Help! LDAP on ACS 1120 appliance

Unanswered Question
Aug 2nd, 2010
User Badges:

Hi all,

I configured LDAP on acs 1120 appliance,but i don't know how to fill parameter on ldap configuration:

Subject ObjectClass

Subject Name Attribute

Certificate Attribute

Group ObjectClass

Group map attribute

Subject search base

Group search base

My domain name is

Mapping group on AD server is internetAccess

Help me, please


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
lomonaco Tue, 08/03/2010 - 05:00
User Badges:

Hi Pham,

If you are using Active Directory, I suggest you use the free tool LDP.EXE (Support Tools or Resource Kit) to find more information about your


Any way, try the following options:

Subject Search Base DC= hph, DC=tct, DC=vn

Group Search Base   DC= hph, DC=tct, DC=vn

Subject ObjectClass user

Subject Name Attribute sAMAccountName

Group Objectclass group

Group Map Attribute member

Group Objects Contain References to Subjects distinguished name

Obs. Is better to restrict the ACS where will look for subjects or groups, but you didn't in your message where the users/groups that will be used in ACS are....

My Best Regards,

Andre Lomonaco

phamthanhchuong Tue, 08/03/2010 - 20:41
User Badges:

Hi lomonaco,

The group that will be used in ACS is NguoiDungThue

The group that will be used in Active Directory server is InternetAccess
And i don't know how to mapping 2 groups

Thanks for your help,

Best Regards


This Discussion