cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3335
Views
5
Helpful
5
Replies

How to set UCS Locales using Radius/Tacacs+ Attributes

Doug Barnes
Level 1
Level 1

I know how to set a remotely authenticated/authorized users Role using the Radius av-pairs with UCS.

What Radius attribute/av-pair syntax is needed to set the users Locale within UCS?

I have tried shell:roles="role@locales" and shell:locales="locale name" with no success.

5 Replies 5

ncowger
Level 1
Level 1

It's not straight forward.  See the attached PDF how I made it work.

Something else to note:

Configuring locales to the user roles are not valid as these are global-system users:

-          aaa

-          admin

-          operations

Locales can be configured only with following user roles:

-          Network

-          Server-equipment

-          Server-profile

-          Server-security

-          Storage

Is there an example of using locales with IAS or Radius, roles are working but the locales seem to be ignored. Should the locales be a seperate attribute or combined with the role?

Hi Peter,

I have tested this using Tacacs and it had worked well:

         shell:roles*" " shell:locales*" "

          (single attribute, separator between role and locale is SPACE, separator between multiple roles/locales is also SPACE)

Probably the same syntax will work with Radius as well.

Cheers,

Gabor

james.munroe
Level 1
Level 1

Just a FYI to those out there trying to get Locales in UCSM working with with Cisco ACS 5.x.  The attached image is the method to create the proper shell profile attribute values for locales support in UCSM with TACACS+ as the authenication domain.  Vincent above also has it right on the priviledges available with locales support.

I am using the Manditory requirement as this shell profile is only used on Cisco UCS Devices.

I hope this saves someone a lot of frigging around! :-)

Jim

Review Cisco Networking for a $25 gift card

Review Cisco Networking for a $25 gift card