User's Manual

282 Using the CMC Directory Service
(Ctrl-Alt-Del) screen and check to see if Windows detects the Smart Card
and displays the PIN dialog-box.
Incorrect Smart Card PIN
Check to see if the Smart Card has been locked out due to too many
attempts with an incorrect PIN. In such cases, the issuer of the Smart Card
in the organization is able to help you get a new Smart Card.
Unable to Log into CMC as an Active Directory User
If you cannot log into CMC as an Active Directory user, try logging into
CMC without enabling the Smart Card logon. You also have the option of
disabling the Smart Card Logon through the local RACADM using the
following commands:
racadm config -g cfgActiveDirectory -o cfgADSCLEnable 0
racadm config -g cfgActiveDirectory -o cfgADSSOEnable 0
Using CMC with Generic LDAP
A CMC administrator can now integrate the LDAP server user logins with
CMC. This integration requires configuration on both LDAP server and
CMC. On the LDAP server, a standard group object is used as a role group. A
user who has CMC access becomes a member of the role group.Privileges are
still stored on CMC for authorization similar to the working of the Standard
Schema setup with Active Directory support.
To enable the LDAP user to access a specific CMC card, the role group name
and its domain name must be configured on the specific CMC card. You can
configure a maximum of five role groups in each CMC. Table 5-41shows the
privileges level of the role groups and Table 8-1 shows the default role group
settings.