<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for TACACS+ stuff</title>
	<atom:link href="http://tacacs.org/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://tacacs.org</link>
	<description>Casting Light on the Dark Art of TACACS+</description>
	<lastBuildDate>Fri, 26 Feb 2010 00:49:45 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by helpdeskdan</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-533</link>
		<dc:creator>helpdeskdan</dc:creator>
		<pubDate>Fri, 26 Feb 2010 00:49:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-533</guid>
		<description>DanH - try &#039;DEFAULT&#039; instead of &#039;default&#039; in your tac_plus.conf

Skip - This code works by commands, not privilege levels.  Not that it couldn&#039;t be done, I just did not have a need at the time to modify the tac pairs.  You could take priv-lvl = 15 out of the config and deny &quot;enable&quot; to the users you don&#039;t want to enable.  Or, put them in a different group in tac_plus.conf, but that means you now have to modify two configuration files instead of one. 

The examples above were done in much haste, there might be errors; if other people are actually interested in this, I&#039;ll try to fix it up a bit.  My current employer doesn&#039;t use tac_plus, so I don&#039;t have a testing environment any more.</description>
		<content:encoded><![CDATA[<p>DanH &#8211; try &#8216;DEFAULT&#8217; instead of &#8216;default&#8217; in your tac_plus.conf</p>
<p>Skip &#8211; This code works by commands, not privilege levels.  Not that it couldn&#8217;t be done, I just did not have a need at the time to modify the tac pairs.  You could take priv-lvl = 15 out of the config and deny &#8220;enable&#8221; to the users you don&#8217;t want to enable.  Or, put them in a different group in tac_plus.conf, but that means you now have to modify two configuration files instead of one. </p>
<p>The examples above were done in much haste, there might be errors; if other people are actually interested in this, I&#8217;ll try to fix it up a bit.  My current employer doesn&#8217;t use tac_plus, so I don&#8217;t have a testing environment any more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by Skip</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-531</link>
		<dc:creator>Skip</dc:creator>
		<pubDate>Thu, 25 Feb 2010 21:39:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-531</guid>
		<description>Dan,
I would like to implement this but have a question first.
The way I would like to use it is, default user has no access and then set the privileged user according to their access level. Is there away to do that?</description>
		<content:encoded><![CDATA[<p>Dan,<br />
I would like to implement this but have a question first.<br />
The way I would like to use it is, default user has no access and then set the privileged user according to their access level. Is there away to do that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by DanH</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-507</link>
		<dc:creator>DanH</dc:creator>
		<pubDate>Wed, 17 Feb 2010 21:29:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-507</guid>
		<description>This doesn&#039;t appear to work with ASA 8.21 for command authorization. It just spits out; 2010-02-17 16:20:29: Error: Option &#039;default&#039; does not exist in section users in file /etc/tac_plus/do_auth.ini whenever trying to authorize commands.</description>
		<content:encoded><![CDATA[<p>This doesn&#8217;t appear to work with ASA 8.21 for command authorization. It just spits out; 2010-02-17 16:20:29: Error: Option &#8216;default&#8217; does not exist in section users in file /etc/tac_plus/do_auth.ini whenever trying to authorize commands.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Managing ScreenOS firewalls with TACACS+ by Dan</title>
		<link>http://tacacs.org/2008/10/16/managing-screenos-firewalls-with-tacacs/comment-page-1/#comment-484</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Tue, 09 Feb 2010 16:09:08 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/jpayne/?p=31#comment-484</guid>
		<description>Failover and Sourced IP is working in 6.3.0R2.0.</description>
		<content:encoded><![CDATA[<p>Failover and Sourced IP is working in 6.3.0R2.0.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by fever</title>
		<link>http://tacacs.org/about/comment-page-1/#comment-454</link>
		<dc:creator>fever</dc:creator>
		<pubDate>Thu, 14 Jan 2010 03:57:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?page_id=16#comment-454</guid>
