HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
Based on the success or failure of authentication, the HP-UX AAA Server sends
an Access-Accept or Access-Reject message to the user.
Supported OTP Functions for RADIUS Standard Password (PAP) and
MS-CHAP v2
OTP support for MS-CHAP v2 is compatible with RFC 4226. Table 16-1 describes the
supported functions for PAP and MS-CHAP v2.
Table 16-1 Supported OTP Functions for PAP and MS-CHAP v2
MS-CHAP v2RADIUS Standard Password (PAP)Functions
YesYesValidate OTP
YesYesValidate Password
YesYesStore OTP
YesYesValidate OTP and Password
YesYesProxy the OTP and password to
another RADIUS server for OTP
and password validation
NoYesSplitting the OTP and password,
and proxying the OTP or
password to another RADIUS
server for OTP or password
validation
For information on supported action ids, see Table 16-3 (page 190).
Components Required to Configure OTP Authentication
The following components, which are required to configure OTP authentication, are
provided with the HP-UX AAA Server:
Modified Finite State Machine (FSM)
Database schema files
The following sample configuration files:
sqlaccess.config
Policy configuration files:
oath-proxy-egress.grp
oath-request-ingress.grp
oath-reply-egress.grp
User Database Administration Manager (This web-based interface enables you
to administer user profiles and token information in the SQL database
effectively.) For more information, see Administering Users and Tokens Stored
in an SQL Database” (page 374).
182 OATH Standards-Based OTP Authentication