Author Service denied on service=shell

Hello,
in a ACS 3.3 environment, a service shell (exec) is enable to check user's authorization commands (outbound direction).
Normally commands are permitted or denied according to users/groups config.
Sometimes... the service seems disable and all authorizations fail... !
When it happens, the Failed Attempts Log Example is as below:
27/04/2010,10:11:35,Author failed,user1,Group1,10.1.50.21,,Command denied,service=shell cmd=http 66.xx.xx.xx,80 ----> Correct
27/04/2010,10:11:36,Author failed,user1,Group1,10.1.50.21,,Service denied,service=shell cmd=http 66.xx.xx.xx,80 ---> Wrong, "Cmd denied" as above
27/04/2010,10:12:10,Author failed,User2,Group2,10.1.50.22,,Service denied,service=shell cmd=https 213.xx.xx.xx,443 ---> Wrong, normally it's permit
27/04/2010,10:12:32,Author failed,User3,Group3,10.1.50.24,,Service denied,service=shell cmd=https 212.xx.xx.xx,443 ---> Wrong, normally it's permit
27/04/2010,10:12:32,Author failed,User4,Group4,10.1.50.26,,Service denied,service=shell cmd=https 212.xx.xx.xx,443 ---> Wrong, normally it's permit
To restore the normal condition about authorization's check, we restart CSTacacs service, below Tacacs service's Log:
TCS 27/04/2010 10:11:36 E 0155 4060 AAAClient1: user 'user1' using an invalid service: shell
TCS 27/04/2010 10:12:10 E 0155 4060 AAAClient1: user 'user2' using an invalid service: shell
TCS 27/04/2010 10:12:32 E 0155 4060 AAAClient1: user 'user3' using an invalid service: shell
TCS 27/04/2010 10:12:32 E 0155 4060 AAAClient1: user 'user4' using an invalid service: shell
TCS 27/04/2010 10:12:34 A 0651 2864 Server stop requested
TCS 27/04/2010 10:12:34 A 1256 0348 Release Host Cache
TCS 27/04/2010 10:12:34 A 1262 0348 Close Proxy Cache
TCS 27/04/2010 10:12:34 A 1285 0348 Calling CMFini()
TCS 27/04/2010 10:12:35 A 1287 0348 CMFini() Complete
TCS 27/04/2010 10:12:35 A 1301 0348 Closing Password Aging
TCS 27/04/2010 10:12:35 A 1314 0348 Closing Finished
TCS 27/04/2010 10:12:37 A 5020 0520 CSTacacs server starting ==============================
TCS 27/04/2010 10:12:37 A 5026 0520 Running as NT service.
TCS 27/04/2010 10:12:38 E 1051 0520 Doing Stats
TCS 27/04/2010 10:12:38 A 1092 0520
**** Registry Setup ****
TCS 27/04/2010 10:12:38 A 1119 0520 Single TCP connection operation enabled
TCS 27/04/2010 10:12:38 A 1129 0520 Base Proxy enabled.
TCS 27/04/2010 10:12:38 A 1196 0520 ************************
TCS 27/04/2010 10:12:38 E 1083 0520 TACACS+ server started
Any idea/suggest about this problem ? Is it a known "bug" ?
Thanks a lot in advance!

Jan,
It seems you have command authorization configured in acs. Make sure you have shell exec checked on acs --->group set.
Regards,
~JG
Do rate helpful posts

Similar Messages

  • ACS 4.2 Service denied service=shell cmd*

    Hi,
    I am trying to setup acs 4.2 for auth to windows AD 2003, dial-in is enable.
    I get this error msg in the ACS when I try to logon from our switch.
    Service denied service=shell cmd*
    Any sugestion?
    Regdars Jan

    Jan,
    It seems you have command authorization configured in acs. Make sure you have shell exec checked on acs --->group set.
    Regards,
    ~JG
    Do rate helpful posts

  • Windows Server 2008 R2 Standard "Certificate Authority Service" / Exchange Server 2010 EMC not starting and no AD connectivity for authentication.

