136
Chapter 9: Authentication
TheTrippLiteConsoleServerisadedicatedLinuxcomputer,anditembodiespopularandprovenLinuxsoftwaremodulesfor
securenetworkaccess(OpenSSH)andcommunications(OpenSSL)andsophisticateduserauthentication(PAM,RADIUS,
TACACS+,KerberosandLDAP).
• ThischapterdetailshowtheAdministratorcanusetheManagementConsoletoestablishremoteAAAauthenticationfor
all connections to the Console Server and attached serial and network host devices
• ThischapteralsocoversestablishingasecurelinktotheManagementConsoleusingHTTPSandusingOpenSSLand
OpenSSHtoestablishasecureAdministrationconnectiontotheConsoleServer
9.1 Authentication Configuration
Authenticationcanbeperformedlocally,orremotelyusinganLDAP,RadiusorTACACS+authenticationserver.Thedefault
authentication method for the Console Server is Local.
AnyauthenticationmethodthatisconguredwillbeusedforauthenticationofanyuserattemptingtologinthroughTelnet,
SSH or the Web Manager to the Console Server and any connected serial port or network host devices.
TheConsoleServercanbeconguredtothedefault(Local)oranalternateauthenticationmethod(TACACS, RADIUS
Kerberos or LDAP)withtheoptionofaselectedorderinwhichlocalandremoteauthenticationistobeused:
Local TACACS /RADIUS/LDAP/Kerberos:Trieslocalauthenticationrst,fallingbacktoremoteiflocalfails
TACACS /RADIUS/LDAP/Kerberos Local:Triesremoteauthenticationrst,fallingbacktolocalifremotefails
TACACS /RADIUS/LDAP/Kerberos Down Local:Triesremoteauthenticationrst,fallingbacktolocaliftheremote
authenticationreturnsanerrorcondition(e.g.theremoteauthenticationserverisdownorinaccessible)
9.1.1 Local authentication
• SelectSerial and Network: Authentication and check Local
• ClickApply