HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
Configuration Attributes
You can add configuration attributes that are not directly supported by the Server
Manager graphic interface. You can add configuration attributes through the Server
Manager as a check item under the Free tab on the User Creation screen. For more
information, see “Tabs on the Add Users Screen” (page 130).
Authentication-Type
The authentication type is applied to a user just as it
would be applied to a user belonging to a realm. Check
and reply items in the user entry will be appended to
any items used later in the authentication process.
Comment
This attribute does not perform any server function. It
allows you to provide any necessary explanation for the
entry.
Deny-Message
This attribute specifies a string that would be returned
as a Reply-Message value to the user in the Access-Reject
if any deny item for this user caused a rejection. You can
configure a denial message (using the Free tab in the
Check Item list box in the Server Manager) as follows:
Deny-Message = "You can't do that."
NAS-Port != 3160
You can also use an asterisk wildcard:
Deny-Message = "*"
NAS-Port != 3160
This wildcard string sends the following message
indicating what deny item triggered the rejection:
Access denied,
NAS-Port != 3160
IMPORTANT: The Deny-Message will only be returned
if a deny item (Attribute!= Value) comparison fails. It
will not be returned if a check item fails.
Expiration
In date format, specifies when an entry expires. After
the date, the user will receive an Access-Reject with the
message, “Password has expired,” in response to all
Access-Requests. The correct syntax is as follows:
Expiration = mth day year
mth is the first three letters of the month. day is the
two-digit date. year is the four-digit year. The following
is an example of an Expiration check item:
Expiration = Jan 31 2004
548 Attribute-Value Pairs