In CUCM 8.x, you can now use LDAP filters which work great.  You can set the 
search base to be the top-level domain, then only allow the accounts that match 
what you define in the LDAP filter.  Not sure on the number of search bases 
though.

Thanks,
Kevin
________________________________
From: [email protected] 
[[email protected]] on behalf of Hough, Earl 
[[email protected]]
Sent: Saturday, September 11, 2010 2:01 PM
To: Randall Saborio
Cc: [email protected]; Tam Nhu
Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory

Ah, I missed the part about them still being sync’d with LDAP, but just not 
visible to the Coporate Directory.

Yeah, that’s an interesting problem.  Hopefully one of these days they will 
expand on how the LDAP integration is done to make it a bit more user friendly. 
 For an enterprise-class server, the integration is pretty much an all or 
nothing scenario.  Not to mention, you can only have 5 different user search 
bases.  So, if your AD structure includes more than five Active Directory 
dissimilar name spaces, you’re not going to be able to include them all.  Or at 
least that’s been my experience with 7.0 and 7.1  I don’t know if they’ve 
increased that limitation with 8.0 or not.


From: Randall Saborio [mailto:[email protected]]
Sent: Saturday, September 11, 2010 2:54 PM
To: Hough, Earl
Cc: Tam Nhu; [email protected]
Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory

Earl, I believe your recommendations will work for excluding specific users to 
be synchronized with CUCM.

You can do this in several ways using the AXL tool kit and knowing how LDAP 
attributes work, but in the end, the user is either included or excluded.

The problem with Tam's requirement, is that he needs the users to be included 
and synched, however, just not show on the Corporate Directory search.

I cannot think of a way to achieve this. Let us know how it goes about adding 
the special characters on LDAP.
I tried adding the special characters but just locally without any LDAP synch, 
and the users would still show up on the Corporate Directory.
On Sat, Sep 11, 2010 at 7:38 AM, Hough, Earl 
<[email protected]<mailto:[email protected]>> wrote:
Just so I know we’re talking about the same thing, when you’re referring to DC 
Directory, you’re referring to the external LDAP integration with Active 
Dirctory, right?  Not the internal UCM user directory.

If so, that’s the same requirement I had where I had to alter the LDAP search 
string for the integration between AD and UCM so that instead of looking at the 
“account enabled” property, it looked for the “ip phone” field value.  That 
would accomplish the same thing you’re trying to do, I believe.

Thanks,
Earl Hough
CCIE #16508 (R/S,Security)

From: Tam Nhu [mailto:[email protected]<mailto:[email protected]>]
Sent: Saturday, September 11, 2010 9:30 AM
To: Hough, Earl
Cc: Daniel Berlinski; 
[email protected]<mailto:[email protected]>

Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory

Hi Earl,


The reason for to hide these particular users in Corporate Directory is because 
they are UCCX Admin users that don't have DN and customer doesn't want to show 
up in CD.  Is your solution work for the UCCX admin users that need to log into 
UCCX Admin page.  Based on my test yesterday, if the account is 'Inactive', or 
'disabled' in AD, then it cannot be used to login on the UCCX Admin page, or it 
won't show up in the search in UCCX user assignment.  I might have to test more 
to see how it works.

I will try Daniel's idea as well to put a special char in the First and Last 
name to see how it comes out.

I don't see any more suggestions or workaround regarding hide UCCX admin user 
in DC Directory.  It should have a way to do so, since this is very popular in 
the real world.

Just keep finding and digging though, or might be Vik or Amy know the solution 
or workaround for this.

Thanks,
TN.

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



The information contained in this transmission is confidential. It is

intended solely for the use of the individual(s) or organization(s) to

whom it is addressed. Any disclosure, copying or further distribution is

not permitted unless such privilege is explicitly granted in writing by

PC Mall, Inc. Furthermore, PC Mall, Inc. is not responsible for

the proper and complete transmission of the substance of this

communication, nor for any delay in its receipt.



_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com<http://www.ipexpert.com>



--
Randall "da ill" Saborio
CCIE Voice Wannabe #10054675811

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

The information contained in this transmission is confidential. It is
intended solely for the use of the individual(s) or organization(s) to
whom it is addressed. Any disclosure, copying or further distribution is
not permitted unless such privilege is explicitly granted in writing by
PC Mall, Inc. Furthermore, PC Mall, Inc. is not responsible for
the proper and complete transmission of the substance of this
communication, nor for any delay in its receipt.



________________________________

This communication (including any attachments) is intended only for the use of 
the individual or entity to which it is addressed, and may contain information 
that is privileged, confidential and exempt from disclosure under applicable 
law. If you are not the intended recipient, any dissemination, distribution or 
copying of this communication is strictly prohibited. If you have received this 
communication in error, please notify Vital Support Systems at 515 334 5700 and 
delete or destroy all copies and the original document.
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to