<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UAM LDAP Sync setup in IMC</title>
    <link>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6963632#M3778</link>
    <description>&lt;P&gt;Did you set up the virtual computer?&lt;/P&gt;&lt;P&gt;The user synch with AD, which uses a credential configured in the LDAP server setup, gets user information from the &lt;SPAN&gt;domain controller&amp;nbsp;&lt;/SPAN&gt;and set up user accounts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as Peter describes above the user credentials do not come across from the &lt;SPAN&gt;domain controller&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;The virtual computer is used by UAM to proxy the authentication request to the domain controller when a user logs in. You have to add the virtual computer to the domain so it is trusted for this purpose.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 May 2017 19:04:47 GMT</pubDate>
    <dc:creator>NeilR</dc:creator>
    <dc:date>2017-05-08T19:04:47Z</dc:date>
    <item>
      <title>UAM LDAP Sync setup</title>
      <link>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6018475#M546</link>
      <description>&lt;P&gt;Going to ask what might be considered a silly question...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why does the AD LDAP userPassword attribute not appear in the list of LDAP Sync attributes? What am i supposed to map the sync'd password field to in order to use the AD User Password with UAM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2013 22:53:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6018475#M546</guid>
      <dc:creator>MartiBarber</dc:creator>
      <dc:date>2013-04-02T22:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: UAM LDAP Sync setup</title>
      <link>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6019545#M547</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some LDAP servers store the user password in the password field (I know, that sounds obvious :) ), so external authorized users (admin/service accounts) could read the password and sync it for example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Microsoft AD (MS LDAP server), stores the password with a 1way algoritm, so a password can be validated, but not reverse de-crypted. Due to this (good) decision, any external system can sync all the ldap objects and their attributes, but not the password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So IMC UAM can sync the new/existing users and their attributes, but not the password. This is why the AD LDAP sync does not allow the ldap password sync.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For IMC UAM to authenticate users with their password, the IMC UAM server must be joined to the domain, (see domain controller assisted PEAP auth), so it can validate the user pass at the moment the user actually logs in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,Peter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2013 18:55:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6019545#M547</guid>
      <dc:creator>Peter_Debruyne</dc:creator>
      <dc:date>2013-04-03T18:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: UAM LDAP Sync setup</title>
      <link>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6019651#M548</link>
      <description>&lt;P&gt;Thanks Peter, very helpful. I'll move onto to the domain assisted section and keep reading.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2013 20:54:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6019651#M548</guid>
      <dc:creator>MartiBarber</dc:creator>
      <dc:date>2013-04-03T20:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: UAM LDAP Sync setup</title>
      <link>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6963333#M3775</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you get this resolved? We have v7.2 and I have the same issue. It says :&lt;/P&gt;&lt;P&gt;Failure Reason: Incorrect Password.&lt;/P&gt;&lt;P&gt;It syncs no problem with AD.&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 01:32:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6963333#M3775</guid>
      <dc:creator>WayneWIlson</dc:creator>
      <dc:date>2017-05-08T01:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: UAM LDAP Sync setup</title>
      <link>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6963632#M3778</link>
      <description>&lt;P&gt;Did you set up the virtual computer?&lt;/P&gt;&lt;P&gt;The user synch with AD, which uses a credential configured in the LDAP server setup, gets user information from the &lt;SPAN&gt;domain controller&amp;nbsp;&lt;/SPAN&gt;and set up user accounts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as Peter describes above the user credentials do not come across from the &lt;SPAN&gt;domain controller&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;The virtual computer is used by UAM to proxy the authentication request to the domain controller when a user logs in. You have to add the virtual computer to the domain so it is trusted for this purpose.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 19:04:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/uam-ldap-sync-setup/m-p/6963632#M3778</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2017-05-08T19:04:47Z</dc:date>
    </item>
  </channel>
</rss>

