How to skip enable mode password prompt.

Hi,
I just installed ACS 4.1 (first time working with ACS). Everything is working great and I'm using the ACS internal database for user authentication.
The question I have is this. When logging into a router, which is authenticating against the ACS server, is there a way to bypass having to enter my password a second time to get to enable mode??
Currently, I have to enter my username and password to login to the router and when I go to enable mode, I have to re-enter my password again.
Any help is greatly appreciated.
Thanks,
Tony

Hi,
Here's my two penny's worth;
I would take off the "authorization" lines as these are only needed to authorize exec and commands:
no aaa authorization exec default group tacacs+ if-authenticated
no aaa authorization commands 15 default group tacacs+ if-authenticated
I would also remove the authentication enable line as this tells the device to authenticate enable mode access
no aaa authentication enable default group tacacs+ enable
And just test with the authentication login line, leave the accounting lines for now
I would double check the following in ACS:
Is the device in the right NDG?
Do you have Per Group Defined Network Access Restrictions defined for this device?
Is the user in the right group?
In the group settings, Check you have Shell(exec) enabled, Privilege level set to 15, and under Enable Options ensure you have the right Priv level defined, per device, per group etc.
Do you have either Shell Command Authorization Set or Per Group Command Authorization radio button selected?
If you have Shell Command Authorization Set for the group ensure you have Unmatched Commands Permit selected.
And authentication should be ok, then you can troubleshoot the authorization part...
Is this on an appliance or other operating system? My experience of the appliances are that they're pretty c**p, too many bugs and little things that don't work...
Just for info, you should have a last resort local username configured if ACS is down:
username priv 15 password
This will give you local access, and, if you find you have access issues as you have, you can remove the device from ACS, so it doesn't know about it, the device will try ACS not a get a response after the timeout period and prompt you for your username, enter your local password and you're in...
I hope this helps...

Similar Messages

  • How to prevent the regular password prompts when watching a movie on my MacBook Air?

    Hello everyone.
    I recently started renting movies from the iTunes store and watched them on my MacBook Air since I don't have an appleTV. (In fact on my TV connected via HDMI cable to the MacBook but I think that doesn't change the cause)
    Now every now and then a automatic password prompt kicks in overlaying the movie, so I have to stand up each time and type in the administrator password in the middle of the movie. This happens maybe about every 30-45 mins. Needless to say this is extremely unpleasant when watching a movie. Unfortunately I cannot tell you which programm causes the prompt since I always close all other programms other than iTunes.
    Is there a way to temporarily prevent all automatic password prompts?
    I hope you can help me,
    Greetings jonezdotcom

    This is taken from Mac Help.  It should guide you in solving your issue.
    Changing the way users log in
    You can require users to enter a password to log in to your computer, or you can turn on automatic login, which automatically logs in a specified user each time the computer starts up.
    Automatic login is useful if you’re the only person who uses your computer, and the computer is always in a safe and secure place. If you have more than one user account on your computer, or if you’re concerned about the security of information on your computer, you should require users to log in with a password. Automatic login is not available for accounts that are using FileVault encryption.
    If you require users to log in, you can change what they see in the login window. You can show a list of users with a picture next to each name and a place to enter the password, or require users to enter both their user name and password.
    To change the way users log in:
    Choose Apple menu > System Preferences and click Accounts.
    Open Accounts preferences
    Click the lock icon to unlock it, and then type an administrator name and password.
    Click Login Options.
    Do one of the following:
    To require users to log in whenever the computer starts up, choose Off from the “Automatic login” pop-up menu.
    To have the computer automatically log in to a particular account when the computer starts up, choose the account from the “Automatic login” pop-up menu, enter an administrator password, and click OK.
    IMPORTANT: Automatic login allows anyone to get immediate access to your computer simply by restarting it. If you turn on automatic login, make sure the computer doesn’t automatically log in to an account with administrator privileges.
    Next to the ”Display login window as,” select how you want the login window to appear:
    To have users select an account from a list in the login window, select “List of users.”
    To require users to type their user account name and password, select “Name and password.”
    To show each user’s password hint, select the “Show password hints” checkbox.
    If you turn on automatic login for yourself, the computer opens your account when it starts up. If you log out, other users see a login window to log in to their user accounts.
    The Login Options pane of Accounts preferences
    Use the Login Options pane of Accounts preferences to change the way the login window behaves to be more secure or set up the way users will log in to their accounts
    PREFERENCE EXPLANATION
    Automatic login
    To have the computer automatically log in to an account at startup, choose the account from the pop-up menu. This is less secure than requiring users to log in, since it allows anyone to use the computer just by turning it on.
    To require users to select an account and enter a password to log in, choose Off from the pop-up menu.
    Automatic login is not available for accounts that are using FileVault encryption.
    Display login window as
    Select “List of users” to have users choose their accounts from a list in the login window.
    Select “Name and password” to require users to type their name and password in the login window.