    Hello,
    I am a new IT Manager at this company and need assistance big time. Their environment looks as follows:
    Server 1. Domain Controller Server (Windows Server 2008 R2 Standard) running active directory.
    Server 2. Email Server (Windows Server 2008 R2 Standard) running Exchange Server 2010 .
    * Note. No back ups to work with aside from whats mentioned below.
    DC had a virus infection causing a lot of issues on the shared network drives 2 days ago locking up all the files with a crypto ransom virus. Running Avast suppressed the infection. Had to recover the file shares which luckily had a back up. 
    The issue is that the Exchange Server 2 post this lost connectivity with the AD Server 1. Exchange Server 2 when launching EMC could not launch the console stating the following:
    "No Exchange servers are available in any Active Directory sites. You can’t connect to remote
    Powershell on a computer that only has the Management Tools role installed."
    Shortly after I found that it is possible the EMC launcher was corrupt and needed to be reinstalled following another blog post. I deleted the exchange management console.msc  per instructions only to discover I couldnt relaunch it because there was
    no way how. So I copied another msc file that happened to be on the DC Server 1  back to Exchange Server 2 and got it to launch again. 
    Another post said that it might be an issue with the Domain Account for the Computer, so to delete it in the AD Server 1 only to find that rejoining it from Exchange Server 2 using Computer>Properties> Chage Settings > Change is greyed out because
    it is using the Certificate Authority Service.
    I tried manually re-adding the computer in AD and modeling permissions after another server in group settings but no go. After this I was unable to login to the Exchange Server 2 with domain accounts but only local admin, receiving the following Alert:
    "The Trust Relationship between this workstation and primary domain failed."
    I tried running the Power Shell tools on Exchange Server 2 to rejoing and to reset passwords for domain accounts as noted in some other blogs but no luck as the Server 2 could not make the connection with Server1 or other errors it kept spitting out.
    I also during the investigation found the DNS settings were all altered on both the Server 1 and Server 2 which I luckily was able to change back to original because of inventorying it in the beginning when I started. 
    I need help figuring out if I need to rejoin the Exchange Server 2 manually by disabling the Certificate Authority Service (or removing the CA as listed here:
    https://social.technet.microsoft.com/Forums/exchange/en-US/fb23deab-0a12-410d-946c-517d5aea7fae/windows-server-2008-r2-with-certificate-authority-service-to-rejoin-domain?forum=winserversecurity
    and getting exchange server to launch again. (Mind you I am relatively fresh to server managing) Please help E-Mail has been down for a whole day now!
    Marty

    I recommend that you open a ticket with Microsoft Support before you break things more.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • Replacement Needed. This iphone is not able to complete the activation process and needs to be replaced. Please visit your nearest apple store or authorized service center.

    Probably will never ever think of buying a locked phone from AT&T cause its one of the worst system integrations ever that these companies could think of.
    The entire problem started when I put in a request with at&t to unlock my iphone 4s (ios7) which did get approved. I performed the entire instructions they asked me to do, which is to backup and restore. After doing those instructions my iphone gave me an error message below
    The SIM card inserted in this iPhone does not appear to be supported.
    The SIM card that you currently installed in this iPhone is from a carrier that is not supported under the activation policy that is currently assigned by the activation server. This is not a hardware issue with the iPhone. Please insert another SIM card from a supported carrier or request that this iPhone be unlocked by your carrier. Please contact Apple for more information.
    Basically saying that at&t hasn't still unlocked the iphone which a really helpful apple executive was able to confirm. I initiated another unlock process from at&t in order to unlock the iphone, just to be sure that its not something wrong from my end. The nice at&t lady stayed on chat with me to unlock the iphone step my step while I was calling the apple tech too. And the apple tech confirmed again that the iphone is locked to at&t.
    Now, just a few minutes ago I tried another restore to see if any progress is being made and to my surprise I got an error message saying
    Replacement Needed. This iphone is not able to complete the activation process and needs to be replaced. Please visit your nearest apple store or authorized service center.
    I feel like I am just going around these two different "money hogger" companies which set certain rules and regulations to screw a regular phone buyer. I purchased this iphone in USA and trying to unlock in India, is it really this hard to simply unlock a device.
    For now I am going to try to call a apple office in india (apprently we don't have very many out here) and see if they can help me. But any other assistance regarding unlocking an iphone 4s would be helpful. I have however, tried checking IMEI.info, called up apple, talked to at&t (which always say go talk to apple) I do have a case number from apple as well in case an apple executive reads this discussion forum (case number: 566383594)
    Thanks

