Tacacs+ Authentication; Enabling/Disabling Tacacs - Safran SecureSync 2400 User Manual

Hide thumbs Also See for SecureSync 2400:
Table of Contents

Advertisement

4.3  Managing Users and Security
4.3.6

TACACS+ Authentication

Terminal Access Controller Access-Control System Plus (TACACS+) is a protocol
that handles authentication, authorization, and accounting (AAA) services.
SecureSync supports pam_ tacplus, allowing users to validate their user-
name/password when logging into SecureSync via a TACACS+ server. Currently,
http/https/ssh/telnet/ftp protocols are supported, i.e. you can login to a
SecureSync unit using TACACS+ authentication via applications using any of
these protocols.
E x a m p l e :
A user with the username
SecureSync unit, if on that unit a local user account with the username
However, once the user deleted the local
the TACACS+
Sources of general reference information on TACACS+:
See also
4.3.6.1

Enabling/Disabling TACACS+

To enable or disable the use of TACACS+ authentication on a SecureSync unit:
294
Note:
Your TACACS+ files will need to have either a pap or global
user attribute. SecureSync does not authenticate tacacs.conf files
with the default login user attribute.
Caution:
In order to utilize TACACS+ authentication, the account
username on the TACACS+ server must NOT be used with a local
user account.
user3
user3
account.
https://en.wikipedia.org/wiki/TACACS
http://www.cisco.com/c/en/us/support/docs/security-vpn/remote-
authentication-dial-user-service-radius/13838-10.html
https://github.com/jeroennijhof/pam_tacplus
"RADIUS Authentication" on page 290
on the TACACS+ server will not be able to login to a
user3
account, she will be able to login with
CHAPTER
4
user3
exists.
SecureSync 2400 User Manual Rev. 5.2

Advertisement

Table of Contents
loading

Table of Contents