HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
Basic or Typical Configuration....................................................................................186
Advanced Configuration.............................................................................................187
Advanced OTP Authentication Configuration Concepts......................................187
Attributes for Configuring OTP Authentication..............................................192
Advanced Deployment Scenarios..........................................................................199
Validating OTP Alone.......................................................................................200
Configuring Two-Factor Authentication..........................................................202
OTP or Password Validation at External RADIUS Server................................210
Predefined Mapping and Conversion Functions........................................................217
Sample Configuration Files.........................................................................................217
The sqlaccess.config Sample File..................................................................217
Sample Policy Files.................................................................................................220
The oath-request-ingress.grp Sample File...........................................221
The oath-reply-egress.grp Sample File..................................................221
The oath-proxy-egress.grp Sample File..................................................222
17 Configuring EAP-SIM and EAP-AKA Authentication Methods......................................................224
EAP-SIM............................................................................................................................224
Overview.....................................................................................................................224
EAP-SIM Authentication Using HP-UX AAA Server.................................................225
Features........................................................................................................................227
Benefits........................................................................................................................228
Configuring EAP SIM..................................................................................................228
EAP-SIM Client Configuration..............................................................................228
EAP-SIM User Credential Lookup Configuration.................................................228
EAP-SIM Realm-Based Configurations.................................................................229
Realm-Based EAP-SIM Configuration Information in authfile........................229
Realm-Based EAP-SIM Configuration Information in EAP.authfile................232
Global EAP-SIM Configuration in aaa.config........................................................235
EAP-AKA..........................................................................................................................236
Overview.....................................................................................................................236
EAP-AKA Authentication Using HP-UX AAA Server...............................................236
Features........................................................................................................................237
Benefits........................................................................................................................238
Configuring EAP-AKA................................................................................................239
EAP-AKA Client Configuration.............................................................................239
EAP-AKA User Credential Lookup Configuration...............................................239
EAP-AKA Realm-Based Configurations................................................................240
Realm-Based EAP-AKA Configuration Information in authfile......................240
Realm-Based EAP-AKA Configuration Information in EAP.authfile..............242
Global EAP-AKA Configuration in aaa.config......................................................247
Fast Re-Authentication.....................................................................................................248
Configuring for Fast Re-Authentication......................................................................248
Configuring for Fast Re-Authentication in EAP.authfile.................................248
Table of Contents 155