    You got a confirmation from AT&T that it was authorized. Is this correct? - Yes i did get an email authorization on the 21st.
    Then you connected the phone to a computer with the latest version of iTunes installed. You clicked on the phone's name in iTunes, then clicked "Backup Now". - Yes
    When that finished you clicked "Restore iPhone" (NOT "Restore Backup") - Yes
    Are you with me so far? - Yes.
    And @ Varjak is right that after the 3rd restore I get the replacement error. 
    Plus I have NEVER jailbroken the iPhone. To give you another update, I spoke to a really nice apple tech in India who was atleast able to get me out of the replacement error by doing a recovery mode option. However, the lastest restore still gives me the same error
    The SIM card inserted in this iPhone does not appear to be supported.
    The SIM card that you currently installed in this iPhone is from a carrier that is not supported under the activation policy that is currently assigned by the activation server. This is not a hardware issue with the iPhone. Please insert another SIM card from a supported carrier or request that this iPhone be unlocked by your carrier. Please contact Apple for more information.
    Message was edited by: jabgars

  • How to fix this error "this iPad is not able to complete the activation process. Please press Home and start over. If the issue persists, please visit your nearest Apple Store or Authorized service provider for more information or replacement"?

    How to fix this error "this iPad is not able to complete the activation process. Please press Home and start over. If the issue persists, please visit your nearest Apple Store or Authorized service provider for more information or replacement"? When I plugged in my iPad this popped up!

    Hi csreddy, 
    If you are receiving a message to contact an Apple Retail Store or Authorized Service Provider for help updating from iOS 3, click on the link below to initiate that support:
    Update the iOS software on your iPhone, iPad, and iPod touch - Apple Support
    http://support.apple.com/en-us/HT204204
    Update your device using iTunes
    If you can’t update wirelessly, or if you want to update with iTunes, follow these steps:
    Install the latest version of iTunes on your computer.
    Plug in your device to your computer.
    In iTunes, select your device.
    In the Summary pane, click Check for Update. 
    Click Download and Update.
    If you don't have enough free space to update using iTunes, you'll need to delete content manually from your device.
    Find out what to do if you get other error messages while updating your device.
    Last Modified: Jan 12, 2015
    Apple - Find Locations
    https://locate.apple.com
    Contact Apple for support and service - Apple Support
    http://support.apple.com/en-us/HT201232
    Regards,
    - Judy

  • If I buy a Mac and iPad online, will I still be able to claim warranty at an Apple Authorized Service Provider?

    If I buy a Mac and iPad online, will I still be able to claim warranty at an Apple Authorized Service Provider?
    I am going to buy a Macbook Pro w/ Retina Display and iPad from www.topbuy.com.au . It's a legit website, but they say the items have topbuy warranties, not apple ones. They say I have to send off my faulty device to them, and they will fix it, but I don't want to do that. I just want to walk into an Apple store, tell them the problem and have a happy ending, like what's supposed to happen. Will I be able to do this?
    Thanks

    Apple warranty is good at any Apple service provider, AASP or store.
    But you seem to be reaching far to defend that "it's a legit website", especially when they seem to be directing you from seeking certified Apple service.
    As the saying goes: If it looks like a duck, and it sound like a duck, it's quackers to bypass an Apple store or Apple online to save a few $$.  Well, something like that.

  • I need to complain about iPad 3 i bought only 3 months but have to go to repair 2 times.  Poor services, dirty, not response staffs of APPLE AUTHORIZED SERVICE PROVIDER

    I bought iPad 3 on dated August 19, 2012
    It has a problem when using, happending 3 times already.
    1st problem - while using this ipad 3, it suddenltly shut down and show apple logo.  after reopen, found all application loaded have gone.
    2nd problem - the same issued, but can't re-open or reboot.  I have go to your dirty authorized service provider on dated October 15th, 2012.  after 4 days passed, they said will call me for updated but no any response.  I need to call your service provider myself asking the status.  They said have already been reboot with Itune and can't found any problem. I can take it back and said that They have try my device with using out of battery.  I need to charge after get it back myself.  THIS IS APPLE AUTHORIZED SERVICE PROVIDER.
    This is Macintosh Center Co.,Ltd.  APPLE AUTHORIZED SERVICE PROVIDER
    149/4 Modern Home Tower, Nonsee Road, Bangkok10120
    Staff name : Tan 
    I have called to Apple Suppor Call Center (as understand located in Singapore) report and advise our iPad problem and poor service.
    #001 800 441 2904 Mr. Charlie and Mr. Thawatchai 2 staffs have received my comment/complaint and full understand of this story and situation.
    Yesterday Noverber 12th, 2010 - the 3rd problem happend again - it more worse.  the screen show photo the USB line need to connect to iTunes.
    I have no choice need to go back to that poor APPLE AUTHORIZED SERVICE PROVIDER again as they have my story record. Same thing, they said need to check and reboot.
    IN 3 MONTHS HAVE TO REPAIR AT SERVICE PROVIDER. 
    REBOOT IF PROBLEM CAN GO BACK TO THEM --- PROBLEM  ---  REBOOT ---- AGAIN AND AGAIN.
    THIS IS 28,000- BAHT UP DEVICE BRAND APPLE. 
    MOST IMPORTANT : YOUR IMPORTANT PHOTOS, VIDEO, MESSAGE, RECORD WILL BE GONE. 
    THEY SAID WE NEED TO BACK UP FREQUENTLY WHEN USE ALL APPLE DEVICES NO MATTER ; iPhone or iPad.
    I have iPhone 1st Gen, iPhone 4th Gen, iPad 1, iPad 2, iPad 3 and new iPod 5 for my family.
    Now I thought that Samsung is my new choice and as per from my friend suggestion.  It a lot of best service from there.
    If anyone have the same case as me...Please raise it up...

