5
The authentication model using RADIUS and LDAP
syntax error in the attributes, the password expiration warning will not be issued. If your RADIUS
server maintains its own password expiration attributes, you must set the exact date twice to use
this feature, once on your RADIUS server and once in the VSA attribute. If the dates do not match,
then the RADIUS server authentication fails.
The syntax used for assigning VSA-based account switch roles on a RADIUS server is described in
Table
TABLE 16
Item
Type
Length
Vendor ID
Vendor type
Vendor length
Attribute-specific data
Fabric OS users on the RADIUS server
All existing Fabric OS mechanisms for managing local switch user accounts and passwords remain
functional when the switch is configured to use RADIUS. Changes made to the local switch
database do not propagate to the RADIUS server, nor do the changes affect any account on the
RADIUS server.
Windows 2000 IAS
To configure a Windows 2000 internet authentication service (IAS) server to use VSA to pass the
Admin role to the switch in the dial-in profile, the configuration specifies the Vendor code (1588),
Vendor-assigned attribute number (1), and attribute value (admin), as shown in
100
16.
Syntax for VSA-based account roles
Value
26
7 or higher
1588
1
2
3
4
5
6
7
2 or higher
ASCII string
Description
1 octet
1 octet, calculated by the server
4 octet, Brocade SMI Private Enterprise Code
1 octet, Brocade-Auth-Role; valid attributes for the Brocade-Auth-Role are:
Admin
BasicSwitchAdmin
FabricAdmin
Operator
SecurityAdmin
SwitchAdmin
User
ZoneAdmin
Optional: Specifies the Admin Domain or Virtual Fabric member list. For
more information on Admin Domains or Virtual Fabrics, see
configuration with Admin Domains or Virtual Fabrics"
Brocade-AVPairs1
Brocade-AVPairs2
Brocade-AVPairs3
Brocade-AVPairs4
Brocade Password ExpiryDate
Brocade Password ExpiryWarning
1 octet, calculated by server, including vendor-type and vendor-length
Multiple octet, maximum 253, indicating the name of the assigned role and
other supported attribute values such as Admin Domain member list.
"RADIUS
on page 102.
Figure
10.
Fabric OS Administrator's Guide
53-1002446-01