange server that is configured to relay CWMS emails. Its simple allow only the ip address of CWMS in Exchange to accept and relay e-mail.

    If it does not means that you don't want to receive emails from CWMS and as you know email principal means of CWMS communicate with users.

    Simple way is to leave off authentication and configure the relay. I did this couple of times in the past without problems.

    -Terry

  • Flash Media Server Authentication component software plug-in installation question

    I downloaded the Add-in authentication for use with FME 2.5 and have been unable to install it. I'm trying to install it on my local computer that is running the development version of FMS. If anyone can shed some light it would be great. Thank you

    We have just released a new version of the Add-in to Flash Media Server Authentication for FME 2.5 that works with the release of Flash Media Server relies. You can find it at http://www.adobe.com/go/fme with version 2.5 of FME.

  • How to use WebEx Meeting Center with MX300 G2

    Hi all

    We have telepresence infrastructure following implementation and work:

    -VSC Highway

    -CUCM

    -IM & presence server

    -Telepresence Server

    Can to sign up customers Jabber against Expressway, have put in place all records DNS etc and all this side of things works well.

    We also have our G2 MX300 on Expressway and it can make internal calls to Jabber client etc.

    We are now trying to get the G2 MX300 connected to our WebEx Meeting Center () account, so that we can join the meetings on the G2 MX300 and see the meeting schedule using the 10 "telepresence touchscreen etc..

    Can you please give us a clue on how we get WebEx works on the G2 MX300?

    Thank you very much

    CMR Hyrbid Configuration Guide, Note this requires Cisco Advanced Services or partner Cisco qualified to perform the implementation.

    CMR cloud is just an addon service WebEx Meeting Center.

    Cloud of CMR uses Cisco's TelePresence infrastructure in the cloud to do throughout the Conference, while Hyrbid will use your infrastructure on site.

  • WebEx meets the users server management issues

    Hi all

    I have three questions about the management of the user accounts on CWMS.

    (1) cisco document mentions that a creation of password email will be sent to an new added manually to the users, but the document does not mention if a new user imported via cvs file will be sent an email from creation of password or not?

    (2) If a new user has been added to CWMS via LDAP synchronization, CMWS email will inform the user about the creation of the account automatically?

    (3) If a user account has been imported to CWMS via cvs, if on file after LDAP synchronization, the user account will be overrided or the user account will be duplicated?

    Thank you

    Danny

    Hey Danny,

    Let me answer your questions:

    (1) Yes. Accounts imported via CSV when you use local user (without integration of directory or SSO) accounts marked as active during the import will get a "required Action: create a password for your new account" e-mail system.

    (2) only if you enable LDAP authentication you can configure notifications about creating an account that will be sent. You can configure to be automatic by checking the 'send notifications automatically", or you can manually click the"Learn more now"to inform all users imported from the creation of the account.

    (3) if the e-mail address of the account is the same locally on CUCM, the account will not be substituted. If an e-mail address is different, a new account will be created while the account is disabled.

    I hope this helps.

    -Dejan

  • RADIUS authentication question

    Hello world

    I'm learning the Radius Authentication. Here are my updated laboratory in place:

    R1 (107.107.107.10)-(107.107.107.4) - WIN2008 (RADIUS SERVER)

    Here is the config of RADIUS on the R1:

    AAA authentication login default local radius group

    RADIUS-server host 107.107.107.4 auth-port 1645 acct-port 1646
    key cisco RADIUS server

    I have a few questions:

    (1) above, I do not specify encryption on R1, R1 will use this as the default encryption?

    In the attached file, we see the password is encrypted, but there is no config on R1 to use particular encryption

    (2) we also see "authenticator", which is I think is R1 host name i.e encrypted with the shared secret. I'm wrong?

    Much appreciated and have a great weekend!

    Hello

    The Protocol Radius encrypts the password for the default user. I think that Radius uses MD5.

    The authenticator is a random string generated by the client and is used in the encryption of the password process.

    Thank you

    John

  • Client VPN authentication question

    Hi friends,

    I recently started a new company, where the Cisco VPN Client is used by all remote Windows users. I'm not familiar with the customer. I see by our remote access policy that clients authenticate using PAP. This immediately caught my concern.

    My question is if this poses a threat to security? Even if the authentication is not encrypted, it is always the case in a 3DES IPSec tunnel, right? What is the best practice regarding using the VPN client and authentication?

    Thanks in advance!

    Equipment:

    Cisco VPN Client v5 (latest version) on Windows XP SP3

    Microsoft IAS (RADIUS) on W2K3 Server R2 x 64

    Router Cisco 3825

    IOS 12.4.24T Adv IP Services

    If I understand your customer VPN ends on 3825 router. the customer gets the name of username/password prompt after than phase 1 so it may not be clear.

