(RADIATOR) <AuthBy ACE> and Windows groups

Kawakubo, Ken kkawakub at fhcrc.org
Mon Feb 14 13:54:47 CST 2005


Mike,

It worked as you suggested. Thank you.

Ken

-----Original Message-----
From: Mike McCauley [mailto:mikem at open.com.au] 
Sent: Friday, February 11, 2005 6:42 PM
To: Kawakubo, Ken
Cc: radiator at open.com.au
Subject: Re: (RADIATOR) <AuthBy ACE> and Windows groups


Hello Ken,


On Saturday 12 February 2005 03:21, Kawakubo, Ken wrote:
> All,
>
> I am evaluating RSA SecurID. I am starting with 
> authentication/authorization for access to Cisco switches and routers 
> using SecurID. Currently, we are using <AuthBy LSA> with Windows group 
> to give either privilege 15 or 1 depending on group membership. I 
> would like to replicate the same with <AuthBy ACE>. But I found that 
> <AuthBy ACE> does not support Windows groups. Is there any way to use 
> Windows groups to interact with <AuthBy ACE>?

I havent tried this, but you could chain AuthBy NT with your AuthBy ACE, and

set up the AuthBy NT to use groups but with NoCheckPassword.

Cheers.

>
> Ken Kawakubo
> FHCRC
>
> --
> Archive at http://www.open.com.au/archives/radiator/
> Announcements on radiator-announce at open.com.au
> To unsubscribe, email 'majordomo at open.com.au' with 'unsubscribe 
> radiator' in the body of the message.

-- 
Mike McCauley                               mikem at open.com.au
Open System Consultants Pty. Ltd            Unix, Perl, Motif, C++, WWW
9 Bulbul Place Currumbin Waters QLD 4223 Australia   http://www.open.com.au
Phone +61 7 5598-7474                       Fax   +61 7 5598-7070

Radiator: the most portable, flexible and configurable RADIUS server 
anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald, 
Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS, 
TTLS, PEAP etc on Unix, Windows, MacOS etc.

--
Archive at http://www.open.com.au/archives/radiator/
Announcements on radiator-announce at open.com.au
To unsubscribe, email 'majordomo at open.com.au' with
'unsubscribe radiator' in the body of the message.


More information about the radiator mailing list