Rsa-security 6.1 User Manual

Browse online or download User Manual for Computers Rsa-security 6.1. RSA Security 6.1 User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 118
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - Administrator’s Guide

RSA RADIUS Server 6.1Administrator’s GuidePowered by Steel-Belted Radius®

Page 2 - Copyright

x About This Guide September 2005X Chapter 4, “Administering RADIUS Clients,” describes how to set up remote access server (RAS) devices as RSA RADIUS

Page 3 - Trademarks

88 Using the LDAP Configuration Interface September 2005Figure 29 LDAP Schema (Slide 4 of 4)While the LDAP virtual schema diagram shows as much of the

Page 4 - RSA notice

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 89X Substrings – There are several places where a list of strings i

Page 5 - Contents

90 Using the LDAP Configuration Interface September 2005LDAP Command ExamplesThis section explains how to use the LDAP commands ldapdelete, ldapmodify

Page 6

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 91Modifying RecordsYou can use the ldapmodify command to modify the

Page 7 - Chapter 8 Logging

92 Using the LDAP Configuration Interface September 2005NOTE: You can also use the -h option with ldapmodify to specify the name of a remote host on w

Page 8

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 93The following syntax is valid if the same keyword applies through

Page 9 - About This Guide

94 Using the LDAP Configuration Interface September 2005changetype: add. Once your editing is complete, run an ldapmodify -f command that references t

Page 10 - Syntax Conventions

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 95This file can be passed to the ldapmodify command as follows:ldap

Page 11 - Related Documentation

96 Using the LDAP Configuration Interface September 2005high-auth-threads: 2high-acct-threads: 0high-total-threads: 2stattype: authenticationdn: statt

Page 12 - Getting Support and Service

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 97Rate StatisticsRate statistics are derived from other statistics

Page 13 - About RSA RADIUS Server

RSA RADIUS Server 6.1 Administrator’s Guide About This Guide xiX Angle brackets < > enclose a list from which you must choose an item in format

Page 14 - RSA RADIUS Server Overview

98 Using the LDAP Configuration Interface September 2005

Page 15

RSA RADIUS Server 6.1 Administrator’s Guide Glossary 99Glossary802.1X The IEEE 802.1X standard defines a mechanism that allows a supplicant (client) t

Page 16 - RADIUS Packets

100 Glossary September 2005CA Certificate authority. A trusted entity that registers the digital identity of a site or individual and issues a digital

Page 17 - RADIUS Configuration

RSA RADIUS Server 6.1 Administrator’s Guide Glossary 101IETF Internet Engineering Task Force. Technical subdivision of the Internet Architecture Board

Page 18 - Shared Secrets

102 Glossary September 2005information about users and administering multiple security systems across complex networks.RAS Remote Access Server. Netwo

Page 19 - Node Secret

RSA RADIUS Server 6.1 Administrator’s Guide Glossary 103tokencode The pseudorandom number that is displayed on the LCD of a hardware token or generate

Page 20 - Authentication

104 Glossary September 2005

Page 21 - Accounting

RSA RADIUS Server 6.1 Administrator’s Guide Index 105IndexNumerics802.1X 1Aaccess client 3accounting 2Acct-Authentic 79Acct-Delay-Time 79Acct-Status-T

Page 22 - Accounting Sequence

106 Index September 2005Protected Extensible Authentication Protocol (PEAP)1Protected One-Time Password (POTP) 1Protected One-Time Password, see POTPR

Page 23 - Tunneled Accounting

xii About This Guide September 2005X Internet-Draft, “The Protected One-Time Password Protocol (EAP-POTP)”, M. Nystrom, June 2005. ftp://ftp.rsasecuri

Page 24 - Attributes

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 1Chapter 1About RSA RADIUS ServerRSA RADIUS Server is a complete implementation of

Page 25 - Attribute Lists

2 About RSA RADIUS Server September 2005X Centralized configuration management (CCM) provides simplified configuration management and automatic data d

Page 26 - Attribute Values

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 3Figure 1 RSA RADIUS Authentication1A RADIUS access client, who could be a dial-in

Page 27 - Default Values

4 About RSA RADIUS Server September 2005If the user ID is not found or if the passcode is not appropriate for the specified user, the RSA Authenticati

Page 28

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 5Each RADIUS packet supports a specific purpose: authentication or accounting. A p

Page 29

6 About RSA RADIUS Server September 2005X The RADIUS shared secret to be used by the RSA RADIUS Server and the client device. For information on RADIU

Page 30

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 7RADIUS SecretA RADIUS shared secret is a case-sensitive password used to validate

