Administrator Guide

Security Commands 885
ip https authentication
Use the ip https authentication command in Global Configuration mode to
specify authentication methods for users authenticating over HTTPS. To
return to the default configuration, use the no form of this command.
Syntax
ip https authentication method1 [method2...]
no ip https authentication
method1 [method2...] — Specify at least one from the following table:
Default Configuration
The local user database is checked. This action has the same effect as the
command ip https authentication local.
Command Mode
Global Configuration mode
User Guidelines
The additional methods of authentication are used only if the previous
method returns an error, not if it fails. To ensure that the authentication
succeeds even if all methods return an error, specify none as the final method
in the command line. If none is specified as an authentication method after
radius, no authentication is used if the RADIUS server is down.
When using a Cisco ACS with TACACS+ as the authentication method for
HTTPS, the Cisco ACS must be configured to allow the shell service. In
addition, for admin privileges, the privilege level attribute must be set to 15.
Keyword Source or destination
local Uses the local username database for authentication.
none Uses no authentication.
radius Uses the list of all RADIUS servers for authentication.
tacacs Uses the list of all TACACS+ servers for authentication.