    Phatara, this is a iPad user forum. There's no one here from Apple.
    You need to contact Apple:
    http://www.apple.com/contact/

  • Hi ! I need to send an e.mail reporting a problem with de Authorized Service Provider in Brasil. I contact Apple Brasil, but didn't solve. Someone know an Apple's USA e.mail i can use ? Thanks.

    Hi ! I need to send an e.mail reporting a problem with de Authorized Service Provider in Brasil. I contact Apple Brasil, but didn't solve. Someone know an Apple's USA e.mail i can use ? Thanks.

    There is a link at the bottom of this page. http://www.apple.com/contact/

  • Good morning. I need to send an e.mail reporting a problem with de Authorized Service Provider in Brasil. I contact Apple Brasil, but didn't solve. Someone know an e.mail i can use in Apple USA? Thanks.

    Good morning. I need to send an e.mail reporting a problem with de Authorized Service Provider in Brasil. I contact Apple Brasil, but didn't solve. Someone know an Apple's USA e.mail i can use ? Thanks.

    There is a link at the bottom of this page. http://www.apple.com/contact/

  • I sent my macbook pro to fix in an authorized service place in Colombia... they are saying that my war is damaged and that to buy a new one will cost too much but i want to know what the heck is the war and how much does it really cost.

    where can i get parts for macbook pro

    Take it to another Apple Authorized Service Provider.
    Never heard of damaged "war".
    Best.

  • The authorized service provider send me home with an exploding machine

    I wish the Apple shop over here in Hong Kong opened earlier. I had to deal with the "Authorized" service provider WahFung to try fixing my MBA. Then I was send home with the MBA "repaired" but turned out to have a potential of exploding!
    Here is what happened. My MBA had a power failure and needed a board replacement costing me over $400US at this WahFung service provider in Hong Kong. They "fixed" it by showing me that the little light on the MagSafe connecter lights up and rushed me to sign the receipt and send me home. After taking it home, I found that the whole keyboard was lifted up and the MBA doesn't even close properly! So I took it back to WahFung and ask them why. They said the battery has swollen up and you shouldn't turn on the machine as it might explode! I mean WHAT? so you send me home strapped with a bomb? Ok fine, then fix it up. They said no, you signed for it already and it is not our fault! OK, so thanks I paid $400 for you to mess up my machine and put me in risk. The only thing they said they would do is to contact Apple and see if Apple would replace the battery. (Fine I did hear about there is a replacement service for batteries of this problem of the same age machines) Now it has been about 8 weeks, no one is giving me any feedback. I don't even know if they did contact Apple. They still have the machine.
    Has anybody had similar problems on the service and/or the battery of the MBA?
    Now the Hong Kong Consumer Councel has also contact them and will bring them to court if we cannot settle. That will get me into a lot of time and money commitment having already spent over $400 dollars and hrs of waiting for them to pick up the phone. I have been a long time loyal user of Apple's product since the first Macintosh. Please please don't let these non-Apple people ruin you. If we do lose the court case, there will be media covering the story, I don't want Apple to get involved.
    Steve, I wish you were here, what would you have done?

    skyuen9 wrote:
    If we do lose the court case, there will be media covering the story, I don't want Apple to get involved.
    Is the news really that slow in your country that the news would broadcast a story about one persons negative experience with Apple?
    Steve, I wish you were here, what would you have done?
    Don't ask a rhetorical question towards the recently deceased co-founder of Apple, it is insensitive.  Tim Cook is the new CEO, he replaced Steve Jobs before his passing.  Feel free to mention his name from now on.
    With that said, I hope you recieve a favorable outcome.

