Chapter 11 Working with User Databases
Generic LDAP
11-30
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
d.
If you want Cisco Secure ACS to remove the domain qualifier before
submitting it to the LDAP database, select the Strip domain before
submitting username to LDAP server check box.
e.
If you want Cisco Secure ACS to pass the username to the LDAP database
without removing the domain qualifier, clear the Strip domain before
submitting username to LDAP server check box.
Step 9
If you want to enable Cisco Secure ACS to strip domain qualifiers from
usernames before submitting them to an LDAP server, follow these steps:
Note
For information about domain filtering, see
Domain Filtering,
page 11-18
.
a.
Under Domain Filtering, select Process all usernames after stripping
domain name and delimiter.
b.
If you want Cisco Secure ACS to strip prefixed domain qualifiers, select the
Strip starting characters through the last X character check box, and then
type the domain-qualifier delimiting character in the X box.
Note
The X box cannot contain the following special characters:
# ? " * > <
If any of these characters are in the X box, stripping fails.
c.
If you want Cisco Secure ACS to strip suffixed domain qualifiers, select the
Strip ending characters from the first X character check box, and then
type the domain-qualifier delimiting character in the X box.
Note
The X box cannot contain the following special characters:
# ? " * > <
If any of these characters are in the X box, stripping fails.
Step 10
Under Common LDAP Configuration, in the User Directory Subtree box, type the
DN of the tree containing all your users.
Step 11
In the Group Directory Subtree box, type the DN of the subtree containing all your
groups.