Cisco 2509 - Router - EN User Manual page 48

User guide
Hide thumbs Also See for 2509 - Router - EN:
Table of Contents

Advertisement

AAA Server Functions and Concepts
Password Aging
User Guide for Cisco Secure ACS for Windows Server
1-14
(for example, Fredpassword) while the password value contains an
ASCII/PAP/ARAP password. The TACACS+ and RADIUS servers then
verify that the token is still cached and validate the incoming password
against either the single ASCII/PAP/ARAP or separate CHAP/ARAP
password, depending on the configuration the user employs.
The TACACS+ SENDAUTH feature enables a AAA client to authenticate
itself to another AAA client or an end-user client via outbound
authentication. The outbound authentication can be PAP, CHAP, or ARAP.
With outbound authentication, the Cisco Secure ACS password is given out.
By default, ASCII/PAP or CHAP/ARAP password is used, depending on how
this has been configured; however, we recommend that the separate
SENDAUTH password be configured for the user so that Cisco Secure ACS
inbound passwords are never compromised.
If you want to use outbound passwords and maintain the highest level of security,
we recommend that you configure users in the CiscoSecure user database with an
outbound password that is different from the inbound password.
With Cisco Secure ACS you can choose whether and how you want to employ
password aging. Control for password aging may reside either in the CiscoSecure
user database, or in a Windows NT/2000 user database. Each password aging
mechanism differs as to requirements and setting configurations.
The password aging feature controlled by the CiscoSecure user database enables
you force users to change their passwords under any of the following conditions:
After a specified number of days.
After a specified number of logins.
The first time a new user logs in.
For information on the requirements and configuration of the password aging
feature controlled by the CiscoSecure user database, see
Aging for the CiscoSecure User Database, page
The Windows NT/2000-based password aging feature enables you to control the
following password aging parameters:
Maximum password age in days.
Minimum password age in days.
Chapter 1
Overview of Cisco Secure ACS
Enabling Password
6-20.
78-14696-01, Version 3.1

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure acs

Table of Contents