cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1897
Views
0
Helpful
2
Replies

TACACS password expiration/notification to ssh devices

btrice
Level 1
Level 1

I am running ACS v3.0. On my core routers, running SSH, the password expiration notification is never sent to users (confirmed it does work on telnet devices). Also, once an administrator resets the users password, the user can NOT change their password if accessing a SSH device. It actually expires the users account when they try a SSH connection. I am guessing there is something to do witht he CHAP authentication and how SSH is not handling it correctly. Any suggestions?

2 Replies 2

owillins
Level 6
Level 6

Cisco Secure ACS v3.0 for Windows 2000/NT has MS-CHAP Password Aging against the WinNT/Win2K database. From what I know, PPP users will not get any warning of password expiration. That is probably the reason the notification is not sent to your devices.

But users do get a warning on None SSH Devices.