Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

How can I use generic LDAP as an authorization source in ClearPass?

This thread has been viewed 2 times
  • 1.  How can I use generic LDAP as an authorization source in ClearPass?

    Posted Apr 05, 2016 11:50 AM

    Hi everyone. I am trying to do a role mapping in ClearPass based on a custom attribute defined in a generic LDAP server. I have added the server as an authentication source with type Generic LDAP and have checked the box to fetch attributes for role mapping. I have also added attributes to the source to pull the info I need for the user. The filter queries are working fine (I think), but when I see an authentication come through, there are no authorization attributes coming from the LDAP server (see screenshots below). Can someone point me in the right direction to get the authorization working on a Generic LDAP server? Thanks.



  • 2.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    EMPLOYEE
    Posted Apr 05, 2016 12:02 PM

    Add it as an authorization source to your service instead of an authentication source.



  • 3.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    Posted Apr 05, 2016 12:09 PM

    Thanks, Tim. I have it as an authentication source and an authorization source. See screenshot.SecureService-AuthorizationSources.jpg



  • 4.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    EMPLOYEE
    Posted Apr 05, 2016 12:12 PM

    Remove it from your authentication list. In access tracker, you'll see it's hitting that source instead of AD.



  • 5.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    Posted Apr 05, 2016 12:20 PM

    Still no love. And now the user authentication fails as well since the user account lives only in that generic LDAP database.



  • 6.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    EMPLOYEE
    Posted Apr 05, 2016 12:28 PM

    Oh sorry. Misread. I thought you were only using LDAP for authorization.

     

    In access tracker, I see "Adjunct". Is that coming from the MajorAffiliation attribute?



  • 7.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    Posted Apr 05, 2016 12:33 PM

    This is my role mapping. Currently, faculty and staff live in AD-2012 and students live in IDM. The idea is to apply the role based on the authentication source and the custom attribute called ***majoraffiliation. I have a catchall for IDM mapping the user to the Adjunct role just so I can do CoAs as I test changes.



  • 8.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    Posted Apr 05, 2016 12:34 PM

    SecureService-RoleMapping.jpg



  • 9.  RE: How can I use generic LDAP as an authorization source in ClearPass?

    Posted May 25, 2016 07:27 AM

    when you have it for authentication and authorization again. have you double checked all spelling and caps? do other attributes show up?