ECLYPSE-Based Centralized Credential Authentication
The credential database is centralized in an ECLYPSE controller that is configured as a RADIUS server, to authenticate lo-
gin requests made directly to it, and by other subscribed ECLYPSE controllers.
A
ECLYPSE
Controller B
Cache B
ECLYPSE
Controller A
RADIUS A
Key:
RADIUS
RADIUS Server
Credential Database
1 2 2
3
3
Cache
Cached Credential
Database
Optional
User
Server
Figure30: ECLYPSE-Based Centralized Credential Authentication
This authentication method has the following components.
Component Description
Login Credential 1 This is the login credential used by a user to connect to the Server. This credential is managed by the Server.
Login Credential 2
This is the login credential used by a user to connect to ECLYPSE controller A. This credential is managed in controller’s
A User Management credential database.
Login Credential 3
This is the login credential used by the Server’s Rest Service to connect to any ECLYPSE controller. This credential is
managed in this ECLYPSE controller A's User Management RADIUS server credential database.
Credential Database A This is the Server’s user credential database. This credential database is independent of all other credential databases.
RADIUS Server A Credential
Database
This is the ECLYPSE controller A’s RADIUS Server credential database. This credential database must also have the
credentials for each user that will log in to any ECLYPSE controller (for example, administrators, direct connection users,
ENVYSION users, etc.). See User Management.
Credential Database Cache
B
This is the ECLYPSE controller B’s cached credential database. If the connection to ECLYPSE controller A’s RADIUS
Server is lost, users that have previously authenticated themselves with the ECLYPSE controller A’s RADIUS Server
credential database on a given controller will still be able to log in to those controllers as their credentials are locally
cached.
Supported RADIUS Server Architectures
40
nLight ECLYPSE