Lab Minutes Forum

Technical Discussion => Security => Topic started by: Administrator on August 29, 2014, 09:14:42 AM

Title: User Profile - ACS 5.X (on behalf of Michael)
Post by: Administrator on August 29, 2014, 09:14:42 AM
Can a service be created and attached to User Profiles? Our current implementation for Sandvine-Group = "sv_operator,sv_admin" on ACS 4.2 attaches it to User Profiles and was wondering if there's a way to replicate that for ACS 5.2. (Create a User Profile and attach the Custom attribues to that user). As an alternative, how would you recommend it be implemented? Thanks for your help on this matter. Kind Regards, Michael
Title: Re: User Profile - ACS 5.X (on behalf of Michael)
Post by: Administrator on August 29, 2014, 09:18:22 AM
In ACS 5, you can create per-user custom attribute and use them in authorization profile to replicate what you used to have in ACS 4.x. Please see the video below for example.

http://www.labminutes.com/sec0097_acs_directory_user_custom_attribute

Hopefully I did not misunderstood your question, otherwise, please elaborate your situation and what you are trying to achieve.
Title: Re: User Profile - ACS 5.X (on behalf of Michael)
Post by: nipaseimo on August 29, 2014, 11:30:51 AM
Thanks for your response.

I'm using TACACS+ (Device Administration) with RSA SecureID and not windows active directory.

I had followed the steps earlier to create Internal Users attributes with attribute type string with the following details..

Attribute:Sandvine-Group
Attribute Type:String

But when I wanted to add the attribute value "sv_operator,sv_admin" in the value field, I kept getting error messages, seems it didn't like the " (double quote).
Title: Re: User Profile - ACS 5.X (on behalf of Michael)
Post by: MC on September 03, 2014, 01:12:23 AM
Can you try to add them as two separate lines?
SimplePortal 2.3.7 © 2008-2021, SimplePortal