HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
are limited to 1023 characters, which places a limit on the length of this string.
The value is case-sensitive.
The second form is the configuration of an AKA vector. An AKA vector is a fixed
length binary string (octets) attribute, which holds an EAP-AKA authentication
vector. The attribute value is a 576-bit binary string (72 bytes) partitioned as
described in Table 17-4. Table 17-4 lists the AKA Vector parameters.
Table 17-4 AKA Vector Parameters
DescriptionParameter
The first 128 bits (16 bytes) of the value
RAND
The next 64 bits (8 bytes) of the value
XRES
The next 128 bits (16 bytes) of the value
CK
The next 128 bits (16 bytes) of the value
IK
The last 128 bits (16 bytes) of the value
AUTN
The user credentials can be stored in any supported data repository, such as a local
realm users file, an LDAP database, SQL-compliant database using SQL Access, or a
customer-supplied database.
NOTE: SQL Access feature can be used to retrieve user credentials as well as manage
SQN. For SQL Access sample configuration, see “Realm-Based EAP-AKA Configuration
Information in authfile” (page 240). Configuring user credentials in realm user's file
and LDAP database requires Finite State Machine (FSM) modifications and a module
that manages SQN.
EAP-AKA Realm-Based Configurations
Many EAP-AKA parameters can be configured on a per realm basis. These parameters
are configured in realm entries stored in the authfile and EAP.authfile files.
Realm-Based EAP-AKA Configuration Information in authfile
The user's AKA credentials lookup information is configured in the authfile on a
per realm basis.
The EAP-AKA realm must be configured with the -AKA switch. The following syntax
is used to configure the user credential storage:
eapakarealm.com AKA <AATV name> <xstring, if any>
If user-specific plug-in is added for user lookup, the AATV name is replaced with the
plug-in name. The following section describes configuration of HP-UX AAA Server
and SQL-compliant database for credential lookup (subscriber key).
240 Configuring EAP-SIM and EAP-AKA Authentication Methods