06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Token <strong>Server</strong> <strong>User</strong> Databases<br />

12-54<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Chapter 12 <strong>User</strong> Databases<br />

Note You should only click the From Token <strong>Server</strong> (async tokens only) option if all tokens that are<br />

submitted to this token server are asynchronous tokens.<br />

Step 9 Click Submit.<br />

ACS saves the RADIUS token server database configuration that you created. You can add it to your<br />

Unknown <strong>User</strong> Policy or assign specific user accounts to use this database <strong>for</strong> authentication. For more<br />

in<strong>for</strong>mation about the Unknown <strong>User</strong> Policy, see About Unknown <strong>User</strong> Authentication, page 15-3. For<br />

more in<strong>for</strong>mation about configuring user accounts to authenticate by using this database, see Chapter 6,<br />

“<strong>User</strong> Management.”<br />

Using RSA Token-Card Client Software<br />

ACS supports mapping users who are authenticated by a RSA token server to a single group. For more<br />

in<strong>for</strong>mation, see Group Mapping by External <strong>User</strong> Database, page 16-1.<br />

ACS supports PPP (ISDN and async) and Telnet <strong>for</strong> RSA SecurID token servers by acting as a token-card<br />

client to the RSA SecurID token server. To use this client you must install the RSA token-card client<br />

software on the computer that is running ACS. The following procedure includes the steps that you<br />

follow to install the RSA client correctly on the computer that is running ACS.<br />

ACS supports the RSA SecurID token server custom interface <strong>for</strong> authentication of users. You can create<br />

only one RSA SecurID configuration within ACS.<br />

ACS <strong>for</strong> Windows<br />

Be<strong>for</strong>e You Begin<br />

You should install and configure your RSA SecurID token server be<strong>for</strong>e configuring ACS to authenticate<br />

users with it. For in<strong>for</strong>mation about installing the RSA SecurID server, refer to the documentation <strong>for</strong><br />

your token server.<br />

Ensure that you have the applicable RSA ACE Client.<br />

To configure ACS to authenticate users with an RSA token server:<br />

Step 1 Install the RSA client on the computer that is running ACS:<br />

a. With a username that has administrative privileges, log in to the computer that is running ACS.<br />

b. Run the Setup program of the ACE Client software, following the setup instructions that RSA<br />

provides.<br />

Note Do not restart Windows when installation is complete.<br />

c. Locate the ACE <strong>Server</strong> data directory, <strong>for</strong> example, /sdi/ace/data.<br />

d. Get the file named sdconf.rec and place it in the following Windows directory:<br />

%SystemRoot%\system32.<br />

For example:<br />

\winnt\system32<br />

e. Ensure that the ACE server hostname is in the Windows local host file:<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!