		<description>Hello Dan I&#039;m a student at the IT UNIVERSITY and for my license I need to create and configure a TACACS Server can I get your e-mail please for some informations? Thank you.</description>
		<content:encoded><![CDATA[<p>Hello Dan I&#8217;m a student at the IT UNIVERSITY and for my license I need to create and configure a TACACS Server can I get your e-mail please for some informations? Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by helpdeskdan</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-450</link>
		<dc:creator>helpdeskdan</dc:creator>
		<pubDate>Sat, 09 Jan 2010 00:34:39 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-450</guid>
		<description>You can&#039;t get login = PAM working or can&#039;t get do_auth working?  do_auth is pretty trivial, getting PAM to work with active directory is much more difficult and I can&#039;t help you there.  (Have often suggested somebody write a tutorial)  Getting the two to work together should not be a problem as after authentication scripts are completely separate from the login process.</description>
		<content:encoded><![CDATA[<p>You can&#8217;t get login = PAM working or can&#8217;t get do_auth working?  do_auth is pretty trivial, getting PAM to work with active directory is much more difficult and I can&#8217;t help you there.  (Have often suggested somebody write a tutorial)  Getting the two to work together should not be a problem as after authentication scripts are completely separate from the login process.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by Jamie</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-449</link>
		<dc:creator>Jamie</dc:creator>
		<pubDate>Fri, 08 Jan 2010 20:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-449</guid>
		<description>I really like this and it would make building a front end simple.  My only issue is I use login = PAM and tie authentication back to our Active directory through pam_ldap.  Can&#039;t seem to get that working here, maybe i am missing something.</description>
		<content:encoded><![CDATA[<p>I really like this and it would make building a front end simple.  My only issue is I use login = PAM and tie authentication back to our Active directory through pam_ldap.  Can&#8217;t seem to get that working here, maybe i am missing something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by helpdeskdan</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-358</link>
		<dc:creator>helpdeskdan</dc:creator>
		<pubDate>Mon, 26 Oct 2009 23:54:20 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-358</guid>
		<description>Level 1?  The levels you authorize are set on the device it&#039;s self, they are not set set on the tacacs server.</description>
		<content:encoded><![CDATA[<p>Level 1?  The levels you authorize are set on the device it&#8217;s self, they are not set set on the tacacs server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Easier Tacacs Configurations with do_auth by Uffe Callesen</title>
		<link>http://tacacs.org/2009/09/26/easy-tacacs-control-with-do_auth/comment-page-1/#comment-357</link>
		<dc:creator>Uffe Callesen</dc:creator>
		<pubDate>Mon, 26 Oct 2009 11:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=60#comment-357</guid>
		<description>Excellent guide Dan ! There&#039;s one point that seems uncovered however. What if user Homer need access to specific commands not found on Level1 ?? Is there any way to handle that scenario ?</description>
		<content:encoded><![CDATA[<p>Excellent guide Dan ! There&#8217;s one point that seems uncovered however. What if user Homer need access to specific commands not found on Level1 ?? Is there any way to handle that scenario ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco Wireless Control System by Webs</title>
		<link>http://tacacs.org/2008/11/04/cisco-wireless-control-system/comment-page-1/#comment-19</link>
		<dc:creator>Webs</dc:creator>
		<pubDate>Wed, 10 Dec 2008 16:02:24 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.sackheads.org/tacacsplus/?p=23#comment-19</guid>
		<description>Try following &lt;a href=&quot;http://www.ciscosystems.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml&quot; rel=&quot;nofollow&quot;&gt;this site from Cisco for getting WCS on TACACS&lt;/a&gt;. This is what I did in our enterprise environment and we now have TACACS running on everything.</description>
		<content:encoded><![CDATA[<p>Try following <a href="http://www.ciscosystems.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml" rel="nofollow">this site from Cisco for getting WCS on TACACS</a>. This is what I did in our enterprise environment and we now have TACACS running on everything.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
