|
|
April 17, 2000
These release notes contain important information and describe issues and workarounds regarding CiscoSecure Access Control Server (ACS) 2.3(5) for UNIX. For complete documentation on this product, please refer to the following documents:
These release notes discuss the following topics:
Supplemental Copyright Information, 2
Obtaining Technical Assistance, 7
The following new features are included in this release of CiscoSecure ACS for UNIX:
The following information supplements the copyright information in the CiscoSecure ACS 2.3 for UNIX User Guide:
This section identifies issues that have been resolved in CiscoSecure ACS 2.3(5) for UNIX.
This section identifies issues that remain open in CiscoSecure ACS 2.3(5) for UNIX.
error in line..." user = user6{
profile_id = 37
set server current-failed-logins = 0
profile_cycle = 33
radius=Ascend5 {
check_items= {
21=Mar 15 2000 (Edited for ease to understand)
2=cisco123
}
reply_attributes= {
6=1
7=1
207=1
208=30
}
}
}
User Profile Information
user = NAS.10.22.2.55{
profile_id = 29
profile_cycle = 10
NASName="10.22.2.55"
SharedSecret="cisco54321"
RadiusVendor="Ascend"
Dictionary="DICTIONARY.Ascend5"
}
The password change works as follows:
telnet 10.22.2.55
Trying 10.22.2.55...
Connected to 10.22.2.55.
Escape character is '^]'.
User Access Verification
Username: user6
Password:
Password Has Expired
Please enter new password.
Password:
Please re-enter your new password.
Password: nas3> The NAS output is as follows: 1w2d: AAA: parse name=tty38 idb type=-1 tty=-1 1w2d: AAA: name=tty38 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=38 channel =0 1w2d: AAA/AUTHEN: create_user (0x61297B5C) user='' ruser='' port='tty38' rem_add r='10.22.2.1/' authen_type=ASCII service=LOGIN priv=1 1w2d: AAA/AUTHEN/START (1572192080): port='tty38' list='' action=LOGIN service=L OGIN 1w2d: AAA/AUTHEN/START (1572192080): using "default" list 1w2d: AAA/AUTHEN/START (1572192080): Method=LOCAL 1w2d: AAA/AUTHEN (1572192080): status = GETUSER 1w2d: AAA/AUTHEN/CONT (1572192080): continue_login (user='(undef)') 1w2d: AAA/AUTHEN (1572192080): status = GETUSER 1w2d: AAA/AUTHEN/CONT (1572192080): Method=LOCAL 1w2d: AAA/AUTHEN (1572192080): status = GETPASS 1w2d: AAA/AUTHEN/CONT (1572192080): continue_login (user='user6') 1w2d: AAA/AUTHEN (1572192080): status = GETPASS 1w2d: AAA/AUTHEN/CONT (1572192080): Method=LOCAL 1w2d: AAA/AUTHEN (1572192080): password incorrect 1w2d: AAA/AUTHEN (1572192080): status = ERROR 1w2d: AAA/AUTHEN/START (2502004780): port='tty38' list='' action=LOGIN service=L OGIN 1w2d: AAA/AUTHEN/START (2502004780): Restart 1w2d: AAA/AUTHEN/START (2502004780): Method=RADIUS 1w2d: AAA/AUTHEN (2502004780): status = GETPASS 1w2d: AAA/AUTHEN/CONT (2502004780): continue_login (user='user6') 1w2d: AAA/AUTHEN (2502004780): status = GETPASS 1w2d: AAA/AUTHEN (2502004780): Method=RADIUS 1w2d: RADIUS: ustruct sharecount=1 1w2d: RADIUS: Initial Transmit tty38 id 150 10.22.2.1:1645, Access-Request, len 76 1w2d: Attribute 4 6 0A160237 1w2d: Attribute 5 6 00000026 1w2d: Attribute 61 6 00000005 1w2d: Attribute 1 7 75736572 1w2d: Attribute 30 2 1F0B3130 1w2d: Attribute 31 11 31302E32 1w2d: Attribute 2 18 611EE9DE 1w2d: RADIUS: Received from id 150 10.22.2.1:1645, Password-Expired, len 42 1w2d: Attribute 18 22 50617373 1w2d: AAA/AUTHEN (2502004780): status = GETPASS 1w2d: AAA/AUTHEN/CONT (2502004780): continue_login (user='user6') 1w2d: AAA/AUTHEN (2502004780): status = GETPASS 1w2d: AAA/AUTHEN (2502004780): Method=RADIUS 1w2d: AAA/AUTHEN (2502004780): status = GETPASS 1w2d: AAA/AUTHEN/CONT (2502004780): continue_login (user='user6') 1w2d: AAA/AUTHEN (2502004780): status = GETPASS 1w2d: AAA/AUTHEN (2502004780): Method=RADIUS 1w2d: RADIUS: ustruct sharecount=2 1w2d: RADIUS: Initial Transmit tty38 id 151 10.22.2.1:1645, Change-Password, len 90 1w2d: Attribute 4 6 0A160237 1w2d: Attribute 5 6 00000026 1w2d: Attribute 61 6 00000005 1w2d: Attribute 1 7 75736572 1w2d: Attribute 30 2 1F0B3130 1w2d: Attribute 31 11 31302E32 1w2d: Attribute 2 18 27CB81A8 1w2d: Attribute 17 8 17BC5CC5 1w2d: Attribute 6 6 00000005 1w2d: RADIUS: Received from id 151 10.22.2.1:1645, Change-Password-Accept, len 2 0 1w2d: AAA/AUTHEN (2502004780): status = PASS
You can access the most current Cisco documentation on the World Wide Web at http://www.cisco.com, http://www-china.cisco.com, or http://www-europe.cisco.com.
