In CUCM 8.x, you can now use LDAP filters which work great. You can set the search base to be the top-level domain, then only allow the accounts that match what you define in the LDAP filter. Not sure on the number of search bases though.
Thanks, Kevin ________________________________ From: [email protected] [[email protected]] on behalf of Hough, Earl [[email protected]] Sent: Saturday, September 11, 2010 2:01 PM To: Randall Saborio Cc: [email protected]; Tam Nhu Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory Ah, I missed the part about them still being sync’d with LDAP, but just not visible to the Coporate Directory. Yeah, that’s an interesting problem. Hopefully one of these days they will expand on how the LDAP integration is done to make it a bit more user friendly. For an enterprise-class server, the integration is pretty much an all or nothing scenario. Not to mention, you can only have 5 different user search bases. So, if your AD structure includes more than five Active Directory dissimilar name spaces, you’re not going to be able to include them all. Or at least that’s been my experience with 7.0 and 7.1 I don’t know if they’ve increased that limitation with 8.0 or not. From: Randall Saborio [mailto:[email protected]] Sent: Saturday, September 11, 2010 2:54 PM To: Hough, Earl Cc: Tam Nhu; [email protected] Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory Earl, I believe your recommendations will work for excluding specific users to be synchronized with CUCM. You can do this in several ways using the AXL tool kit and knowing how LDAP attributes work, but in the end, the user is either included or excluded. The problem with Tam's requirement, is that he needs the users to be included and synched, however, just not show on the Corporate Directory search. I cannot think of a way to achieve this. Let us know how it goes about adding the special characters on LDAP. I tried adding the special characters but just locally without any LDAP synch, and the users would still show up on the Corporate Directory. On Sat, Sep 11, 2010 at 7:38 AM, Hough, Earl <[email protected]<mailto:[email protected]>> wrote: Just so I know we’re talking about the same thing, when you’re referring to DC Directory, you’re referring to the external LDAP integration with Active Dirctory, right? Not the internal UCM user directory. If so, that’s the same requirement I had where I had to alter the LDAP search string for the integration between AD and UCM so that instead of looking at the “account enabled” property, it looked for the “ip phone” field value. That would accomplish the same thing you’re trying to do, I believe. Thanks, Earl Hough CCIE #16508 (R/S,Security) From: Tam Nhu [mailto:[email protected]<mailto:[email protected]>] Sent: Saturday, September 11, 2010 9:30 AM To: Hough, Earl Cc: Daniel Berlinski; [email protected]<mailto:[email protected]> Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory Hi Earl, The reason for to hide these particular users in Corporate Directory is because they are UCCX Admin users that don't have DN and customer doesn't want to show up in CD. Is your solution work for the UCCX admin users that need to log into UCCX Admin page. Based on my test yesterday, if the account is 'Inactive', or 'disabled' in AD, then it cannot be used to login on the UCCX Admin page, or it won't show up in the search in UCCX user assignment. I might have to test more to see how it works. I will try Daniel's idea as well to put a special char in the First and Last name to see how it comes out. I don't see any more suggestions or workaround regarding hide UCCX admin user in DC Directory. It should have a way to do so, since this is very popular in the real world. Just keep finding and digging though, or might be Vik or Amy know the solution or workaround for this. Thanks, TN. _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ The information contained in this transmission is confidential. It is intended solely for the use of the individual(s) or organization(s) to whom it is addressed. Any disclosure, copying or further distribution is not permitted unless such privilege is explicitly granted in writing by PC Mall, Inc. Furthermore, PC Mall, Inc. is not responsible for the proper and complete transmission of the substance of this communication, nor for any delay in its receipt. _______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com<http://www.ipexpert.com> -- Randall "da ill" Saborio CCIE Voice Wannabe #10054675811 _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ The information contained in this transmission is confidential. It is intended solely for the use of the individual(s) or organization(s) to whom it is addressed. Any disclosure, copying or further distribution is not permitted unless such privilege is explicitly granted in writing by PC Mall, Inc. Furthermore, PC Mall, Inc. is not responsible for the proper and complete transmission of the substance of this communication, nor for any delay in its receipt. ________________________________ This communication (including any attachments) is intended only for the use of the individual or entity to which it is addressed, and may contain information that is privileged, confidential and exempt from disclosure under applicable law. If you are not the intended recipient, any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify Vital Support Systems at 515 334 5700 and delete or destroy all copies and the original document. _______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
