Chapter 3 Configuring the Server
Setting up the AAA Mode
3-20
User Guide for CiscoWorks Common Services
78-16571-01
Step 5
Click Apply.
It checks whether:
•
The System Identity user password of the Slave matches that of the Master.
•
The Self Signed Certificate of the Master is added as the peer certificate in
the Slave. The CN present in the certificate should match with the Master
server name.
•
The Master is up and running on the specified port.
In case these checks fail, you are prompted to perform these steps, before
proceeding.
Setting up the AAA Mode
The CiscoWorks Server provides mechanisms used to authenticate users for
CiscoWorks applications.
CiscoWorks login modules allow administrators to add new users using a source
of authentication other than the native CiscoWorks Server mechanism (that is, the
CiscoWorks Local login module). You can use Cisco Secure ACS services for this
purpose (see
Setting the Login Module to ACS
).
However, many network managers already have a means of authenticating users.
To use your current authentication database for CiscoWorks authentication, you
can select a login module (NT, UNIX, , Radius, and others).
After you select and configure a login module, all authentication transactions are
performed by that source.
The CiscoWorks Server determines user roles. Therefore, all users must be in the
local database of user IDs and passwords. Users who are authenticated by an
alternative service and who are not in the local database are assigned to the same
role as the guest user (by default, the Help Desk role).
To assign a user to a different role, such as the System Admin role, you must
configure the user locally. Such users must have the same user ID locally, as they
have in the alternative authentication source. Users log in with the user ID and
password associated with the current login module.