Page 31 - Chapter 2

Contact InformationSee our web site for regional Customer Support telephone and fax numbers.RSA Security Inc. RSA Security Ireland Limitedwww.rsasecur

Page 32 - Installing on Windows

8 About RSA RADIUS Server September 2005The RSA Authentication Manager software views the RSA RADIUS Server service as a host agent. Communication bet

Page 33

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 9AccountingTo understand the RSA RADIUS Server accounting sequence, you need an ov

Page 34

10 About RSA RADIUS Server September 2005Accounting SequenceA RAS can issue an Accounting-Request whenever it chooses, for example upon establishing a

Page 35 - Installing on Solaris

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 11Tunneled AccountingDuring authentication, a user is typically identified by attr

Page 36 - , and sdconf.rec files

12 About RSA RADIUS Server September 20056 The server processes the accounting request locally.To implement tunneled accounting, you must configure th

Page 37

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 13nonstandard attributes that it encounters in the packet. Standard RADIUS attribu

Page 38

14 About RSA RADIUS Server September 2005During authentication, RSA RADIUS Server filters the checklist based on the dictionary for the RADIUS client

Page 39

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 15Framed-Compression attribute to appear twice in the return list: once with the v

Page 40 - Migration Log File

16 About RSA RADIUS Server September 2005If an attribute appears once in the checklist marked as default, and the same attribute appears in the return

Page 41 - Installing on Linux

RSA RADIUS Server 6.1 Administrator’s Guide About RSA RADIUS Server 17The Primary RADIUS Server maintains a list of the Replica RADIUS Servers that ha

Page 42

• Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation

Page 43

18 About RSA RADIUS Server September 2005Recovering a Replica After a Failed DownloadIf a Replica RADIUS Server fails during the download of a configu

Page 44

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 19Chapter 2Installing the RSA RADIUS ServerThe RSA RADIUS Server software

Page 45

20 Installing the RSA RADIUS Server September 2005attributes, and return list attributes; and RSA SecurID prompts used to format messages to users.Dat

Page 46

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 21Installing the RSA RADIUS ServerTo install the RSA RADIUS Server softwa

Page 47 - Chapter 3

22 Installing the RSA RADIUS Server September 2005click the Browse button to locate the directory containing the sdconf.rec, radius.cer, server.cer, a

Page 48 - Content Frame

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 23Installing on SolarisThis section describes how to install and uninstal

Page 49 - Panel Menu

24 Installing the RSA RADIUS Server September 2005-identitySpecifies whether you are installing a Primary or Replica RADIUS Server.Valid values are PR

Page 50 - Help Menu

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 25Installing the RSA RADIUS Server SoftwareThe following procedure descri

Page 51 - Adding an Entry

26 Installing the RSA RADIUS Server September 20055 Specify the directory where you want to install the RSA RADIUS Server files.By default, the instal

Page 52 - Editing an Entry

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 27Enter primary host secret:13 If you are installing a Primary RADIUS Ser

Page 53 - Figure 7 Sample Edit Window

Sun Microsystems, Solaris, and all Sun-based trademarks and logos, Java, HotJava, JavaScript, the Java Coffee Cup Logo, and all Java-based trademarks

Page 54 - Using Context Menus

28 Installing the RSA RADIUS Server September 20055 Type y when you are asked to confirm that you want to uninstall the RSA RADIUS Server software.Con

Page 55 - Adding a License Key

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 29Installing on LinuxThis section describes how to install and uninstall

Page 56 - File > Exit

30 Installing the RSA RADIUS Server September 2005-identitySpecifies whether you are installing a Primary or Replica RADIUS Server.Valid values are PR

Page 57 - Administering RADIUS Clients

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 31Installing the RSA RADIUS Server SoftwareThe following procedure descri

Page 58 - Adding a RADIUS Client

32 Installing the RSA RADIUS Server September 20055 Specify the directory where you want to install the RSA RADIUS Server files.By default, the instal

Page 59 - button

RSA RADIUS Server 6.1 Administrator’s Guide Installing the RSA RADIUS Server 3312 Specify the host secret used to authenticate communication between t

Page 60 - Deleting a RADIUS Client

34 Installing the RSA RADIUS Server September 2005Uninstalling the RSA RADIUS Server SoftwareTo uninstall the RSA RADIUS Server software:1 Stop the RA

Page 61 - 3 Click the

RSA RADIUS Server 6.1 Administrator’s Guide Using RSA RADIUS Administrator 35Chapter 3Using RSA RADIUS AdministratorThe RSA RADIUS Administrator is a

Page 62

36 Using RSA RADIUS Administrator September 2005Navigating in RSA RADIUS AdministratorFigure 4 illustrates the RSA RADIUS Administrator user interface

Page 63 - Administering Profiles

RSA RADIUS Server 6.1 Administrator’s Guide Using RSA RADIUS Administrator 37Panel MenuTable 9 describes the functions of each entry in the Panel menu

Page 64 - Default Profile

RSA RADIUS Server 6.1 Administrator’s Guide Contents vContentsAbout This GuideAudience ...

Page 65 - Setting Up Profiles

38 Using RSA RADIUS Administrator September 2005Web MenuTable 10 describes the functions of each entry in the Web menu in the RSA RADIUS Administrator

Page 66

RSA RADIUS Server 6.1 Administrator’s Guide Using RSA RADIUS Administrator 39Figure 5 RSA RADIUS Administrator ToolbarRSA RADIUS Administrator Windows

Page 67 - Removing a Profile

40 Using RSA RADIUS Administrator September 2005RSA RADIUS Administrator displays an Add window. A sample Add window appears in Figure 6.Figure 6 Samp

Page 68

RSA RADIUS Server 6.1 Administrator’s Guide Using RSA RADIUS Administrator 41Figure 7 Sample Edit WindowCutting/Copying/Pasting RecordsPanels displayi

Page 69 - Displaying Statistics

42 Using RSA RADIUS Administrator September 2005Figure 8 Sample Paste WindowResizing ColumnsYou can resize columns in an RSA RADIUS Administrator tabl

Page 70

RSA RADIUS Server 6.1 Administrator’s Guide Using RSA RADIUS Administrator 43If you right-click a blank area in an RSA RADIUS Administrator window, th

Page 71

44 Using RSA RADIUS Administrator September 20053 When the Add a License for Server window (Figure 10) opens, enter the license key and click OK.When

Page 72 - System tab

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Clients 45Chapter 4Administering RADIUS ClientsA RADIUS client is a network device or

Page 73

46 Administering RADIUS Clients September 2005Adding a RADIUS ClientTo add a RADIUS client:1 Open the RADIUS Clients panel.2 Click the Add button.The

Page 74 - Resetting Server Statistics

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Clients 474 Enter the IP address or DNS name of the RADIUS client in the IP Address f

Page 75 - Refresh button in the

vi Contents September 2005Chapter 2 Installing the RSA RADIUS ServerBefore You Begin...

Page 76

48 Administering RADIUS Clients September 2005d Click OK.You must enter the same accounting shared secret when you configure the RADIUS client. 8 Opti

Page 77 - Administering RADIUS Servers

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Clients 492 Select the RADIUS client entry you want to delete.3 Click the Delete butt

Page 78 - Replication Panel

50 Administering RADIUS Clients September 2005

Page 79 - Figure 22 Add Server Window

RSA RADIUS Server 6.1 Administrator’s Guide Administering Profiles 51Chapter 5Administering ProfilesThis chapter describes how to set up and administe

Page 80 - Deleting a RADIUS Server

52 Administering Profiles September 2005Resolving Profile and User AttributesIf user-specific attributes are stored in the RSA Authentication Manager

Page 81 - Notify button on the toolbar

RSA RADIUS Server 6.1 Administrator’s Guide Administering Profiles 53Setting Up ProfilesThe Profiles panel (Figure 15) lets you define standard sets o

Page 82

54 Administering Profiles September 20054 Optionally, enter a description for the profile in the Description field.5 Add checklist and return list att

Page 83

RSA RADIUS Server 6.1 Administrator’s Guide Administering Profiles 55f When you are finished adding attribute/value pairs, click Close to return to th

Page 84 - Regenerating a Node Secret

56 Administering Profiles September 2005

Page 85 - Resetting the RADIUS Database

RSA RADIUS Server 6.1 Administrator’s Guide Displaying Statistics 57Chapter 6Displaying StatisticsThe Statistics panel lets you display statistics for

Page 86

RSA RADIUS Server 6.1 Administrator’s Guide Contents viiChapter 5 Administering ProfilesAbout Profiles ...

