Cisco TelePresence Administrator's Manual page 119

Video communication server
Hide thumbs Also See for TelePresence:
Table of Contents

Advertisement

Field
Description
Secure
Indicates if data transmitted from the VCS
channel
to an AD Domain Controller is sent over a
mode
secure channel.
Auto: automatically adapts to the domain
controller's settings.
Enabled: always attempts to use a secure
channel.
Disabled: does not use a secure channel.
The default is Auto.
Encryption
Sets the encryption to use for the LDAP
connection to the Active Directory Service.
Off: no encryption is used.
TLS: TLS encryption is used.
The default is TLS.
Clockskew
The maximum allowed clockskew (in
seconds) between the VCS and the KDC
before the Kerberos message is assumed
to be invalid. The default is 300 seconds.
Domain
This section is used to define the Domain
Controller
Controllers that can used by the VCS
addresses
when it joins the AD domain.
You can choose to either:
use a DNS SRV lookup of the AD
n
domain to obtain the Domain Controller
addresses
manually enter the IP addresses of up to
n
5 Domain Controllers
Kerberos
This section is used to define the Kerberos
Key
Key Distribution Centers (KDCs) that can
Distribution
be used when connected to the AD
Center
domain.
addresses
You can choose to either:
and ports
use a DNS SRV lookup of the AD
n
domain to obtain the KDC addresses
manually enter the IP addresses and
n
port numbers of up to 5 KDCs
Port numbers default to 88.
Cisco VCS Administrator Guide (X7.2)
Usage tips
You are recommended to use Auto.
If encryption is set to TLS, a valid CA certificate,
private key and server certificate must be uploaded to
the VCS.
Click
Upload a CA certificate file for TLS
Related tasks section) to go to the
certificate
page.
It should be kept in step with the clock skew setting on
the KDC; generally this will be its default value of 300
(5 minutes).
You are recommended to use the default behavior of
using a DNS SRV lookup.
You are recommended to use the default behavior of
using a DNS SRV lookup. Typically, the KDC
addresses will be the same as the Domain Controller
addresses.
Device authentication
(in the
Trusted CA
Page 119 of 498

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Telepresence x7.2

Table of Contents