- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
if I understand correctly, user-information fetch with the Web API from Clearpass should be resolved in an AD Account by AD Query. Also the User Groups would be looked up.
I think the problem lays in the fact that we use UPN (userPrincipalName) as the login on our networks.
If I lookup a user with:
pep s u q usr <username>
PDP: <127.0.0.1, 00000000>; UID: <915a1f11>
==================================================
Client ID : <<IP-address>, 00000000>
Authentication Key : <Unavailable>
Brute force counter: 0
Username : <username>@<suffix>
Machine name : <IP-address>
User groups : <Unavailable>
Machine groups : <Unavailable>
Compliance : <Unavailable>
Identity Role : <>
Time to live : 28830
Cached time : 86400
TTL counter : 57570
Time left : 18094
Last update time : Thu Oct 4 13:57:34 2018
pdp m u <username>
Session: 915a1f11
Session UUID: {<UUID>}
Ip: <IP-address>
Users:
<username>@<suffix>@<domainname> {2b604b71}
Groups: -
Roles: -
Client Type: Identity Awareness API (Aruba ClearPass Policy Manager)
Authentication Method: Trust
Distinguished Name:
Connect Time: Thu Oct 4 13:57:34 2018
Next Reauthentication: Thu Oct 4 22:06:31 2018
Next Connectivity Check: -
Next Ldap Fetch: -
Packet Tagging Status: Not Active
Published Gateways: Local
************************************************************************************
I can see that it is working, but the User Groups aren't fetched.
On the Clearpass side, i set:
"calculate-roles":1,"fetch-user-groups":0,"fetch-machine-groups":0
(as documented by Aruba/HPE)
I read a lot of documentation and think if AD Query is working (it is) and the Web API is giving results, the correlation should be done.
Could it have to do something with the Domain-field in the LDAP Account Unit?
Thanks for any advice and kind regards,
Peter Kruppa
PS We're running R80.20
Yes but it's a pretty easy fix.
See: Changing LDAP lookup type for authentication in Identity Agent
Yes but it's a pretty easy fix.
See: Changing LDAP lookup type for authentication in Identity Agent
Hi Dameon,
thanks for the fast response.
I already found that article but it is for versions: R75.40, R75.45, R75.46, R75.47, R76, R77, R77.10, R77.20, R77.30
We are running R80.20...
Kind regards,
Peter
As far as I know, it should still be relevant for R80.20 as well.
Thanks Dameon, you were indeed right and it did the trick.
I didn't have access to the content and assumed it was a hotfix.
Next time I will check beforehand 🙂
Kind regards
Daemon,
any idea if changing the setting to UPN will affect any other portions of identity awareness or does this only affect how the identity API interacts? If we are using AD query, radius, and portal will this also change these to UPN?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY