HP-UX AAA Server A.08.01 release notes (T1428-90073, May 2010)
using Global System for Mobile Communications (GSM) Subscriber Identity Module
(SIM) as specified in RFC 4186 and using Universal Mobile Telecommunications
System (UMTS) Authentication Key Agreement (AKA) as specified in RFC 4187
in 3rd Generation Partnership Project (3GPP) network environment.
• Scalability and High Availability: Supports running and managing a group of
multiple HP-UX AAA Servers on a single host to process multiple RADIUS requests
simultaneously to offer scalability and better performance. This feature also
supports running and managing a group of multiple HP-UX AAA servers on
different hosts to offer high availability.
• MS-CHAP v2 for OTP Authentication: MS-CHAP v2 module supports Open
Authentication (OATH) standards-based One-Time Password (OTP) authentication.
• OATH Standards-Based OTP and Two-Factor Authentication: Provides Open
AuTHentication (OATH) standards-based One-Time Password (OTP)
authentication for additional security to protect networks from phishing attacks,
unauthorized network access, and identity theft. OATH standards-based OTP
authentication in the HP-UX AAA Server can be customized easily to suit various
deployment scenarios. Typically, OTP is used to provide two-factor authentication.
• Web-Based User Database Administration Manager: Provides a customizable
web interface that can be used to manage user and token information stored in a
SQL database.
• HP-UX AAA Server SDK: Server Plug-in Software Developer's Kit (SDK) for
customizing and extending the features of the HP-UX AAA Server. It enables the
creation of plug-ins to customize the implementation of the HP-UX AAA Server.
The HP-UX AAA Server SDK is now provided with the HP-UX AAA Server.
• Advanced Policy Engine: An updated policy engine that provides extended syntax
for complex policy actions to manipulate RADIUS requests and replies based on
attribute content. The default policy files enable the administrator to execute
policies without customizing the Finite State Machine (FSM). This feature includes
substring manipulation.
• Common Database Interface: Supports HP-UX AAA Server interaction with
supported databases via the SQL Access AATV and database client connector
libraries.
• EAP Support for Authenticated LAN Access: Secure wired and wireless LANs
using Extensible Authentication Protocol (EAP) to support 802.1x enabled network
access devices. EAP methods supported include PEAP, TTLS, TLS, GTC, MS-CHAP
v2, and MD5.
• Multi-Server Session Management: Supports user, group, or custom limits on
concurrent logins to limit simultaneous sessions. Customizable shared session
management for multiple HP-UX AAA Servers is supported via the SQL Access
feature.
6 HP-UX AAA Server A.08.01 Release Notes