cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
779
Views
5
Helpful
2
Replies

LMS 2.6 Login issue

sirbaughmf
Level 1
Level 1

I have a user that is able to login to LMS via TACACS/SecurID without a CW local login account, he gets guest privs, is this a bug, shouldn't he be unable to log in without a local account set up?

1 Accepted Solution

Accepted Solutions

Joe Clarke
Cisco Employee
Cisco Employee

Miheg is absolutely right. This has been the case since we introduced external login modules. Every user with a valid account in the external database will be allowed Help Desk access to LMS unless they have a local account in LMS granting them more access.

I used to have a patch for LMS 2.2 which worked around this. However, in LMS 2.5+ you have the option of using ACS integration. If you do full ACS integration, you can effectively prevent people with ACS accounts from having any access in LMS.

View solution in original post

2 Replies 2

miheg
Level 5
Level 5

No, that is the intended behavior.

Guest or helpdesk level is what he gets.

Cheers,

Michel

Joe Clarke
Cisco Employee
Cisco Employee

Miheg is absolutely right. This has been the case since we introduced external login modules. Every user with a valid account in the external database will be allowed Help Desk access to LMS unless they have a local account in LMS granting them more access.

I used to have a patch for LMS 2.2 which worked around this. However, in LMS 2.5+ you have the option of using ACS integration. If you do full ACS integration, you can effectively prevent people with ACS accounts from having any access in LMS.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: