06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9 System Configuration: Authentication and Certificates<br />

OL-14386-02<br />

EAP-FAST PAC Files Generation (ACS SE)<br />

Step 5 You can now install the replacement certificate in the same manner as an original certificate. For detailed<br />

steps, see Installing an ACS <strong>Server</strong> Certificate, page 9-22.<br />

EAP-FAST PAC Files Generation (ACS SE)<br />

You can use the EAP-FAST PAC Files Generation page to create PAC files <strong>for</strong> manual PAC provisioning.<br />

For more in<strong>for</strong>mation about PACs, see EAP-FAST Authentication, page 9-9.<br />

This section contains:<br />

PAC File Generation Options, page 9-37<br />

Generating PAC Files, page 9-39<br />

PAC File Generation Options<br />

When generating PAC files, you can use:<br />

Specific user—ACS generates a PAC file <strong>for</strong> the username typed in the <strong>User</strong> Name box. For<br />

example, if you checked this option and typed seaniemop in the <strong>User</strong> Name box, ACS generates a<br />

single PAC file, named seaniemop.pac.<br />

Tip You can also specify a domain-qualified username, using the <strong>for</strong>mat DOMAIN\username. For example,<br />

if you specify ENIGINEERING\augustin, ACS generates a PAC filename ENGINEERING_augustin.pac.<br />

<strong>User</strong>s from specific ACS group—ACS generates a PAC file <strong>for</strong> each user in the user group<br />

specified by the ACS Group list. ACS has 500 groups, numbered from 0 (zero) to 499. For example,<br />

assume that Group 7 has 43 users. If you selected this option and chose Group 7 from the ACS<br />

Group list, ACS would generate 43 PAC files, one <strong>for</strong> each user who is a member of Group 7. Each<br />

PAC file is named in the following <strong>for</strong>mat:<br />

where username.pac is the name of the particular user.<br />

Note Generating PAC files <strong>for</strong> users in a specific group restarts the CSAuth service. No users are<br />

authenticated while CSAuth is unavailable.<br />

Tip To generate PAC files <strong>for</strong> more than one group of users, generate PAC files <strong>for</strong> each group separately.<br />

For example, to generate PAC files <strong>for</strong> users in Groups 7 through 10, generate PAC files four times, once<br />

each <strong>for</strong> Groups 7, 8, 9, and 10.<br />

All users in ACS internal DB—ACS generates a PAC file <strong>for</strong> each user in the ACS internal<br />

database. For example, if you have 3278 users in the ACS internal database and check this option,<br />

ACS would generate 3278 PAC files, one <strong>for</strong> each user. Each PAC file is named in the following<br />

<strong>for</strong>mat:<br />

username.pac<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

9-37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!