![Alcatel-Lucent 7950 SR System Management Manual Download Page 161](http://html1.mh-extra.com/html/alcatel-lucent/7950-sr/7950-sr_system-management-manual_2892148161.webp)
Security
7950 SR OS System Management Guide
Page 161
use-priv-lvl —
Specifies that the authorization RESPONSE packet is mapped to the user
profile defined in tmnxTacPlusPrivLvlMapTable. That user profile is used for authorization.
interactive-authentication
Syntax
[no] interactive-authentication
Context
config>system>security>tacplus
Description
This configuration instructs SR OS to send no username nor password in the start mes-
sage, and to display the
server_msg
in the GETUSER and GETPASS response from the
server. Interactive authentication can be used to support a One Time Password scheme (e.g. S/Key).
An example flow (e.g. with a telnet connection) is as follows:
• SR OS will send an authentication start request to the server with no username nor
password.
• server replies with TAC_PLUS_AUTHEN_STATUS_GETUSER and a
server_msg
.
• SR OS displays the
server_msg
, and collects the user name.
• SR OS sends a continue message with the user name.
• server replies with TAC_PLUS_AUTHEN_STATUS_GETPASS and a
server_msg
.
• SR OS displays the
server_msg
(which may contain, for example, an S/Key for One Time Pass-
word operation), and collects the password.
• SR OS sends a continue message with the password.
• server replies with PASS or FAIL.
When interactive-authentication is disabled SR OS will send the username and password in the
tacplus
start message. An example flow (e.g. with a telnet connection) is as follows:
• TAC_PLUS_AUTHEN_TYPE_ASCII.
the login username in the “user” field.
the password in the
user_msg
field (note: this is non-standard but doesn’t cause
interoperability problems).
• server ignores the password and replies with
TAC_PLUS_AUTHEN_STATUS_GETPASS.
• SR OS sends a continue packet with the password in the
user_msg
field.
• server replies with PASS or FAIL.
When interactive-authentication is enabled, tacplus must be the first method specified in the authenti-
cation-order configuration.
Default
no interactive-authentication
timeout
Syntax
timeout second
s
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...