Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: tac_plus and authentication
From: Corneliu Tanasa <cornel @ logicnet . ro>
Date: Tue, 25 Feb 1997 20:50:51 +0200 (EET)
To: Jean Chess <jchess @ telerama . lm . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <Pine . 3 . 89 . 9702250811 . A5804-0100000 @ bosconian . lm . com>

-----BEGIN PGP SIGNED MESSAGE-----

On Tue, 25 Feb 1997, Jean Chess wrote:

Jean,

I think that I can add something at your list:
  How can I disable the possibility of two (or more) concurent logins using 
the same userID?

> 
> I have tac_plus 2.1 running for authentication with a Cisco comm server.
> 
> There are a couple features that I don't think it is possible to 
> implement with the tac_plus code as is - Any comments/suggestions?
> 
>   - lock out users after n successive failures
>     I know how to configure the cisco to kick them out after attempts,
>     but I don't think there is anyway with just tac_plus to also disable
>     the user account on the tacacs server.
> 
>   - pre-expire/age passwords and allow users to change them
>     When I set an account as expired in the config file, it is
>     simply invalid - can't figure out any way to warn user and query
>     for a new password. 
> 
> I think the Shiva and CiscoSecure provide these options - but I assume 
> they do it through enhanced code.
> 
> 
> Thanks
> 
> Jean
> 
> Jean Chess
> RPM Associates, Inc.
> Pager: 800-504-8235
> 
> 


Corneliu Tanasa
Network Administrator - LOGIC TELECOM SA

Phone: +40-1-3213635
Fax:   +40-1-3213730
e-mail: <cornel @
 logicnet .
 ro>
        <corneliu .
 tanasa @
 alliance-partners .
 sprint .
 com>
PGP Key at: <http://swissnet.ai.mit.edu:11371/pks/lookup?op=get&search=0x41C3DBE9>


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQB1AwUBMxM0jS4fmj5Bw9vpAQF4lgMAl2NDMmd1msKh2gIvUrNqls1JQtR+4NoH
nABqaQEmLsJ2m7t9TEWhWsSU83Y+Al3k7pbTB5UF0w7kkBzh/IzGhpxWoWIeBDF3
/CVzS1izozNem88tqYEOOOjxVmn8ltVn
=YVjy
-----END PGP SIGNATURE-----


References:
Indexed By Date Previous: RE: Firewalls-Digest V6 #76
From: "Hicks, Rick" <RHicks @ hussmann . com>
Next: Re: Firewall Sparc platforms?y
From: Mike Shaver <shaver @ neon . ingenia . ca>
Indexed By Thread Previous: tac_plus and authentication
From: Jean Chess <jchess @ telerama . lm . com>
Next: List for all types of tools
From: "Mooney, Mike" <Mike_Mooney @ tds . com>

Google
 
Search Internet Search www.greatcircle.com