Page 87 - Chapter 8

58 Displaying Statistics September 2005Figure 18 Statistics Panel: System Authentication Statistics Table 13 explains the fields on the Authentication

Page 88 - Controlling Log File Size

RSA RADIUS Server 6.1 Administrator’s Guide Displaying Statistics 59Silent Discards The number of requests in which the client could not be identified

Page 89 - Using the Accounting Log

60 Displaying Statistics September 2005Displaying Server Accounting StatisticsAccounting statistics provide information such as the number of transact

Page 90 - Comma Placeholders

RSA RADIUS Server 6.1 Administrator’s Guide Displaying Statistics 61Table 14 describes the accounting statistics and suggested actions in italics (if

Page 91

62 Displaying Statistics September 2005Resetting Server StatisticsTo reset authentication and accounting statistics for an RSA RADIUS server to zero:1

Page 92

RSA RADIUS Server 6.1 Administrator’s Guide Displaying Statistics 635 Optionally, sort the messages by clicking a column header.NOTE: The RADIUS clien

Page 93 - Using the LDAP Configuration

64 Displaying Statistics September 2005

Page 94

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Servers 65Chapter 7Administering RADIUS ServersRSA RADIUS Server supports the replica

Page 95 - LDAP Requests

66 Administering RADIUS Servers September 2005Replication PanelThe Replication panel (Figure 21) lists your Primary and Replica RADIUS Servers and ind

Page 96 - Configuring the LDAP TCP Port

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Servers 67Figure 22 Add Server Window3 Enter the name of the RADIUS server in the Nam

Page 97 - LDAP Virtual Schema

viii Contents September 2005Appendix A Using the LDAP Configuration InterfaceLDAP Configuration Interface File ...

Page 98

68 Administering RADIUS Servers September 2005Enabling a RADIUS ServerTo enable a RADIUS server:1 Open the Replication panel.2 Select the RADIUS serve

Page 99

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Servers 69Publishing Server Configuration InformationIf you change the configuration

Page 100

70 Administering RADIUS Servers September 2005Designating a New Primary RADIUS ServerYou can change which server within a realm is designated as the P

Page 101

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Servers 712 Log into the Replica RADIUS Server as root (Solaris/Linux) or administrat

Page 102 - LDAP Command Examples

72 Administering RADIUS Servers September 20054 Run the rsainstalltool (Windows) or rsaconfiguretool (Solaris/Linux) utility with the identity option.

Page 103 - Modifying Records

RSA RADIUS Server 6.1 Administrator’s Guide Administering RADIUS Servers 73To regenerate the node secret for a a Replica RADIUS Server, enter the foll

Page 104

74 Administering RADIUS Servers September 2005

Page 105 - Adding Records

RSA RADIUS Server 6.1 Administrator’s Guide Logging 75Chapter 8LoggingThis chapter describes how to set up and use logging functions in RSA RADIUS Ser

Page 106 - Deleting Records

76 Logging September 2005Level of Logging DetailYou can control the level of detail recorded in the system log files with LogLevel, LogAccept, and Log

Page 107 - Statistics Variables

RSA RADIUS Server 6.1 Administrator’s Guide Logging 77By default, RADIUS system log files are located in the RADIUS database directory. You can specif

Page 108

RSA RADIUS Server 6.1 Administrator’s Guide About This Guide ixAbout This GuideThe RSA RADIUS Server 6.1 Administrator’s Guide describes how to instal

Page 109 - Rate Statistics

78 Logging September 2005You can edit the account.ini initialization file to add, remove or reorder the standard RADIUS or vendor-specific attributes

Page 110

RSA RADIUS Server 6.1 Administrator’s Guide Logging 79aligned with their headings. For example, based on the “first line” of headings described above,

Page 111 - Glossary

80 Logging September 2005Acct-Input-PacketsNumber of packets received by the port over the connection; present only in STOP records.Acct-Output-Packet

Page 112 - 100 Glossary September 2005

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 81Appendix AUsing the LDAP ConfigurationInterfaceThe LDAP Configura

Page 113

82 Using the LDAP Configuration Interface September 2005About the LDAP Configuration InterfaceThe LDAP Configuration Interface (LCI) consists of an LD

Page 114 - 102 Glossary September 2005

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 83in a specified file. Because ldapmodify uses LDIF update statemen

Page 115

84 Using the LDAP Configuration Interface September 2005Z nsldapssl32v30.dll (if you are on a Windows host)Z libldap30.so (if you are on a Solaris hos

Page 116 - 104 Glossary September 2005

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 85199.198.197.196196.197.198.199If the [LDAPAddresses] section is o

Page 117

86 Using the LDAP Configuration Interface September 2005Figure 27 LDAP Schema (Slide 2 of 4)cn=adminradiusstatus=sessions_by_calling_stationcalling-st

Page 118 - 106 Index September 2005

RSA RADIUS Server 6.1 Administrator’s Guide Using the LDAP Configuration Interface 87Figure 28 LDAP Schema (Slide 3 of 4)Available Attributes:accept &

Comments to this Manuals

No comments