    I hope this helps

    concerning

    -Syed

  • AAA authentication question

    Here is the config, I have a switch:

    AAA authentication login default group Ganymede + local

    AAA authentication login vtylogin group Ganymede + local

    AAA authentication login conlogin group Ganymede + activate none

    the AAA authentication enable default Ganymede + activate

    Now, here are my questions:

    1. when I have my login of Ganymede console connection works, but when I type 'enable' and try to use my password to Active Directory, it does not work.  So I try the enable password, don't worry.  However if I change the 4th line "aaa authentication enable the Activate by default", I can now by using the enable password.

    2. my second question is when I SSH into the switch, I want only that it uses the RADIUS server and use only the database local when the Ganymede is not available.  However while Ganymede is available, I am still able to login using the local user account.  I guess that's by design?  Is there a way to prevent this if it isn't design?

    When you use the local user account to connect to the device, can you check if you can see the log in "past the authentication attempt" on the box of the CSA? If so, the same account could you please check your local ACS DB user to see that it was created by a fake?

  • NTP server authentication

    I'll put up the master NTP server on Catalyst 4000 series switch. I want to implement authentication between the server and the client. I have the following commands is not working.

    What's wrong with the commands below?

    Server:

    NTP-1 xxx md5 authentication key

    authenticate the NTP

    NTP master 6

    NTP max-associations 10

    Client:

    NTP-1 xxx md5 authentication key

    authenticate the NTP

    key to NTP server 10.0.0.1 1

    AV

    I think there are two separate issues here and they are not really related to each other. It is a question if your switch must be configured as master ntp. If the switch is configured as master ntp, then it will offer his version of time that it is authoritative or not (either correct or not). I think it is a bad idea and hope that this is not something that you did intentionally.

    The other question is why the switch is not hours of instruction from the marine server. It seems that there are several reasons why this can happen. It is possible that the NTP requests you are not to get on the server or the server responses aren't you. My guess is that it probably is, since the show ntp association does not show a reference to the server of the Navy clock. Or it is possible that the NTP response is you but there's not enough variability in traffic through the network switch is not able to synchronize with the server. I saw a customer network when it's a problem for a while.

    I would say the next step could be to debug ntp package and see if you send to the correct address and see if you have found answers.

    HTH

    Rick

  • In weblogic server interview questions

    Hello

    Veuileez can you tell me everything time real maintenance issues to the server administration weblogic (8.1 or 9.2 and 10.3) or advice me how to details.


    Thanks in advance
    Bajaji kumar

    Hi Bajaji,

    Especially for the preparation of the interview... There is no such good site on WebLogic... but you can make reference to: http://crkthoughts.blogspot.com/2009/12/weblogic-faqs.html (RaviKiran) Blog to get an idea.

    E docs are always the best... to meet the... interview questions as well as for orders in real time...

    .
    .
    Thank you
    Jay SenSharma
    http://WebLogic-wonders.com/WebLogic (WebLogic wonders are here)

  • new OS authentication question

    Hi guys,.

    Firstly that it is a cross-post of confused about "identified on the outside" , the reason being that I had already marked this issue as 'answer' (before I came up with another question) and so a lot of people will probably look into it.

    In any case, I was looking at the following link
    [http://www.dba-oracle.com/t_windows_external_user_authentication.htm | http://www.dba-oracle.com/t_windows_external_user_authentication.htm]

    Where it is said

    -----------------------------------------------------------------------------------------------------------------------
    CREATE USER OPS$ SCOTT IDENTIFIED BY TIGER;

    Assuming that Scott has logged on to the operating system, Scott could enter SQLPlus with or without password:

    sqlplus.
    sqlplus scott/tiger

    You can also create the user with the clause "identified externally:

    CREATE USER OPS$ SCOTT IDENTIFIED EXTERNALLY.
    -----------------------------------------------------------------------------------------------------------------------

    Why Scott may enter without a password? We have not said that Scott is identified on the outside in the first example. Yes, we preceded the name of scott with OPS$, but only enough to tell Oracle that this user must be identified by the authentication of the os?

