Users Guide

172 Fabric OS Administrator’s Guide
53-1002920-02
Remote authentication
6
Fabric OS users on the RADIUS server
All existing Fabric OS mechanisms for managing local-switch user accounts and passwords remain
functional when the switch is configured to use RADIUS. Changes made to the local switch
database do not propagate to the RADIUS server, nor do the changes affect any account on the
RADIUS server.
Windows 2000 IAS
To configure a Windows 2000 Internet authentication service (IAS) server to use VSA to pass the
admin role to the switch in the dial-in profile, the configuration specifies the Vendor code (1588),
Vendor-assigned attribute number (1), and attribute value (admin), as shown in Figure 10.
Vendor type 1 1 octet, Brocade-Auth-Role; valid attributes for the Brocade-Auth-Role are:
Admin
BasicSwitchAdmin
FabricAdmin
Operator
SecurityAdmin
SwitchAdmin
User
ZoneAdmin
2 Optional: Specifies the Admin Domain or Virtual Fabric member list. For
more information on Admin Domains or Virtual Fabrics, refer to “RADIUS
configuration with Admin Domains or Virtual Fabrics” on page 173.
Brocade-AVPairs1
3Brocade-AVPairs2
4Brocade-AVPairs3
5Brocade-AVPairs4
6Brocade Password ExpiryDate
7Brocade Password ExpiryWarning
Vendor length 2 or higher 1 octet, calculated by server, including vendor-type and vendor-length
Attribute-specific data ASCII string Multiple octet, maximum 253, indicating the name of the assigned role and
other supported attribute values such as Admin Domain member list.
TABLE 23 Syntax for VSA-based account roles (Continued)
Item Value Description