HP-UX AAA Server A.08.00.01 Administrator's Guide

Figure 1-6 Authorization Steps
Authorization Steps
1. The server receives the Access-Request.
2. The server evaluates the request-ingress policy. This is the first step in the FSM,
before the request is despatched for processing. The request ingress policy can be
used to alter the request in one of the following ways:
A-V pairs may be added, changed, or removed.
The request classification may be altered.
The request may be rejected immediately.
The request may be dropped entirely, and no reply is sent.
If the request-ingress policy is evaluated successfully, the HP-UX AAA Server
continues with the authorization process.
3. If a request is being proxied, then the HP-UX AAA Server evaluates the
proxy-egress and proxy-ingress policies. The HP-UX AAA Server applies the
proxy-egress policy before the RADIUS proxy request message is created and sent.
The proxy-ingress policy is applied after the proxy response is received. Table 1-2
discusses how these policies are used to alter requests.
44 Overview: The HP-UX AAA Server