    Thank you

    Generally, it took "identified on the outside", but there is a documented exception: ops$. "+ If the OS_AUTHENT_PREFIX is set to OPS$ user can connect in a manner if created with a password." + »

    SYS@orcl > show parameter os_authent_prefix
    os_authent_prefix          string   ops$
    SYS@orcl > create user ops$eorbegozo identified by oracle;
    SYS@orcl > grant create session to ops$eorbegozo;
    
    [eorbegozo@caliope ~]$ connect /
    Connected to:
    Oracle Database 10g Enterprise Edition Release 10.2.0.4.0 - Production
    With the Partitioning, OLAP, Data Mining and Real Application Testing options
    OPS$EORBEGOZO@orcl >
    
    SYS@orcl > show parameter os_authent_prefix
    os_authent_prefix          string   osuser$
    SYS@orcl > create user osuser$eorbegozo identified by oracle;
    SYS@orcl > grant create session to osuser$eorbegozo;
    
    [eorbegozo@caliope ~]$ sqlplus /
    ERROR:
    ORA-01017: invalid username/password; logon denied
    
    SYS@orcl > alter user osuser$eorbegozo identified externally;
    User altered.
    
    [eorbegozo@caliope ~]$ sqlplus /
    Connected to:
    Oracle Database 10g Enterprise Edition Release 10.2.0.4.0 - Production
    With the Partitioning, OLAP, Data Mining and Real Application Testing options
    OSUSER$EORBEGOZO@orcl >
    

    You can read the Note: 18088.1 UNIX: OS authentication on the Oracle server for more info.

    Enrique

  • Happy Integration Suite: Mode of Stand Alone Server: authentication

    I'm just started to try to understand and the CIS. The question I'm trying to answer is: why when trying to initialize the CIS, we do not credentials. I looked at the example and CheckInFile.java for example, I do not see a routine that asks the customer to identify or authenticate.

    I see that in the SIS API, the client must connect / authenticate but not in the CIS. What did I miss?

    Thank you!

    Published by: user644025 on September 11, 2008 12:11

    Hello

    You will not miss anything, it's actually a really cool feature. Default WHAT CIS connects to your content server, much the same way that the web server is on port 4444. When you live like that, you can ignore the authentication and just get a username. The content server must be pre-configured, but to allow a connection from the server you use CIS, although. You probably run it local on the same machine the server content, so you do not encounter any questions, but if you you connect from a remote server is ip must be included in the security filter in the config.cfg file server ip. CIS can be configured to connect to the web server rather than on the content server case you need credentials.

    David

  • Thunderbird 24 pop server authentication

    I use Time Warner Cable (TWC) and Thunderbird (24.4.0) running OS X on a macbook air 10.9.2

    Until about 01:45 east coast U.S. today, I could send and receive on my two accounts in Thunderbird, which all worked fine for the last 2 years 1/2. I can always send and receive emails fine with their web client. I can receive receive in Thunderbird now, but cannot send. The failure of sending began with one account and now affects both.

    At first, I got a message error ro1007005 failed to authenticate to an account, then the other. After

    After more than an hour with TWC we confirmed that my SMTP settings are correct view of TWC as follows

    Server SMTP = mail.twc.com Port = 587 = password, transmitted unsecured way authentication method.

    However, I now get the following:

    Whenever I try to send, I get the following:

    The message send failed.
    The message could not be sent using SMTP server mail.twc.com for some unknown reason. Please check that your SMTP server settings are correct and try again or contact your network administrator.

    Any help would be accepted with gratitude.

    Have you contacted TWC to see if they have some sort of failure?

  • Windows 7 slow login / delay authentication question user wireless via ACS 5.8

    Just set up a new ACS 5.8 farm (only 2 servers) here and which I hope someone here can shed light on the difficulties.

    The new ACS server is set up to correctly authenticate administration network device and I am currently working on the definition of profiles for our wireless users authentication and business laptops.

    Being new to this version of ACS (we will migrate manually ACS 4) I followed an excellent example of this task described in a video on this site: http://www.labminutes.com/sec0044_ise_1_1_wireless_dot1x_machine_auth_peap

    I managed to have a Windows XP sp3 client authenticate properly, first with the authentication of the computer, then the authentication of users... and the domain logon process takes place in a short period of time< 1min="" and="" the="" user="" gets="" all="" their="" networked="" drives="" via="" the="" domain="" login="">

    However, I'm fighting to get our Windows 7 clients to authenticate properly.  It seems that the machine authentication does not work as expected (I can ping the laptop test from another machine on the network while the test machine is sitting at the login screen; and I see Authentication host recorded in the papers of authentication Radius ACS).  But, when a domain user logs in with his credentials, the connection process takes 4-5 minutes before an event to authenticate the user is entered in the register authentication Radius ACS, after which the login process completes, except that the domain logon script does not work and the user does not receive the drive mappings.

    Can someone point me in the right direction here?  I would be grateful any entry on this.

    Thanks in advance,

    John

    I had a similar problem with Wireless 802.1 x Win 7 clients unable to connect unless they had cached credentials of the AD.  Authenticate in the machine, but the user would take a lot of time if the Windows credentials have been cached.

    I could solve the problem by expanding the ACL of the air space used during the user authentication to include all DC in the environment.

Maybe you are looking for