  • Do Apple Authorized Service Providers "recycle" hard drives as new?

    I'd like to upgrade the hard drive in my iMac (500 gigs ain't cutting it!) to a 2 TB drive. While I've done this before in Macbook Pros, Towers and other computers, the iMac hard drive upgrade is a little sketchy to do on your own (you have to removed the glass with suction cups and then the display... no thanks).
    I was wondering if Apple Authorized Service Providers "recycle" old drives, meaning that you could potentially be getting someone elses old drive put into your machine. I know some computer repair chains have been caught doing it and was wondering if anyone has experienced this with an Apple Service Provider (not an Apple Store). I'd like to think Apple has high standards but you never know...
    Thanks!

    I agree with WZZZ, you should ask your local AASP and ask what becomes of old drives. If you decide to upgrade the old drive in your iMac is yours to do with what you want. The new drive you purchase should be just that, "new." Most firms could care less about what is on your old drive, they are aware of the liabilities and don't want to risk their businesses. IMHO you should proceed confidently.
    Roger

  • Complain to the authorized service

    I consider it necessary to complain to the authorized service partner Brand Service in St. Petersburg, Russia. http://www.brandservice.pro/
    This service partner addictive repair time, which affects the image of Apple as a whole.
    In lJanuary, I was bought iPhone 6 plus and I immediately ran into a problem - native usb cable lightning does not charge the phone or laptop via usb from or through the native network adapter. An error occurred: This cable or accessory is not certified, so the reliability of its work with the iPhone / iPad can not be guaranteed.
    2015 january 30 set charger (usb cable and power adapter 220) were put on the warranty repair service brand, Saint-Petersburg, 11 line V.O. d.22, where I was told that the charger will be ordered and waiting time of 5-7 days.
    2015 february 10 me was to make a call to the service brand, where I was told that in order to service center to order, it is necessary to me on the phone to disable the "Find my iPhone". On the legal question as to why I did not said when accepting the goods for repair to answer and could not, the question of why not call, said that rang, but I did not answer, though missed calls on my phone between 30.01 - 10.02 was not. Maximum kindly informed that now disable the function as soon as the call. At the end of the tube said ok, ordering, delivery time 1-2 days!
    2015 february 25 After 2 weeks and one day I made another call to the service brand and once again asked the fate of my charger.
    Long something figured out and said that in a way. On the question of how long these things usually come was said about 5-7 business days. Argue that the previous call was 10 february and it was already 10 workers and 5 days off could not. On direct and specific question: "When will the charge in your office?", Said vaguely: "Maybe next week" Suppose ordered just that, at the time of the call, and then about 5-7 working days to all converges and 10 february just scored forgotten etc.
    I think that this behavior is unacceptable authorized service representative and discredit the bright image of Apple in Russia.

    Sorry, but you are not addressing Apple here, this is a user to user forum and Apple does not follow these discussions. If you want to contact Apple, use the "Contact Us" link in the right corner of the page. Additionally you can also use this link: Apple - iPhone - Feedback

  • I buy new iphone 4 at singapore and i go back to my country indonesia, and then after few months the iphone 4 dead and the screen not show anything, and i try to contact the authorized service centre for iphone in indonesia, but they don't respond, so??

    im buy new iphone 4 at singapore and then i go back to my country indonesia, and after few months my iphone had trouble, the screen blank and no electric appears, i try to recharge but nothing happen, so i try to contact authorized service in jakarta, but they ignore my
    i already register my iphone 4 at the internet and there is global service, why they don't accept my service request
    this is my apple serial no : 7U04326EA4S
    and these the authorized service that ignore me
    iBox  Service Center
    Menteng Central Jl. HOS Cokroaminoto 78 (sebelah Satay House), Menteng, Jakarta Pusat
    10270
    Telephone:  6221-3900194, 6221-3908194
    INDONESIA

    That is because the iPhone warranty is country specific. You will need to return to Singapore, or send it to someone you know there, to get it serviced.

  • My iPhone 5, screen broken, What to do now? Authorized  service centers in Dubai asks AED2000 for changing screen. What to do now?

    My iPhone 5, screen broken, What to do now? Authorized  service centers in Dubai asks AED2000 for changing screen. What to do now?

    Accidental damage is not covered by warranty
    If you want a complete i|Phone you have no choice
    Make sure the servicew is carried out by authorised centre to protect remaining warranty

Maybe you are looking for