6-25
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 6 Setting Up and Managing User Groups
Configuration-specific User Group Settings
Step 8
To save the group settings you have just made, click Submit.
For more information, see
Saving Changes to User Group Settings, page 6-53
.
Step 9
To continue specifying other group settings, perform other procedures in this
chapter, as applicable.
Enabling Password Aging for Users in Windows Databases
Cisco Secure ACS supports two types of password aging for users in Windows
databases. Both types of Windows password aging mechanisms are separate and
distinct from the other Cisco Secure ACS password aging mechanisms. For
information on the requirements and settings for the password aging mechanisms
that control users in the CiscoSecure user database, see
Enabling Password Aging
for the CiscoSecure User Database, page 6-20
.
Note
You can run both the Windows NT/2000 Password Aging and the
Cisco Secure ACS Password Aging for Transit Sessions mechanisms
concurrently, provided that the users authenticate from the two different
databases.
The two types of password aging in Windows databases are as follows:
•
RADIUS-based password aging—RADIUS-based password aging depends
upon the RADIUS AAA protocol to send and receive the password change
messages. Requirements for implementing the RADIUS-based Windows
password aging mechanism include the following:
–
Communication between Cisco Secure ACS and the AAA client must be
using RADIUS.
–
The AAA client must support MS CHAP password aging in addition to
MS CHAP authentication.
–
Users must be in a Windows NT/2000 database.
–
Users must be using the Windows DUN client.
–
You must enable MS CHAP version 1 or MS CHAP version 2, or both,
in the Windows NT/2000 configuration within the External User
Databases section.