HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
C - D
Challenge Handshake Authentication Protocol
Log-in security procedure for dial-in access. Rather than send an unencrypted password, a random
number is sent to the client as a challenge. The challenge is one-way hashed with the password,
and the result is sent back to the server. The server does the same with its copy of the password
and verifies that it gets the same result to authenticate the user, abbreviated as CHAP.
CHAP Challenge Handshake Authentication Protocol.
Client NAS, proxy server, or other networking device that uses the AAA Server services to authenticate
and authorize users.
Common
Open Policy
Service
A query and response protocol that can be used to exchange policy information between a policy
server (Policy Decision Point or PDP) and its clients (Policy Enforcement Points or PEPs, such as
a router), abbreviated as COPS.
COPS Common Open Policy Service.
DHCP
(Dynamic
Host
Configuration
Protocol)
Protocol that automatically and dynamically assigns IP addressees.
Dialed Number Identification Service
Each request is authenticated locally or forwarded to a remote server according to the number
called to access a network service.
DNIS Dialed Number Identification Service.
Dynamic
Authorization
A capability of the HP-UX AAA Server that enables RADIUS-server initiated requests to be sent
to the authenticator.
E - F - G
EAP Extensible Authentication Protocol.
EAP-AKA EAP Authentication and Key Agreement (AKA) authentication method. EAP-AKA is an
authentication and session key distribution mechanism used in the third generation mobile
networks: UMTS and CDMA 2000.
EAP-SIM EAP Subscriber Identity Module (SIM) authentication method. An authentication method capable
of operating in wireless networks.
Extensible Authentication Protocol
Described in RFC 2284, abbreviated as EAP.
Finite State
Machine
The Finite State Machine is the component of the AAA Server software that controls the flow of
access request authentication and accounting request handling, abbreviated as FSM.
Forwarding
Server
The AAA Server that receives an Access-Request from a client and forwards that request to another
AAA server for authentication.
FSM Finite State Machine.
GTC (Generic
Token Card)
Carries user specific token cards for authentication. The main feature in GTC is Digital
Certificate/Token Card-based Authentication.
604 Glossary of Terms