<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic user group mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/38032#M27847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using PanOS 4.1.2 on 5020&lt;/P&gt;&lt;P&gt;listing group mapping:&lt;/P&gt;&lt;P&gt;show user group name "&amp;lt;DOMAIN&amp;gt;\&amp;lt;GROUP NAME&amp;gt;"&lt;/P&gt;&lt;P&gt;we get something like this&lt;/P&gt;&lt;P&gt;[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] &amp;lt;DOMAIN&amp;gt;\&amp;lt;name&amp;gt;.&amp;lt;surname&amp;gt;&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;though in "user id identification-&amp;gt;group mapping settings" under "user objects"&lt;/P&gt;&lt;P&gt;we discretely choose&lt;/P&gt;&lt;P&gt;"Object Class: person"&lt;/P&gt;&lt;P&gt;"User Name: sAMAccountName"&lt;/P&gt;&lt;P&gt;and browsing ldap shows that sAMAccountName holds no such information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this missmatches the info which is collected by user-id agent and prevents us using user identification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;furthermore if we delete "Domain" parameter in LDAP configuration (which is`t a production environment option, just for debug puposes, because we are in multi domain environment) listing users as mentioned above - we get same info as in "userPrincipalName" attribute:&lt;/P&gt;&lt;P&gt;show user group name "&amp;lt;DOMAIN&amp;gt;\&amp;lt;GROUP NAME&amp;gt;"&lt;/P&gt;&lt;P&gt;[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] &amp;lt;userPrincipalName value&amp;gt;&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this hardcoded(user name attribute - userPrincipalName)&amp;nbsp; bug? Or we can do something about it? Install previous version of panos/something using cli?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help, insights into this problem - appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Feb 2012 17:25:59 GMT</pubDate>
    <dc:creator>mpaskevic</dc:creator>
    <dc:date>2012-02-21T17:25:59Z</dc:date>
    <item>
      <title>user group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/38032#M27847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using PanOS 4.1.2 on 5020&lt;/P&gt;&lt;P&gt;listing group mapping:&lt;/P&gt;&lt;P&gt;show user group name "&amp;lt;DOMAIN&amp;gt;\&amp;lt;GROUP NAME&amp;gt;"&lt;/P&gt;&lt;P&gt;we get something like this&lt;/P&gt;&lt;P&gt;[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] &amp;lt;DOMAIN&amp;gt;\&amp;lt;name&amp;gt;.&amp;lt;surname&amp;gt;&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;though in "user id identification-&amp;gt;group mapping settings" under "user objects"&lt;/P&gt;&lt;P&gt;we discretely choose&lt;/P&gt;&lt;P&gt;"Object Class: person"&lt;/P&gt;&lt;P&gt;"User Name: sAMAccountName"&lt;/P&gt;&lt;P&gt;and browsing ldap shows that sAMAccountName holds no such information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this missmatches the info which is collected by user-id agent and prevents us using user identification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;furthermore if we delete "Domain" parameter in LDAP configuration (which is`t a production environment option, just for debug puposes, because we are in multi domain environment) listing users as mentioned above - we get same info as in "userPrincipalName" attribute:&lt;/P&gt;&lt;P&gt;show user group name "&amp;lt;DOMAIN&amp;gt;\&amp;lt;GROUP NAME&amp;gt;"&lt;/P&gt;&lt;P&gt;[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] &amp;lt;userPrincipalName value&amp;gt;&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this hardcoded(user name attribute - userPrincipalName)&amp;nbsp; bug? Or we can do something about it? Install previous version of panos/something using cli?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help, insights into this problem - appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 17:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/38032#M27847</guid>
      <dc:creator>mpaskevic</dc:creator>
      <dc:date>2012-02-21T17:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: user group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/38033#M27848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;4.1.3 version fixes this issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; mso-ansi-language: EN-US; font-family: Calibri; "&gt;"35907 - When a user account in Active Directory has a different value for the&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; mso-ansi-language: EN-US; font-family: Calibri; "&gt;userPrincipleName (UPN) name and the sAMAccountName, group mapping is not&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; mso-ansi-language: EN-US; font-family: Calibri; "&gt;working correctly because the user to IP mapping process uses the sAMAccountName and&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; mso-ansi-language: EN-US; font-family: Calibri; "&gt;user to group mapping process uses the UPN name. Update made so both processes use&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #1f497d; mso-ansi-language: EN-US; font-family: Calibri; "&gt;the sAMAccountName."&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 12:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/38033#M27848</guid>
      <dc:creator>mpaskevic</dc:creator>
      <dc:date>2012-02-22T12:06:51Z</dc:date>
    </item>
  </channel>
</rss>

