<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS+ enable authentication 2500 Series in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347748#M17252</link>
    <description>Hello everyone,&lt;BR /&gt;&lt;BR /&gt;I was curious if anyone has any experience or similar issues.  Here is the problem:&lt;BR /&gt;&lt;BR /&gt;I can enable tacacs on the switch with:&lt;BR /&gt;&lt;BR /&gt;aaa authentication telnet login tacacs local &lt;BR /&gt;aaa authentication telnet enable tacacs local &lt;BR /&gt;tacacs-server key password &lt;BR /&gt;tacacs-server host 10.10.10.151&lt;BR /&gt;&lt;BR /&gt;and I can telnet into the device using my credentials.  But when I attempt to enable myself with the same credentials I'm told the password is incorrect.&lt;BR /&gt;&lt;BR /&gt;The TACACS server we use is from: &lt;A href="http://www.shrubbery.net/tac_plus/" target="_blank"&gt;http://www.shrubbery.net/tac_plus/&lt;/A&gt; and we use this one so we can auth against an LDAP/Kerberos setup.&lt;BR /&gt;&lt;BR /&gt;Here are the logs from our TACACS servers:&lt;BR /&gt;&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_value: name= isuser=1 attr=enable rec=1&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_value: no user/group named&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_pvalue: returns NULL&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_hvalue: name=10.10.10.156 attr=enable&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_phvalue: returns cleartext password&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: verify daemon password == NAS supersecretpassword&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: Password is incorrect&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: enable query for 'unknown' unknown from 10.10.10.156 rejected&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_hvalue: name=10.10.10.156 attr=key&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_phvalue: returns password&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The TACACS server is a production server and is known to work.&lt;BR /&gt;&lt;BR /&gt;If anyone has any insight or any further questions, please let me know.</description>
    <pubDate>Thu, 29 Jan 2009 17:53:20 GMT</pubDate>
    <dc:creator>switchtower</dc:creator>
    <dc:date>2009-01-29T17:53:20Z</dc:date>
    <item>
      <title>TACACS+ enable authentication 2500 Series</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347748#M17252</link>
      <description>Hello everyone,&lt;BR /&gt;&lt;BR /&gt;I was curious if anyone has any experience or similar issues.  Here is the problem:&lt;BR /&gt;&lt;BR /&gt;I can enable tacacs on the switch with:&lt;BR /&gt;&lt;BR /&gt;aaa authentication telnet login tacacs local &lt;BR /&gt;aaa authentication telnet enable tacacs local &lt;BR /&gt;tacacs-server key password &lt;BR /&gt;tacacs-server host 10.10.10.151&lt;BR /&gt;&lt;BR /&gt;and I can telnet into the device using my credentials.  But when I attempt to enable myself with the same credentials I'm told the password is incorrect.&lt;BR /&gt;&lt;BR /&gt;The TACACS server we use is from: &lt;A href="http://www.shrubbery.net/tac_plus/" target="_blank"&gt;http://www.shrubbery.net/tac_plus/&lt;/A&gt; and we use this one so we can auth against an LDAP/Kerberos setup.&lt;BR /&gt;&lt;BR /&gt;Here are the logs from our TACACS servers:&lt;BR /&gt;&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_value: name= isuser=1 attr=enable rec=1&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_value: no user/group named&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_pvalue: returns NULL&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_hvalue: name=10.10.10.156 attr=enable&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_phvalue: returns cleartext password&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: verify daemon password == NAS supersecretpassword&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: Password is incorrect&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: enable query for 'unknown' unknown from 10.10.10.156 rejected&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_hvalue: name=10.10.10.156 attr=key&lt;BR /&gt;Thu Jan 29 12:41:21 2009 [7533]: cfg_get_phvalue: returns password&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The TACACS server is a production server and is known to work.&lt;BR /&gt;&lt;BR /&gt;If anyone has any insight or any further questions, please let me know.</description>
      <pubDate>Thu, 29 Jan 2009 17:53:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347748#M17252</guid>
      <dc:creator>switchtower</dc:creator>
      <dc:date>2009-01-29T17:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ enable authentication 2500 Series</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347749#M17253</link>
      <description>Some things to try to isolate:&lt;BR /&gt;&lt;BR /&gt;set primary auth source for enable to be local &lt;BR /&gt;set primary auth source for login to be local.&lt;BR /&gt;&lt;BR /&gt;Does enable work in both cases?&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Feb 2009 02:38:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347749#M17253</guid>
      <dc:creator>Tabasco</dc:creator>
      <dc:date>2009-02-04T02:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ enable authentication 2500 Series</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347750#M17254</link>
      <description>I see the same problem - looks like the procurve is not sending the username in the enable packet (i.e. user is unknown as opposed to 'czane'): &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Fri Mar 20 14:30:04 2009 [3607]: connect from 128.171.132.112 [128.171.132.112]&lt;BR /&gt;Fri Mar 20 14:30:06 2009 [3607]: login query for 'czane' unknown-port from 128.171.132.112 accepted&lt;BR /&gt;Fri Mar 20 14:30:07 2009 [3602]: session.peerip is 128.171.132.112&lt;BR /&gt;Fri Mar 20 14:30:07 2009 [3608]: connect from 128.171.132.112 [128.171.132.112]&lt;BR /&gt;Fri Mar 20 14:30:09 2009 [3608]: enable query for 'unknown' unknown from 128.171.132.112 rejected&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;A cisco switch works fine (i.e. user in the enable query is 'czane'): &lt;BR /&gt;&lt;BR /&gt;Fri Mar 20 14:29:46 2009 [3603]: connect from 128.171.132.114 [128.171.132.114]&lt;BR /&gt;Fri Mar 20 14:29:48 2009 [3603]: login query for 'czane' tty2 from 128.171.132.114 accepted&lt;BR /&gt;Fri Mar 20 14:29:49 2009 [3602]: session.peerip is 128.171.132.114&lt;BR /&gt;Fri Mar 20 14:29:49 2009 [3604]: connect from 128.171.132.114 [128.171.132.114]&lt;BR /&gt;Fri Mar 20 14:29:51 2009 [3604]: enable query for 'czane' tty2 from 128.171.132.114 accepted&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Is this a bug with the procurve tacacs implementation? This "feature" is holding me up from recommending these switches to deploy on our campus.&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Mar 2009 17:22:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/tacacs-enable-authentication-2500-series/m-p/4347750#M17254</guid>
      <dc:creator>Chris Zane</dc:creator>
      <dc:date>2009-03-24T17:22:21Z</dc:date>
    </item>
  </channel>
</rss>

