Wireless Edge Services xl Module Release Notes WS.02.27

Table Of Contents
14
Support Notes
Release WS.02.07
Configuring Authentication for Web-Users
Note
Use this section to supplement the information in the chapter “Configuring the ProCurve Wireless
Edge Services xl Module” of the Management and Configuration Guide (5013-5912, May 2007).
Instead of (or in addition to) using the local list to authenticate users, you can use a RADIUS server.
If the RADIUS server authenticates a user, that user has the rights configured on the RADIUS
database.
Make sure that the configuration on the RADIUS server meets these requirements:
The user’s password is at least 8 characters.
SNMP v3 requires a password of at least this length. Your RADIUS server, however, may or may
not enforce such a requirement. (For example, the Wireless Edge Services xl Module’s internal
server does not.) Check the accounts for users that need management access to the module and,
if necessary, set a new password of the correct length.
The RADIUS server supports vendor specific attributes (VSAs).
For the RADIUS server to properly authorize the management user, you must set two VSAs in
the policy that the RADIUS server uses to authenticate the user. Table 3 shows the proper values
for the “HP-Management-Protocol” and the “HP-Management-Role” attributes.
Table 1. VSAs for Authorizing Management Users
Attribute Type Length Vendor ID Vendor Type Vendor
Length
Format Vendor Value
Decimal Format
HP-Management-
Protocol
26 12 11
(HP)
4
(HP-Management-
Protocol)
6 Decimal 5 = HTTP
6 = HTTPS
HP-Management-
Role
26 12 11 1
(HP-Management-
Role)
6 Decimal 1 = SuperUser
2 = Monitor
16 = HelpDesk
Manager
17 = Network Admin-
istrator
18 = System Adminis-
trator
19 = WebUser Admin-
istrator