HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
The Secure LAN Advisor.......................................................................................159
Preparing Your LAN ...................................................................................................160
Determining the EAP Authentication Method to Use................................................161
Securing WLANs with the HP-UX AAA Server.........................................................164
Digital Certificate Administration...............................................................................164
Using the “Self-Signed” Digital Certificates..........................................................165
Installing Your Own Digital Certificates and Keys................................................166
Installing Server Certificates and Keys.............................................................166
Installing Client Certificates and Keys.............................................................167
Defining Certificate Locations on the HP-UX AAA Server..............................167
14 Managing Sessions.........................................................................................................169
Session Logs.................................................................................................................169
Displaying Session Attributes................................................................................169
Stopping a Session..................................................................................................170
Session Limits..............................................................................................................170
Setting Limits on a User-by-User Basis..................................................................171
Setting Timeout Values.....................................................................................171
Establishing a Filter...........................................................................................171
Limiting Access Points (NAS-Port, NAS-ID, Calling-Station ID, and
others)...............................................................................................................171
Denying Access (Called-Station-ID and others)...............................................172
Limiting Simultaneous Sessions.......................................................................172
Setting Limits for Users on a Global Basis.............................................................173
Setting Limits for All User Profiles Grouped by Realms.................................173
15 Assigning IP Addresses....................................................................................................174
Assigning Static IP Addresses.....................................................................................174
To Assign a Static IP (IPv4) Address to a Profile in Flat Files................................174
To Assign a Static IPv6 Address to a Profile in Flat Files......................................175
To Assign Static Traditional IP (IPv4) Addresses to a User Profile in an LDAP
LDIF File.................................................................................................................177
To Assign Static IPv6 Addresses to a User Profile in an LDAP LDIF File.............178
Assigning Dynamic IP Addresses Using DHCP.........................................................178
16 OATH Standards-Based OTP Authentication.......................................................................179
OTP and OATH Overview..........................................................................................179
HP-UX AAA Server and OATH Support....................................................................180
Supported OTP Functions for RADIUS Standard Password (PAP) and MS-CHAP
v2.................................................................................................................................182
Components Required to Configure OTP Authentication..........................................182
Configuring OTP Authentication on the HP-UX AAA Server ..................................183
OTP Authentication Configuration Flowchart......................................................183
Basic or Typical Configuration...............................................................................186
Advanced Configuration........................................................................................187
Advanced OTP Authentication Configuration Concepts.................................187
Table of Contents 7