06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 12 <strong>User</strong> Databases<br />

PAP Procedure Output<br />

OL-14386-02<br />

ODBC Database (ACS <strong>for</strong> Windows Only)<br />

The stored procedure must return a single row that contains the nonnull fields.<br />

Table 12-2 lists the procedure results that ACS expects as output from stored procedure.<br />

Table 12-2 PAP Stored Procedure Results<br />

Field Type Explanation<br />

CSNTresult Integer See Table 12-7.<br />

CSNTgroup Integer The ACS group number <strong>for</strong> authorization. You use 0xFFFFFFFF to assign the default<br />

value. Values other than 0-499 are converted to the default.<br />

Note The group that is specified in the CSNTgroup field overrides group mapping that<br />

is configured <strong>for</strong> the ODBC external user database.<br />

CSNTacctInfo String 0-16 characters. A customer-defined string that ACS adds to subsequent account log file<br />

entries.<br />

CSNTerrorString String 0-255 characters. A customer-defined string that ACS writes to the CSAuth service log file<br />

if an error occurs.<br />

The CSNTGroup and CSNTacctInfo fields are processed only after a successful authentication. The<br />

CSNTerrorString file is logged only after a failure (if the result is greater than or equal to 4).<br />

Note If the ODBC database returns data in recordset <strong>for</strong>mat rather than in parameters, the procedure must<br />

return the result fields in the order previously listed.<br />

CHAP/MS-CHAP/ARAP Authentication Procedure Input<br />

ACS provides a single value <strong>for</strong> input to the stored procedure that supports CHAP/MS-CHAP/ARAP<br />

authentication. The stored procedure should accept the named input value as a variable.<br />

Note Because ACS per<strong>for</strong>ms authentication <strong>for</strong> CHAP/MS-CHAP/ARAP, the user password is not an input<br />

(Table 12-3).<br />

Table 12-3 CHAP Stored Procedure Input<br />

Field Type Explanation<br />

CSNTusername String 0-64 characters<br />

The input name is <strong>for</strong> guidance only. A procedure variable that is created from it can have a different<br />

name.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

12-41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!