beautypg.com

External server authentication, In this chapter, Remote server authentication with netconf overview – Brocade Network OS NETCONF Operations Guide v4.1.1 User Manual

Page 229: Chapter 16, Chapter 16, “external server authentication, Chapter 16, “external server, Authentication

background image

Network OS NETCONF Operations Guide

197

53-1003231-02

Chapter

16

External Server Authentication

In this chapter

Remote server authentication with NETCONF overview . . . . . . . . . . . . . . . 197

Login authentication mode. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198

RADIUS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 202

TACACS+ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207

TACACS+ accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211

LDAP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215

Remote server authentication with NETCONF overview

This chapter provides procedures for configuring external AAA servers using the NETCONF
interface. Refer to the Network OS Administrator’s Guide for the following related information:

An overview of remote authentication server concepts, including the supported authentication
modes:

-

Terminal Access Controller Access Control System Plus (TACACS+)

-

Remote Authentication Dial In User Service (RADIUS)

-

Lightweight Directory Access Protocol (LDAP)

-

Local

Procedures for configuring remote authentication using the Network OS command line
interface (CLI)

Procedures for configuring server-side RADIUS

Through the NETCONF interface, you can perform the following operations on LDAP:

Use the RPC to connect to or disconnect from a authentication server, or
configure client-side TACACS+, RADIUS, or LDAP parameters.

Use the RPC to validate configuration settings.

Use the action located in the urn:mgmt:brocade.com:mgmt:brocade-certutil
namespace to import or delete an LDAP CA certificate.

Parameters for configure remote authentication are defined in the brocade-aaa YANG module.
Refer to the Network OS YANG Reference Manual for details.