HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
Adding a Group.....................................................................................................278
Modifying a Group................................................................................................279
Deleting a Group....................................................................................................279
Adding a Server.....................................................................................................280
Modifying a Server.................................................................................................284
Deleting a Server....................................................................................................284
Cloning a Server.....................................................................................................284
Administering HP-UX AAA Servers Using HP-UX AAA Server Admin Tool
(Command Line)..........................................................................................................287
rad_admin Syntax..................................................................................................287
Examples of Administering Multiple HP-UX AAA Servers.................................288
Administering HP-UX AAA Servers Using Interactive User Interface.................288
Disaster Recovery of the HP-UX AAA Server Manager..................................................289
19 Configuring the HP-UX AAA Server for Client Functionality .......................................................291
Overview...........................................................................................................................291
CLIENT AATV..................................................................................................................292
Configuring CLIENT AATV........................................................................................292
Working of the CLIENT AATV...................................................................................292
Supported APIs.................................................................................................................294
Internal Attributes and Mapping Functions.....................................................................295
20 Configuring the HP-UX AAA Server for Dynamic Authorization..................................................297
Dynamic Authorization Overview...................................................................................297
HP-UX AAA Server and Dynamic Authorization...........................................................297
Processing of Dynamic Authorization Requests..............................................................298
Configuring for Dynamic Authorization..........................................................................300
Basic Configuration.....................................................................................................301
Advanced Configuration.............................................................................................302
Migrating Existing SQL Access Deployments for Dynamic Authorization..........302
Configuring Multiple HP-UX AAA Servers as a Group........................................304
Configuring for Disconnect and CoA Request Processing...............................306
Dedicated HP-UX AAA Servers for Dynamic Authorization..........................311
Dynamic Authorization in Authorize Only Mode................................................316
Configuring for Dynamic Authorization in Authorize Only Mode.................317
Configuring for Proxy Functionality.....................................................................319
Configuring for Dynamic Authorization Proxy Functionality.........................320
Configuring for Failover........................................................................................321
Security Consideration in Dynamic Authorization...............................................321
Replay Protection..............................................................................................321
Message-Authenticator.....................................................................................324
Reverse Path Forwarding Check for Proxies....................................................324
Sample Configuration Files..............................................................................................326
The client-request-init.grp.dynauth Sample File......................................327
The client-reply-ingress.grp.dynauth Sample File....................................327
Table of Contents 157