config authentication scheme
Configure Authentication Schemes.
config authentication scheme
Description: Configure Authentication Schemes.
edit <name>
set digest-algo {option1}, {option2}, ...
set domain-controller {string}
set external-idp {string}
set fsso-agent-for-ntlm {string}
set fsso-guest [enable|disable]
set group-attr-type [display-name|external-id]
set kerberos-keytab {string}
set method {option1}, {option2}, ...
set negotiate-ntlm [enable|disable]
set require-tfa [enable|disable]
set saml-server {string}
set saml-timeout {integer}
set ssh-ca {string}
set user-cert [enable|disable]
set user-database <name1>, <name2>, ...
next
end
config authentication scheme
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
digest-algo |
Digest Authentication Algorithms. |
option |
- |
md5 sha-256 |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
domain-controller |
Domain controller setting. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
external-idp |
External identity provider configuration. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
fsso-agent-for-ntlm |
FSSO agent to use for NTLM authentication. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
fsso-guest |
Enable/disable user fsso-guest authentication (default = disable). |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
group-attr-type |
Group attribute type used to match SCIM groups (default = display-name). |
option |
- |
display-name |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
kerberos-keytab |
Kerberos keytab setting. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
method |
Authentication methods (default = basic). |
option |
- |
|
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
name |
Authentication scheme name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
negotiate-ntlm |
Enable/disable negotiate authentication for NTLM (default = disable). |
option |
- |
enable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
require-tfa |
Enable/disable two-factor authentication (default = disable). |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
saml-server |
SAML configuration. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
saml-timeout |
SAML authentication timeout in seconds. |
integer |
Minimum value: 30 Maximum value: 1200 |
120 |
||||||||||||||||||||||||
|
ssh-ca |
SSH CA name. |
string |
Maximum length: 35 |
|
||||||||||||||||||||||||
|
user-cert |
Enable/disable authentication with user certificate (default = disable). |
option |
- |
disable |
||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||||
|
user-database |
Authentication server to contain user information; "local-user-db" (default) or "123" (for LDAP). Authentication server name. |
string |
Maximum length: 79 |
|
||||||||||||||||||||||||