Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM admin users local and from external source priority

This thread has been viewed 2 times
  • 1.  CPPM admin users local and from external source priority

    Posted Mar 06, 2013 02:32 PM

    when using admin users via the Administration > Users and Privileges > Admin Users section and from a changed service based on [Policy Manager Admin Network Login Service] where AD is a source does either of them have a priority. what if you have the same name in both sources?



  • 2.  RE: CPPM admin users local and from external source priority

    EMPLOYEE
    Posted Mar 06, 2013 02:35 PM

    It will search from the top down. So if the user is in both location it will use the auth from the first source. 



  • 3.  RE: CPPM admin users local and from external source priority

    Posted Mar 06, 2013 03:01 PM

    but the admin users, so i don't mean the local users, but specially the admin users isn't a source i use in any service.



  • 4.  RE: CPPM admin users local and from external source priority

    MVP
    Posted Mar 07, 2013 03:59 AM

    mm, it seems the admin user repository doesn't need to be included in any service but can be used nonetheless.

    Perhaps this is a security measure to not lock oneselves out completely?

     

    I've also noticed my successfull admin user repository logons do not get logged in the access tracker regardless of using the admin user rep in a service or not. Even if I use a service with both AD and admin user rep as sources failures against both only show the AD failure. 

     

    Is this intended behaviour?



  • 5.  RE: CPPM admin users local and from external source priority

    EMPLOYEE
    Posted Mar 07, 2013 05:59 AM

    You would see that under monitoring> event viewer.



  • 6.  RE: CPPM admin users local and from external source priority

    Posted Mar 08, 2013 03:39 PM

    @KoenV wrote:

    mm, it seems the admin user repository doesn't need to be included in any service but can be used nonetheless.

    Perhaps this is a security measure to not lock oneselves out completely?

     


    I assume the same, would be nice if Aruba could confirm this.