Gebruiksaanwijzing /service van het product 11I V2 van de fabrikant HP (Hewlett-Packard)
Ga naar pagina of 64
HP-UX AAA Server A.06.01 Getting Started Guide HP-UX 11.0, 11i v1, 11i v2 Manufacturing P art Number : T1428-90058 E 10 04 U .S .A. © Copyright 2001-2004 Hewlett-P ackard Development Company , L.
ii Legal Notices The information in this document is subject to change without notice. Hewlett-P ackard makes no warranty of any kind with regard to this manual, including , but not limited to , the implied warranties of merchantability and fitness f or a particular purpose .
Contents iii About This Document 1. Introduction to AAA Server RADIUS Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 RADIUS T opology . . . . . . . . . . . . . . . . . . . . . .
Contents iv Storing User Profiles in the Default Users File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Grouping Users by Realm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Adding and Modifying Users .
v About This Document This document provides an overview of the HP-UX AAA Server and explains how to install and start the product. The document also provides steps to basic configuration tasks for beginning users. Refer to the HP-UX AAA Server Administrator’ s Guide for complete HP-UX AAA Server documentation.
vi Publishing History The following table shows the printing history of this document. The first entry in the table corresponds to this document, while previous releases are listed in descending order .
vii NO TE Emphasizes or supplements parts of the text. Y ou can disregard the information in a note and still complete a task. IMPORT ANT Notes that provide information that are essential to completing a task. CA UTION Describes an action that must be avoided or followed to prevent a loss of data.
viii.
Chapter 1 1 1 Introduction to AAA Server This chapter contains an overview of product features and basic information about using the HP-UX AAA Server .
Introduction to AAA Ser ver RADIUS Overview Chapter 1 2 RADIUS Overview The Remote Authentication Dial In User Service (RADIUS) protocol is widely used and implemented to manage access to network services.
Introduction to AAA Ser ver RADIUS Overview Chapter 1 3 Figure 1-1 Generic AAA Network T opology Establishing a RADIUS Session The handling of a user request is series of message exchanges that attempts to provide the user with a network service by establishing a session for the user .
Introduction to AAA Ser ver RADIUS Overview Chapter 1 4 transaction between a RADIUS AAA server and a client (a NAS in this example). When the user’ s workstation connects to the client, the client sends an Access-Request RADIUS data packet to the AAA server .
Introduction to AAA Ser ver RADIUS Overview Chapter 1 5 Accounting-Request—triggered by the user , by the client, or an interruption in service—to stop the session. Again, the server will acknowledge the Accounting-Request with an Accounting-Response.
Introduction to AAA Ser ver RADIUS Overview Chapter 1 6 mechanisms . This flexibility also allows EAP to be implemented in a way (LEAP , for example) that is more suitable for wireless and mobile environments than other authentication protocols.
Introduction to AAA Ser ver RADIUS Overview Chapter 1 7 defined wa y of extending RADIUS . Conflicts can occur when the RFC is not followed. In those cases , the server can map the attributes to unique internal values for processing. F or a full description of RADIUS attribute-value pairs , see the Administrator’s Guide .
Introduction to AAA Ser ver Product Structure Chapter 1 8 Product Structure The HP-UX AAA Server , based on a client/server architecture , consists of the following components which may be installed i.
Introduction to AAA Ser ver Product Structure Chapter 1 9 The 802.1x Advisor The 802.1x Advisor is an HTML tutorial/help system in the Server Manager GUI that walks you through the tasks and Server Manager screens for securing WLANs with the HP-UX AAA Server .
Introduction to AAA Ser ver Product Structure Chapter 1 10 Accessing the Server Manager The Server Manager provides access to the AAA server management functions and configuration files . From a remote client workstation, administrators can access the AAA Server Manager interface through a W eb browser .
Introduction to AAA Ser ver Product Structure Chapter 1 11 Some advanced features of the HP-UX AAA Server cannot be configured through the Server Manager interface. F or example , if you want to define session management parameters, policies, or vendor -specific attributes, you must manually edit the configuration files .
Introduction to AAA Ser ver AAA Server Architecture Chapter 1 12 AAA Server Architecture The HP-UX AAA Server Architecture consists of three primary components: • Configuration files .
Introduction to AAA Ser ver AAA Server Architecture Chapter 1 13 <realm name>.users The same information as the users file, but this user information is associated with a particular realm. These files are only necessary to perform File type authentication for a defined realm.
Introduction to AAA Ser ver AAA Server Architecture Chapter 1 14 Y ou can find out more information about these files by referring to the HP-UX AAA Server Administrator’ s Guide .
