Active Directory Service (Ads) Configuration - Cisco TelePresence Administrator's Manual

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

5. The VCS challenges the request from Movi and Movi responds to the challenge.
6. The VCS sends the challenge and response received from the Movi endpoint to the AD Domain Controller
which then responds with an authentication good/no-good message.
7. The VCS uses the response from the AD Domain Controller to either allow or deny the registration
request.
Note that the VCS embeds NTLMv2 authentication protocol messages within standard SIP messages when
communicating with Movi, and uses a secure RPC channel when communicating with the AD Domain
Controller. Users' Windows domain credentials and the AD domain administrator credentials are not stored
on the VCS.
More information about how to configure your system to use NTLM and Active Directory Service is contained
in
Authenticating devices deployment

Active Directory Service (ADS) configuration

The
Active Directory Service
Service) is used to configure a connection to an
endpoints (Movi version 4.2 or later).
The configurable options are:
Field
Description
Connect to
Enables or disables the VCS's
Active
connection to the Active Directory
Directory
Service.
Service
AD domain
This must be the fully qualified domain
name (FQDN) of the AD domain that
the VCS will join.
Short
The short domain name used by the
domain
VCS when it joins the AD domain.
name
Secure
Indicates if data transmitted from the
channel
VCS to an AD Domain Controller is
mode
sent over a secure channel.
Auto: automatically adapts to the
domain controller's settings.
Enabled: always attempts to use a
secure channel.
Disabled: does not use a secure
channel.
The default is Auto.
Cisco VCS Administrator Guide (X7.1)
guide.
page
(VCS configuration > Authentication > Devices > Active Directory
Active Directory Service
Usage tips
When the connection is enabled, the VCS will include
NTLM protocol challenges when authenticating
endpoints, according to the
setting.
Turning Connect to Active Directory Service to Off
does not cause the VCS to leave the AD domain.
Case sensitivity issues with Active Directory have been
reported and therefore upper case entry is enforced.
Typically the domain would be the same as the DNS
name of the Kerberos server.
It is also known as the NetBIOS domain name.
You are recommended to use Auto.
Device authentication
for device authentication of Movi
NTLM protocol challenges
Page 109 of 479

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x7.1

Table of Contents