HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
reply_check=+abort
reply_check=+dump
reply_check=+ignore
reply_check=+verbose
reply_check=clear
reply_check=none
reply_check=Attribute
The value of first (default) means to check only the first match. The value of all
means to check all the attributes for matches. The value of +abort means to abort and
coredump if a check fails. The value of +dump means to dump the offending packet
(in hexadecimal). You can specify a specific attribute to check with the syntax
reply_check=Attribute.
NOTE: This feature may not work well in situations where the HP-UX AAA Server
is communicating with non-HP servers.
OTP Authentication-Related Configuration Items
The following OTP authentication related configuration items can be set in the
aaa.config file:
otp_token_length <68>
otp_lookup_window <0 -any positive integer>
otp_token_lock_counter <1-any positive integer>
otp_add_checksum <yes or no>
For more information on these configuration items, see “System-Wide OTP
Configuration Items” (page 195).
Dynamic Authorization-Related Configuration Items
The following Dynamic Authorization-related configuration items can be set in the
aaa.config file:
Table 33-1 Dynamic Authorization-Related Configuration Items
DescriptionConfiguration Items
The maximum number of client requests allowed in the client
queue.
global_client_q.limit
The size of the hash table used for performing retransmissions of
client requests.
client_retry_tbl_size
The time interval for which an incoming Event-Timestamp is
valid.
event_timestamp_window
Enforces the HP-UX AAA server to perform Reverse Path
Forwarding (RPF) checks on the incoming Disconnect and CoA
requests. This is disabled by default.
enable_rpf_check
The aaa.config File 525