Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

AD group type

This thread has been viewed 9 times
  • 1.  AD group type

    Posted Apr 27, 2015 02:54 PM

    Short version: Does the AD group type (universal, global or domain local) have any bearing on role derivation in CPPM?  User is in a global group "elementary" which is then part of domain local group "Employees".  I keep getting failures to authenticate because CPPM does not indicate the user is in "Employees" but AD clearly shows that it is there.  The user in question does show up in the groups he is directly added to but not the nested group (in CPPM details).  SubTree Search is turned on for the AD authentication source.

     

    I've done this before at a previous job but I had no access to AD at that location.  I suspect it doesn't matter but I could be wrong.



  • 2.  RE: AD group type

    EMPLOYEE
    Posted Apr 27, 2015 02:56 PM
    Are you using "Groups" or "memberOf" in your authorization?


  • 3.  RE: AD group type

    Posted Apr 27, 2015 02:59 PM

    memberof  CONTAINS

     

    Learned that the hardway previously.



  • 4.  RE: AD group type

    EMPLOYEE
    Posted Apr 27, 2015 03:02 PM
    Can you try using Group instead? memberOf sometimes has issues with nested
    groups.



    You should be able to see the contents of Group in access tracker under
    authorization.


  • 5.  RE: AD group type

    Posted Apr 27, 2015 03:07 PM

    I tried "groups CONTAINS"

     

    This was added to the "Input" -> "Authorization Attributes" when I used groups but still not seeing "Employees" show up.

      

    Authorization:Active Directory:Groups:   Elementary, Elementary Teachers   



  • 6.  RE: AD group type

    EMPLOYEE
    Posted Apr 27, 2015 03:23 PM
    Remember when you are testing you must clear the cache if you make a change on the AD side. we only auth live each time but AD groups and etc are only pulled on the cache intervals.


  • 7.  RE: AD group type

    Posted Apr 28, 2015 07:29 AM

    Still not showing up in CPPM.  I'll work on getting upgraded to the latest CPPM release and see if it corrects the issue.



  • 8.  RE: AD group type

    Posted Aug 13, 2015 04:12 PM

    Did this ever get resolved?  I am seeing similar issues and have tried configuring for nested groups in several ways, but with no success.