Cisco documentation and additional literature are available in a CD-ROM package, which ships with your product. The Documentation CD-ROM is updated monthly. Therefore, it is probably more current than printed documentation. The CD-ROM package is available as a single unit or as an annual subscription.
Registered CCO users can order the Documentation CD-ROM and other Cisco Product documentation through our online Subscription Services at http://www.cisco.com/cgi-bin/subcat/kaojump.cgi.
Nonregistered CCO users can order documentation through a local account representative by calling Cisco's corporate headquarters (California, USA) at 408 526-4000 or, in North America, call 800 553-NETS (6387).
Cisco provides Cisco Connection Online (CCO) as a starting point for all technical assistance. Warranty or maintenance contract customers can use the Technical Assistance Center. All customers can submit technical feedback on Cisco documentation using the web, e-mail, a self-addressed stamped response card included in many printed docs, or by sending mail to Cisco.
Cisco continues to revolutionize how business is done on the Internet. Cisco Connection Online is the foundation of a suite of interactive, networked services that provides immediate, open access to Cisco information and resources at anytime, from anywhere in the world. This highly integrated Internet application is a powerful, easy-to-use tool for doing business with Cisco.
CCO's broad range of features and services helps customers and partners to streamline business processes and improve productivity. Through CCO, you will find information about Cisco and our networking solutions, services, and programs. In addition, you can resolve technical issues with online support services, download and test software packages, and order Cisco learning materials and merchandise. Valuable online skill assessment, training, and certification programs are also available.
Customers and partners can self-register on CCO to obtain additional personalized information and services. Registered users may order products, check on the status of an order and view benefits specific to their relationships with Cisco.
You can access CCO in the following ways:
You can e-mail questions about using CCO to cco-team@cisco.com.
The Cisco Technical Assistance Center (TAC) is available to warranty or maintenance contract customers who need technical assistance with a Cisco product that is under warranty or covered by a maintenance contract.
To display the TAC web site that includes links to technical support information and software upgrades and for requesting TAC support, use www.cisco.com/techsupport.
To contact by e-mail, use one of the following:
| Language | E-mail Address |
|---|---|
English | tac@cisco.com |
Hanzi (Chinese) | chinese-tac@cisco.com |
Kanji (Japanese) | japan-tac@cisco.com |
Hangul (Korean) | korea-tac@cisco.com |
Spanish | tac@cisco.com |
Thai | thai-tac@cisco.com |
In North America, TAC can be reached at 800 553-2447 or 408 526-7209. For other telephone numbers and TAC e-mail addresses worldwide, consult the following web site: http://www.cisco.com/warp/public/687/Directory/DirTAC.shtml.
If you are reading Cisco product documentation on the World Wide Web, you can submit technical comments electronically. Click Feedback in the toolbar and select Documentation. After you complete the form, click Submit to send it to Cisco.
You can e-mail your comments to bug-doc@cisco.com.
To submit your comments by mail, for your convenience many documents contain a response card behind the front cover. Otherwise, you can mail your comments to the following address:
Cisco Systems, Inc.
Document Resource Connection
170 West Tasman Drive
San Jose, CA 95134-9883
We appreciate and value your comments.
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Posted: Fri May 5 15:05:17 PDT 2000
Copyright 1989 - 2000©Cisco Systems Inc.