06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OL-14386-02<br />

Enabling Machine Authentication 12-15<br />

<strong>User</strong>-Changeable Passwords with Windows <strong>User</strong> Databases 12-16<br />

Preparing <strong>User</strong>s <strong>for</strong> Authenticating with Windows 12-17<br />

Selecting Remote Agents <strong>for</strong> Windows Authentication (Solution Engine Only) 12-17<br />

Windows <strong>User</strong> Database Configuration Options 12-18<br />

Configuring a Windows External <strong>User</strong> Database 12-21<br />

Machine Authentication Support in a Multi-Forest Environment 12-22<br />

Generic LDAP 12-23<br />

ACS Authentication Process with a Generic LDAP <strong>User</strong> Database 12-23<br />

Multiple LDAP Instances 12-24<br />

LDAP Organizational Units and Groups 12-24<br />

Domain Filtering 12-24<br />

LDAP Failover 12-25<br />

Successful Previous Authentication with the Primary LDAP <strong>Server</strong> 12-26<br />

Unsuccessful Previous Authentication with the Primary LDAP <strong>Server</strong> 12-26<br />

LDAP Admin Logon Connection Management 12-26<br />

Distinguished Name Caching 12-26<br />

LDAP Configuration Options 12-27<br />

Configuring a Generic LDAP External <strong>User</strong> Database 12-31<br />

ODBC Database (ACS <strong>for</strong> Windows Only) 12-35<br />

What is Supported with ODBC <strong>User</strong> Databases 12-36<br />

ACS Authentication Process with an ODBC External <strong>User</strong> Database 12-36<br />

Preparing to Authenticate <strong>User</strong>s with an ODBC-Compliant Relational Database 12-37<br />

Implementation of Stored Procedures <strong>for</strong> ODBC Authentication 12-38<br />

Type Definitions 12-38<br />

Microsoft SQL <strong>Server</strong> and Case-Sensitive Passwords 12-39<br />

Sample Routine <strong>for</strong> Generating a PAP Authentication SQL Procedure 12-39<br />

Sample Routine <strong>for</strong> Generating an SQL CHAP Authentication Procedure 12-40<br />

Sample Routine <strong>for</strong> Generating an EAP-TLS Authentication Procedure 12-40<br />

PAP Authentication Procedure Input 12-40<br />

PAP Procedure Output 12-41<br />

CHAP/MS-CHAP/ARAP Authentication Procedure Input 12-41<br />

CHAP/MS-CHAP/ARAP Procedure Output 12-42<br />

EAP-TLS Authentication Procedure Input 12-42<br />

EAP-TLS Procedure Output 12-43<br />

Result Codes 12-43<br />

Configuring a System Data Source Name <strong>for</strong> an ODBC External <strong>User</strong> Database 12-44<br />

Configuring an ODBC External <strong>User</strong> Database 12-44<br />

Downloading a Certificate Database (Solution Engine Only) 12-47<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Contents<br />

XVII

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!