  • How to set new sudo password prompt?

    Hi guys, i've a problem with sudo!
    I want set a new password prompt for me but unfortunately don't how to do...
    I set  a defaults line in sodoers file with this syntax:
    Defaults     passprompt="MyPass:"
    but don't work...
    I tried also start sudo with -p paramenter: sudo -p "Mypass:" but nothing
    Someone can help me please...:(

    skymt wrote:
    Actually, sudo has an option for this:
    sudo -p 'Enter your password, %u:'
    '%u' will be replaced with your username. You can also use %H or %h for the hostname with or without the domain, %U for the username sudo will use to run your command, or %% for an actual percent sign.
    If you want to set a permanant prompt, either set the environment variable "SUDO_PROMPT" or set "passprompt" in /etc/sudoers using visudo.
    I tried this solution but don't work for me..
    If i try to do:
    # sudo -p 'My Password:' i've "Password" for pass prompt..
    I've re-checked the sudoers file, is this:
    # sudoers file.
    # This file MUST be edited with the 'visudo' command as root.
    # See the sudoers man page for the details on how to write a sudoers file.
    # Host alias specification
    # User alias specification
    # Cmnd alias specification
    # Defaults specification
    Defaults passprompt="Password:"
    # Runas alias specification
    # User privilege specification
    root ALL=(ALL) SETENV: ALL
    # Uncomment to allow people in group wheel to run all commands
    # and set environment variables.
    %wheel ALL=(ALL) ALL

  • How can I enable firmware password for normal boot?

    I've enabled firmware password protection, but it won't work unless you try to boot in other mode ( like holding c, d or option to boot from other drives ). However, what I want is a complete lock from opening my computer. Is there a way to enforce this?
    Best Regards

    Even if with the firmware password, you're not safe. There are ways to bypass both the firmware password and the login password. To be as safe as possible:
    1) Turn on the firmware password, as you have done
    2) Turn off auto-login, so that users have to log in to use the machine
    3) Set the login window to ask for name and password instead of displaying a list of users
    4) Use good encryption with a good password to protect any sensitive data
    or,
    4b) Don't ever let the machine out of your sight!
    Disk Utility can help with #4 through use of encrypted sparse disk images on which you store sensitive data. File Vault can also help by encrypting your entire user folder, but IMHO this is a bad idea unless absolutely necessary, as it complicates backups and means that any little disk corruption could trash your entire user directory (since it'll be stored in one big, encrypted file).

  • How do I enable Firmware Password from ARD for 10.9.5

    I've searched all over the NET and cannot find a solid answer, how do I use the Firmware Password Utility to enable Firmware passwords in ARD on 10.9.5 Networked machines?

    See:
    *[[/questions/785267]] How do I uninstall inbox.com on a Mac
    Try to reset prefs on the <b>about:config</b> page that refer to <b>inbox</b>.
    *Open the <b>about:config</b> page via the location bar and do a search for <i>inbox</i> via the Search bar at the top of the about:config page.<br />
    *Reset all <i>inbox</i> related prefs that appear bold (user set) via the right-click context menu to their default values.
    Try to reset some preferences to the default with the SearchReset extension:
    *https://addons.mozilla.org/firefox/addon/searchreset/
    Note that the SearchReset extension only runs once and then uninstalls automatically, so it won't show on the "Firefox > Add-ons" page (about:addons).

  • XP pro file sharing and guest password - how to enable guest password?

