45
ECLYPSE APEX
ECLYPSE-Based Centralized Credential Authentication
The credential database is centralized in an ECLYPSE controller that is configured as a RADIUS
server, to authenticate login requests made directly to it, and by other subscribed ECLYPSE con-
trollers. This architecture is ideal when you are not using EC-Net on your network.
EC-Net cannot subscribe to a remote RADIUS server. Due to this, you will have to add user credentials to both the
ECLYPSE RADIUS server and to the EC-Net station. For this reason, if you are using EC-Net on your network, it is
best to centralize credential authentication by using this EC-Net station as a RADIUS server. See
EC-
gfx
Program
EC-Net
A
ECLYPSE
Controller B
Cache B
ECLYPSE
Controller A
RADIUS A
Key:
RADIUS
RADIUS Server
Credential Database
1
2
2
3
3
Cache
Cached Credential
Database
Optional
Figure 32: ECLYPSE-Based Centralized Credential Authentication
This authentication method has the following components.
Component
Description
Login Credential 1
This is the login credential used by an EC-
gfx
Program user to connect to the EC-Net station. This
credential is managed in the EC-Net User Service.
Login Credential 2
This is the login credential used by an EC-
gfx
Program user to connect to ECLYPSE controller A. This
credential is managed in controller’s A
Login Credential 3
This is the login credential used by the EC-Net station's RestService to connect to any ECLYPSE
controller. To program an ECLYPSE controller with EC-
gfx
Program through EC-Net, the RestService
must be configured on the EC-Net station with a login credential to all ECLYPSE controllers. This
credential is managed in this ECLYPSE controller A's
RADIUS server credential
database.
Credential Database A
This is the EC-Net station UserService credential database. This credential database is independent
of all other credential databases.
RADIUS Server A
Credential Database
This is the ECLYPSE controller A’s RADIUS Server credential database. If EC-
gfx
Program users are
to connect to this controller through the EC-Net station, this credential database must have the
credentials for EC-Net station’s RestService. This credential database must also have the credentials
for each user that will login to any ECLYPSE controller (for example, administrators, direct
connection EC-
gfx
Program users, ENVYSION users, etc.). See
.
Credential Database
Cache B
This is the ECLYPSE controller B’s cached credential database. If the connection to ECLYPSE
controller A’s RADIUS Server is lost, users that have previously authenticated themselves with the
ECLYPSE controller A’s RADIUS Server credential database on a given controller will still be able to
login to those controllers as their credentials are locally cached.
Supported RADIUS Server Architectures
Содержание ECLYPSE APEX
Страница 1: ...User Guide ECLYPSE APEX...
Страница 171: ...ECLYPSE APEX_UG_11_EN...