Introduction to AAA Ser ver HP-UX AAA Server Features Chapter 1 15 HP-UX AAA Server F eatures General F eatures • Compliant with RADIUS protocol RFC 2865 and 2866 standards • Supports multiple ven.
Introduction to AAA Ser ver HP-UX AAA Server Features Chapter 1 16 • Supports multiple user definition ( realm ) files keyed by realm (File type authentication) • Authentication of users define.
Introduction to AAA Ser ver HP-UX AAA Server Features Chapter 1 17 • “Self-signed” AAA Server digital certificates created during installation allow for a secured TLS , TTLS, and PEAP environme.
Introduction to AAA Ser ver HP-UX AAA Server Features Chapter 1 18.
Chapter 2 19 2 Installing and Starting the HP-UX AAA Server This chapter leads you through the steps to install and start the HP-UX AAA Server ..
Installing and Star ting the HP-UX AAA Ser ver Getting the HP-UX AAA Server Software Chapter 2 20 Getting the HP-UX AAA Server Software Y ou can get the most recent version of the HP-UX AAA Server software at the HP Softw are Depot: http://software.hp.
Installing and Star ting the HP-UX AAA Ser ver Installing the HP-UX AAA Server Chapter 2 21 Installing the HP-UX AAA Server IMPORT ANT Be sure to review the HP-UX AAA Server Release Notes before installation. The Release Notes list the requirements for each release, inc luding: installation, patch, and browser requirements .
Installing and Star ting the HP-UX AAA Ser ver Starting the HP-UX AAA Ser ver Chapter 2 22 Starting the HP-UX AAA Server NO TE Refer to the Securing the HP-UX AAA Server section in the HP-UX AAA Server Administrator’ s Guide for information on securing your HP-UX AAA Server .
Installing and Star ting the HP-UX AAA Ser ver T esting the Installation Chapter 2 23 T esting the Installation T o quickly test the server installation, you will use Server Manager to add a loopback connection to a AAA server , start the server , and then check its status for a response .
Installing and Star ting the HP-UX AAA Ser ver T esting the Installation Chapter 2 24 Step 10. V erify your HP-UX AAA Server is installed and operating correctly by using the testing user (named test_user) created during installation.
Installing and Star ting the HP-UX AAA Ser ver Installation Defaults Chapter 2 25 Installation Defaults The HP-UX AAA Server can be run as root user , however non-root user is recommended. A user and group, both named aaa , will be created during installation.
Installing and Star ting the HP-UX AAA Ser ver Installation Defaults Chapter 2 26 /opt/aaa/examples/orac le • create.sql : SQL script to create Oracle users table • delete.
Installing and Star ting the HP-UX AAA Ser ver Installation Defaults Chapter 2 27 /etc/opt/aaa Configuration files: • aaa.config : runtime and tunneling configuration file • authfile : realm to authentication-type mapping file • clients : client to shared secret mapping file • db_srv.
Installing and Star ting the HP-UX AAA Ser ver Installation Defaults Chapter 2 28 The following table lists the files generated during operation and located in /var/opt/aaa/ by default: T able 2-2 Files Generated During Operation Directory File /acct/session.
Installing and Star ting the HP-UX AAA Ser ver Commands, Utilities, & Daemons Chapter 2 29 Commands, Utilities, & Daemons T able 2-3 Commands, Utilities, & Daemons Command Description db_srv The db_srv daemon performs Oracle database access operations for authentication on behalf of one or more remote HP-UX AAA Servers.
Installing and Star ting the HP-UX AAA Ser ver UnInstalling the HP-UX AAA Server Software Chapter 2 30 UnInstalling the HP-UX AAA Server Software Use the following steps to uninstall the HP-UX AAA Server: Step 1. Select Administration in the Navigation Tree .
Chapter 3 31 3 Basic Configuration T asks This chapter explains a few basic configuration tasks . Refer to the HP-UX AAA Server Administrator’ s Guide for complete information on configuring the HP-UX AAA Server .
Basic Configuration T asks Storing User Profiles Chapter 3 32 Storing User Profiles The user information that determines how an access request is authenticated and authorized is configured in a profile as a set of A-V pairs.
Basic Configuration T asks Storing User Profiles Chapter 3 33 the method you choose is compatible with the client password hashing method. The following table lists the supported client password hashing methods and each storage hash you should use for each method: Step 9.
Basic Configuration T asks Storing User Profiles Chapter 3 34 Step 3. In the Name field, enter the realm name. Step 4. Select Authentication from the Realm Type drop-down list. Step 5. Select Users File in the User Profile Storage drop-down list. Step 6.
Basic Configuration T asks Storing User Profiles Chapter 3 35 CA UTION Save Configuration will save the entire server configuration (access devices , proxies , local realms , users , and server properties) to the servers you specify .
