HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
Adding a Server................................................................................................280
Modifying a Server...........................................................................................284
Deleting a Server...............................................................................................284
Cloning a Server................................................................................................284
Administering HP-UX AAA Servers Using HP-UX AAA Server Admin Tool
(Command Line)....................................................................................................287
rad_admin Syntax.............................................................................................287
Examples of Administering Multiple HP-UX AAA Servers............................288
Administering HP-UX AAA Servers Using Interactive User Interface............288
Disaster Recovery of the HP-UX AAA Server Manager.............................................289
19 Configuring the HP-UX AAA Server for Client Functionality .................................................291
Overview.....................................................................................................................291
CLIENT AATV.............................................................................................................292
Configuring CLIENT AATV..................................................................................292
Working of the CLIENT AATV..............................................................................292
Supported APIs...........................................................................................................294
Internal Attributes and Mapping Functions...............................................................295
20 Configuring the HP-UX AAA Server for Dynamic Authorization.............................................297
Dynamic Authorization Overview..............................................................................297
HP-UX AAA Server and Dynamic Authorization......................................................297
Processing of Dynamic Authorization Requests.........................................................298
Configuring for Dynamic Authorization....................................................................300
Basic Configuration................................................................................................301
Advanced Configuration........................................................................................302
Migrating Existing SQL Access Deployments for Dynamic Authorization.....302
Configuring Multiple HP-UX AAA Servers as a Group..................................304
Configuring for Disconnect and CoA Request Processing.........................306
Dedicated HP-UX AAA Servers for Dynamic Authorization.....................311
Dynamic Authorization in Authorize Only Mode...........................................316
Configuring for Dynamic Authorization in Authorize Only Mode...........317
Configuring for Proxy Functionality................................................................319
Configuring for Dynamic Authorization Proxy Functionality...................320
Configuring for Failover...................................................................................321
Security Consideration in Dynamic Authorization..........................................321
Replay Protection........................................................................................321
Message-Authenticator................................................................................324
Reverse Path Forwarding Check for Proxies...............................................324
Sample Configuration Files.........................................................................................326
The client-request-init.grp.dynauth Sample File.................................327
The client-reply-ingress.grp.dynauth Sample File...............................327
The sqlaccess.config.dynauth Sample File................................................327
The sqlaccess.config.dynauth_server_group Sample File....................329
The dbsetup.sql.dynauth_server_group Sample File...............................331
10 Table of Contents