[tac_plus] Re: Error Cannot generate skey prompt for USER

john heasley heas at shrubbery.net
Sat Jun 2 07:04:44 UTC 2007


Fri, Jun 01, 2007 at 06:53:46PM -0300, ninjabytes:
> Hi folks,
> 
> I have installed tac_plus version F4.0.4.alpha on my OpenBSD 4.1-STABLE BOX.
> 
> Below is my /etc/tac_plus.conf config file:
> 
> user = john {
> login = skey
> }
> 
> When i run tac_plus in debug mode and I telnet in my router which uses that
> tacacs server I get the following error message:

does that mean it works when not in debug mode?

> Jun  1 14:49:51 angor tac_plus[12374]: Error Cannot generate skey prompt for
> angel
> on the router side I dont get the SKEY chalenge but a regular Login and
> Password I think thats why tacacs complains and gives me that error.
> 
> is there any "specifical" config that needs to be done on the router side to
> tell it to use "skey" with tacacs? What could be causing this?

does skey work outside of tacacs?  ie: skeyinfo  skey itself does require
some config/initialization.


More information about the tac_plus mailing list