Basic Configuration T asks Adding and Modifying Users Chapter 3 36 Adding and Modifying Users User profiles associate information with a user name for authentication and authorization.
Basic Configuration T asks Adding and Modifying Users Chapter 3 37 User Name: V alue to compare to the User-Name attribute value in the request. It must be less than 64 characters .
Basic Configuration T asks Adding and Modifying Users Chapter 3 38 Figure 3-2 Server Manager’s F ree User Attributes Screen T o add attributes to the list boxes, follow the Attribute = V alue syntax. A-V pairs may be listed one per line. When adding a new user profile , you select the Create button to submit it to the AAA Server Manager .
Basic Configuration T asks Session Logging and Monitoring Chapter 3 39 Session Logging and Monitoring Y ou can view the log files that record the details of each AAA transaction or the session logs that record information about each user's session.
Basic Configuration T asks Session Logging and Monitoring Chapter 3 40 Step 4. Select a session. The AAA server manager will display the attributes for the selected session.
Basic Configuration T asks Session Logging and Monitoring Chapter 3 41 Figure 3-4 Server Manager’s Logfile Screen.
Basic Configuration T asks Session Logging and Monitoring Chapter 3 42 Search P arameters Y ou can filter what dates and times to retrieve from the logfile.
Basic Configuration T asks Session Logging and Monitoring Chapter 3 43 Viewing Server Statistics Selecting the Statistics link from Server Manager’s Na vigation Tree allows you to retrieve a count of events that occurred on the AAA server within a time range.
Basic Configuration T asks Securing WLANs with the HP-UX AAA Server Chapter 3 44 Securing WLANs with the HP-UX AAA Server The HP-UX AAA Server provides security framework to support EAP authentication mechanisms for WLAN users .
Glossar y of T er ms Chapter 4 45 4 Glossary of T erms 802.1x Advisor The 802.1x Advisor is an HTML tutorial/help system in the Server Manager GUI that walks you through the tasks and Server Manager screens for securing WLANs with the HP-UX AAA Server .
Glossar y of T er ms Chapter 4 46 Administrator Special user , known by the system on which the AAA server is running and is able to configure and to manage the AAA server .
Glossar y of T er ms Chapter 4 47 Client NAS , proxy server , or other networking device that uses the AAA server services to authenticate and authorize users.
Glossar y of T er ms Chapter 4 48 When a user requests access to a service of a specific configuration, a client may provide this information in an Access-Request as a hint to the AAA server .
Glossar y of T er ms Chapter 4 49 See Integrated Services Digital Network . LAS See Local Authorization Server . LDAP See Lightweight Directory Access Protocol . Lightweight Directory Access Protocol Used for directories providing naming, location, management, security , and other services for Internet networking, abbreviated as LDAP .
Glossar y of T er ms Chapter 4 50 See P assword Authentication Protocol . P assword Authentication Protocol A simple password protocol that transmits a user name and password across the network, unencrypted, abbreviated as P AP . PEAP (Protected EAP) Functionally very similar to TTLS , but does not encapsulate legacy authentication methods.
Glossar y of T er ms Chapter 4 51 A NAS or other device that sends requests to an AAA server . RAS See Remote Access Server . Realm A realm is a logical group of users, who usually can be authenticated using one particular method. Grouping users into realms simplifies the management of those users in a distributed environment.
Glossar y of T er ms Chapter 4 52 See Simultaneous Access T oken . Server Manager A W eb-based graphical user interface which provides an interface between an administrator and the AAA servers.
Glossar y of T er ms Chapter 4 53 A token pool contains a number of tokens belonging to some organization and having a given name . These tokens may be shared among one or more realms . Tunneling A secure connection between a client workstation and an intranet or other network, that provides a VPN to a user .
Glossar y of T er ms Chapter 4 54.
55 Index Numerics 802.1x Advisor , 9 A acquiring HP-UX AAA Server software , 20 C Challenge Handshake Authentication Protocol , 5 CHAP (Challenge Handshake Authentication Protocol) , 5 check items , 3.
Index 56 user sessions , 39 W Wireless LAN , 9 , 44 Wireless LAN , Authentication , 9 Wireless LAN , securing , 9 , 44.
Een belangrijk punt na aankoop van elk apparaat HP (Hewlett-Packard) 11I V2 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen HP (Hewlett-Packard) 11I V2 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens HP (Hewlett-Packard) 11I V2 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding HP (Hewlett-Packard) 11I V2 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over HP (Hewlett-Packard) 11I V2 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van HP (Hewlett-Packard) 11I V2 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de HP (Hewlett-Packard) 11I V2 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met HP (Hewlett-Packard) 11I V2 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.