300-085 · Question #305
A Cisco Unity Connection System has users imported from the Cisco Unified Communications Manager, which in turn is integrated with LDAP. A user has reset the LDAP password and can authenticate with…
The correct answer is D. The Cisco Unity Connection administrator forgot to use the Synch Users page, which must be. When an LDAP password is reset, Cisco Unity Connection does not automatically reflect the change and requires a manual admin sync via the Synch Users page to update its cached credentials.
Question
A Cisco Unity Connection System has users imported from the Cisco Unified Communications Manager, which in turn is integrated with LDAP. A user has reset the LDAP password and can authenticate with the organization's other systems, but cannot authenticate with Cisco Unity Connection Web application despite using the same and correct username and password. Which cause of this issue is true?
Options
- AThe Cisco Unity Connection administrator did not use the Synch Users option.
- BThe user does not have the default web application authentication rile associated in Cisco
- CThe Cisco Unity Connection administrator changed the PIN in Cisco Unity Connection admin
- DThe Cisco Unity Connection administrator forgot to use the Synch Users page, which must be
- EThe user is locked out of Cisco Unity Connection due to too many incorrect tries.
How the community answered
(43 responses)- A7% (3)
- B2% (1)
- C21% (9)
- D60% (26)
- E9% (4)
Why each option
When an LDAP password is reset, Cisco Unity Connection does not automatically reflect the change and requires a manual admin sync via the Synch Users page to update its cached credentials.
While superficially similar to D, this choice lacks the critical detail that the Synch Users page is a mandatory step required specifically after LDAP password changes, making it an incomplete and less precise explanation.
Web application authentication rules govern which authentication method is used, but the issue here is that CUC has not yet received the updated LDAP password via sync - not that the user lacks the correct authentication rule.
The CUC PIN is used for telephone or voicemail access, not for web application login, so a PIN change by the administrator would not affect the user's ability to log into the CUC web application with LDAP credentials.
Cisco Unity Connection caches LDAP authentication credentials and does not poll for password changes in real time. After an LDAP password reset, an administrator must manually trigger synchronization using the Synch Users page to push the updated credentials into CUC, which is why the user can authenticate with other LDAP-integrated systems but not with the CUC web application.
An account lockout due to too many incorrect attempts is a separate condition from a stale password cache; the scenario specifies the user is entering the correct and current LDAP password, ruling out lockout as the cause.
Concept tested: Cisco Unity Connection LDAP password synchronization requirement
Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/15/ldap/b_15cucldap.html
Topics
Community Discussion
No community discussion yet for this question.