06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>User</strong> and AAA Client Import Option<br />

Table C-3 ADD Statement Tokens<br />

UPDATE Statements<br />

C-12<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Appendix C CSUtil Database Utility<br />

Token Required<br />

Value<br />

Required Description<br />

ADD Yes username Add user in<strong>for</strong>mation to ACS. If the username already exists, no in<strong>for</strong>mation is<br />

changed.<br />

PROFILE No group<br />

number<br />

CHAP No CHAP<br />

password<br />

Group number to which the user is assigned. This must be a number from 0 to<br />

499, not a name. If you do not use the PROFILE token or fail to provide a group<br />

number, the user is added to the default group.<br />

Require a Challenge Authentication Handshake Protocol (CHAP) password <strong>for</strong><br />

authentication.<br />

CSDB No password Authenticate the username with the ACS internal database.<br />

CSDB_UNIX No UNIXencrypted<br />

password<br />

Authenticate the username with the ACS internal database, using a UNIX<br />

password <strong>for</strong>mat.<br />

EXT_NT No — Authenticate the username with a Windows external user database.<br />

EXT_SDI No — Authenticate the username with an RSA external user database.<br />

EXT_ODBC No — Authenticate the username with an Open Database Connectivity (ODBC) external<br />

user database.<br />

EXT_LDAP No — Authenticate the username with a generic Lightweight Directory <strong>Access</strong> Protocol<br />

(LDAP) external user database.<br />

EXT_LEAP No — Authenticate the username with a Lightweight and Efficient Application Protocol<br />

(LEAP) proxy Remote <strong>Access</strong> Dial-In <strong>User</strong> Service (RADIUS) server external<br />

user database.<br />

EXT_RADIUS No — Authenticate the username with a RADIUS token server external user database.<br />

For example, the following ADD statement would create an account with the username John, assign it<br />

to Group 3, and specify that John should be authenticated by the ACS internal database with the<br />

password closedmondays:<br />

ADD:John:PROFILE:3:CSDB:closedmondays<br />

UPDATE statements are optional. They make changes to existing user accounts. Only the UPDATE<br />

token and its value are required by CSUtil.exe, but if no other tokens are included, no changes are made<br />

to the user account. You can use the UPDATE statement to update the group that a user is assigned to or<br />

to update which database ACS uses to authenticate the user.<br />

Table C-4 lists the valid tokens <strong>for</strong> UPDATE statements.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!