Users Guide

NOTE:
For added security, it is strongly recommended that you change the default password of the root account during initial
setup.
When Certicate Validation is enabled, Fully Qualied Domain Name (FQDN) of the system should be provided. If
certicate validation is enabled and IP address is provided for the Domain Controller, then the login is not successful.
CMC does not support extended ASCII characters, such as ß, å, é, ü, or other characters used primarily in non-English languages.
You cannot log in to the Web interface with dierent user names in multiple browser windows on a single workstation.
NOTE: Multi Domain Conguration for CMC:
The schema must be extended in all the Sub Domains in the forest.
The user should be added to each domain and the CMC Device should be created in each Domain.
When conguring the extended schema for CMC, the domain being congured must be mentioned. For example, if the
root domain is fwad2.lab and user is cmcuser5@NodeA.GrandChildA.SubChildA.ChildA.fwad2.lab, then the domain
where the user is congured is NodeA.GrandChildA.SubChildA.ChildA.fwad2.lab. The user
cmcuser5@NodeA.GrandChildA.SubChildA.ChildA.fwad2.lab can be validated from CMC.
To log in as local user, Active Directory user, or LDAP user:
1. In the Username eld, type your user name:
CMC user name: <user name>
Active Directory user name: <domain>\<user name>, <domain>/<user name> or <user>@<domain>.
LDAP user name: <user name>
NOTE: "For Active Directory user, the Username is case sensitive.
2. In the Password eld, type the user password.
NOTE: This eld is case-sensitive.
3. In the Domain eld, from the drop-down menu, select the required domain.
4. Optionally, select a session timeout. This is the amount of time you can stay logged in with no activity before you are
automatically logged out. The default value is the Web Service Idle Timeout.
5. Click OK.
You are logged into CMC with the required user privileges.
NOTE: If LDAP authentication is enabled and you attempt logging into CMC using the local credentials, the credentials
are rst checked in the LDAP server and then in CMC.
NOTE: For LDAP authentication with OPEN-DS, the DH key must be larger than 768 bits.
Related link
Conguring User Accounts and Privileges
Accessing CMC Web Interface
Logging Into CMC Using Smart Card
You can log in to CMC using a smart card. Smart cards provide Two Factor Authentication (TFA) that provide two-layers of security:
Physical smart card device.
Secret code such as a password or PIN.
Users must verify their credentials using the smart card and the PIN.
NOTE: You cannot use the IP address to log in to CMC using Smart Card login. Kerberos validates your credentials based
on the Fully Qualied Domain Name (FQDN).
Before you log in as an Active Directory user using Smart Card, make sure to:
39