HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
a. The HP-UX AAA Server can contact an external service such as a database or
LDAP directory server to retrieve user information and perform authentication.
b. The HP-UX AAA Server can forward the request to a proxy HP-UX AAA Server
for authentication.
c. The HP-UX AAA Server can contact a DHCP server for IP address management.
If the external service is busy, unavailable, or invalid credentials are passed to it
by the HP-UX AAA Server, the HP-UX AAA Server will not authenticate the user
and may not respond.
5. If authentication is successful, the HP-UX AAA Server returns an Access-Accept
message along with provisioning attributes to the RADIUS client.
The RADIUS client allows the supplicant to connect to the configured network
service.
At this stage, incorrect attributes returned to the RADIUS client (or incorrect
attributes expected by the RADIUS clients) can prevent the supplicant from
connecting to the network service.
The HP-UX AAA Server is administered through the Server Manager. Here, problems
with the browser, Tomcat, and RMI object, or incorrect credentials by the administrator
can lead to problems while launching or using the Server Manager.
Probable Causes for Failure
This section discusses the problems, limitations, and considerations before
troubleshooting the AAA environment.
Configuration Problems
The RADIUS client, supplicant, or the HP-UX AAA Server is configured incorrectly
and lead to problems.
Some configuration related problems can result in the HP-UX AAA Server silently
discarding the message without any reply being sent to the RADIUS client. For example,
if the authentication queue is full, subsequent authentication requests are dropped.
External Service Problems
The HP-UX AAA Server interoperates with external services in the environment, such
as database servers, LDAP, DHCP, and SNMP. The following problems can be caused
by external services:
An external service failure can result in the HP-UX AAA Server not sending a
reply back to the RADIUS client.
The RADIUS message packet contains information about the realm. The realm
configuration specifies the external datastore used for user profile lookup. This
Probable Causes for Failure 467