[tac_plus] PAM authentication issue with TAC_PLUS

Klaus_Peters at mckinsey.com Klaus_Peters at mckinsey.com
Fri May 9 14:46:52 UTC 2008


Hi,

First of all - thank you for the development of the Tacacs+ daemon - I've 
been using it for quite some time and it has proven to be a very stable, 
nice piece of software.

I am looking for Directoy integration of the Cisco login and woul like to 
use PAM authentication.

The documentation says this can be accomplished by :

4). Authentication using PAM (Pluggable Authentication Modules)

Assuming that your OS supports it, tac_plus can be configured to use PAM
for authentication, which may make it possible to use LDAP, SecureID, etc
if you have the appropriate PAM module.  Use may require configuration of
the PAM libraries themselves; see their documentation.

    user = fred {
      login = PAM
    }


what I am getting when putting login = PAM into the config file is:

tac_plus -C /etc/tacacs/tacacs.conf -l /var/log/tac_plus.log
Error: expecting 'file', 'cleartext', 'nopassword', or 'des' keyword after 
'login =' on line 33

Can you please shed some light on this error?
Do I have to set the PAM support during compilation?

thanks and regards
        Klaus Peters

+=========================================================+
This message may contain confidential and/or privileged
information.  If you are not the addressee or authorized to
receive this for the addressee, you must not use, copy,
disclose or take any action based on this message or any
information herein.  If you have received this message in
error, please advise the sender immediately by reply e-mail
and delete this message.  Thank you for your cooperation.
+=========================================================+
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.shrubbery.net/pipermail/tac_plus/attachments/20080509/2a4d6793/attachment.html 


More information about the tac_plus mailing list