Chapter 8 Establishing Cisco Secure ACS System Configuration
Local Password Management
8-6
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
The remote change password options are listed below:
–
Disable TELNET Change Password against this ACS and return the
following message to the users telnet session—When selected, this
option disables the ability to perform password changes during a Telnet
session hosted by a AAA client. Users who submit a password
change receive the text message that you type in the corresponding box.
–
Upon remote user password change, immediately propagate the
change to selected replication partners—This setting determines
whether Cisco Secure ACS sends to its replication partners any
passwords changed during a Telnet session hosted by a AAA
client, by the CiscoSecure Authentication Agent, or by the
User-Changeable Passwords web interface. The Cisco Secure ACSes
configured as this Cisco Secure ACS’s replication partners are listed
below this check box.
This feature depends upon having the CiscoSecure Database Replication
feature configured properly; however, replication scheduling does not
apply to propagation of changed password information.
Cisco Secure ACS sends changed password information immediately,
regardless of replication scheduling.
Changed password information is replicated only to Cisco Secure ACSes
that are properly configured to receive replication data from this
Cisco Secure ACS. The automatically triggered cascade setting for the
CiscoSecure Database Replication feature does not cause
Cisco Secure ACSes that receive changed password information to send
it to their replication partners.
For more information about CiscoSecure Database Replication, see
CiscoSecure Database Replication, page 8-9
.
•
Password Change Log File Management—These settings enable you to
configure how Cisco Secure ACS handles log files generated for the User
Password Change report. For more information about this report, see
Cisco Secure ACS System Logs, page 9-11
.
The log file management options for the User Password Changes Log are
listed below:
–
Generate New File—You can specify the frequency at which
Cisco Secure ACS creates a User Password Changes Log file: daily,
weekly, monthly, or after the log reaches a size in kilobytes that you
specify.