If you specify the group method or local method and it fails, the authorization can fail. If you have not
configured a fallback method after the TACACS+ or LDAP server group method, authorization fails if all
server groups fail to respond.
This command does not require a license.
Examples
This example shows how to configure LDAP authorization with certificate authentication as the default AAA
authorization method for LDAP servers:
switch# configure terminal
switch(config)# aaa authorization ssh-certificate default group LDAPServer1 LDAPServer2
Related Commands
DescriptionCommand
Configures LDAP or local authorization with the SSH
public key as the default AAA authorization method
for LDAP servers.
aaa authorization ssh-publickey
Enables the LDAP feature.feature ldap
Enables the TACACS+ feature.feature tacacs+
Displays the AAA authorization configuration.show aaa authorization
Cisco Nexus 7000 Series Security Command Reference
44
A Commands
aaa authorization ssh-certificate