    Hi,
    I want to share files between two Windows XP pro computers. I would also like that these shares can only be accessed with a password.
    Here's a description of my setup:
    I have two laptops: over 1 yo Fujitsu-Siemens (FS) running on Windows XP pro (finnish) and a brand new Thinkpad T61 (TP) running on Windows XP pro (english). Both of theses computers have guest account enabled and these accounts have also been password protected. FS's guest account is called "vieras" because of the language settings and TP's guest account is of course just "guest". Guest account passwords have been enabled using "net user <user name> *".
    I've disabled simple file sharing on both computers, set shared folder permission to only contain these users: TP - "Guest (TP\Guest)" and FS - "Vieras (FS\Vieras)". Both computers have F-secure on them so I've made firewall rules which enable following services both ways to a specific IP: Ping / ICMP echo request and reply ; Windows file sharing and network printers ; Windows network browsing ; ICMP / Internet Control Message Protocol. I've also enabled these services on Windows firewall.
    These computers can connect to each other either via Wi-Fi access point (b-mode) or directly using an ad-hoc Wi-Fi configuration (g-mode). Obviously the latter is used for more bandwidth hungry file transfers. Also, sometimes a cross-over Ethernet cable is used as well for even faster file transfers.
    Everything on my setup works just fine except just one thing. I connect to a shared resource by running the computer's IP address. When I connect from TP to FS it prompts for username and password. FS accepts both english and finnish names for  the guest account provided that the password is correct. But here's the problem... When connecting from FS to TP _no password or username prompt appears_. If I browse TP's shared folder sessions (under My Computer -> manage) I can see that FS is logged on as "vieras" i.e. FS's guest account.
    Since I enabled FS's network shares over a year a go I can't remember everything I did to make it work. Every relevant configuration on TP and FS seem to be identical (e.g. "Security settings -> local policies -> security options -> Accounts: limit local account use of blank passwords to console logon only -> enabled") but still TP accepts connections without password prompt.
    I've tried to get TP's password prompts enabled for a while now without any success. I did a lot of searching on the subject but I could only find instructions on how to disable guest account password prompts for network shares.
    Has anyone had similar experiences or does anyone know what I should try out next? Thanks...
    Solved!
    Go to Solution.

    Success!
    I solved my problem by changing guest account passwords. I tried to keep things simple by using the same guest password on both computers. This however allowed FS to log on to TP without guest password for some unknown reason. My logic would tell me that having the same guest password would allow both computers to log in without password but this wasn't obviously the case. I guess Windows has its own logic that I can't figure out or this issue had something to do with different language setups. Anyhow my shares work now like I want them to work.

  • Log into Device with AAA, how do I get right into enable mode?

    I am using a Cisco ACS server with an RSA server behind it. When the user is authenticated from the ACS server, I want them to go straight into enable mode, not have to type the enable mode password. What line am I missing?
    aaa authentication login ACS group ACS_servers local enable
    aaa authorization exec ACS group ACS_servers local
    aaa authorization commands 15 ACS group ACS_servers local
    aaa accounting commands 1 default start-stop group ACS_servers
    aaa accounting commands 15 default start-stop group ACS_servers
    line vty 0 5
    login authentication ACS
    authorization commmands 15 ACS

    The configuration in question is for telnet, but I do need to design my new console access connection. Console access would be either remotely or on-site, but I don't feel comfortable giving priv 15 right into it. I plan to use the same authentication method on the console (ACS group 1st, local database 2nd) and will just have to enter the enable password through the console.
    One more question on the aaa config, I kept getting this error in the log:
    AAA/AUTHOR: config command authorization not enabled
    So I added:
    aaa authorization config-commands
    I don't know if it was needed because I could still execute config-commands, but it kept giving me that warning if I didn't have that line.
    Also, do I really need this line if the ACS server is taking care of priv 15 authorization:
    aaa authorization commands 15 ACS if-authenticated

  • How do you remove password prompt?

    how do you disable the password prompt when you are moving items around on the laptop or installing items? Its so **** annoying.

    HI,
    That "password prompt" is there for your security. You can't install software updates without providing your admin password.
    Carolyn

  • IPAD NO WIRELESS PASSWORD PROMPT

    My wife's Ipad 1 will not allow for a password to be entered when joining a wireless network.  Only the "Couldn't Join" message and a dismiss option.  How can I get a password prompt?

    Does the network you're trying to join show a little lock icon beside it, indicating that a password is required? If not, then no p/w is required for it, which is the good answer for you, or there might some issue with the network itself, which you can do nothing about on your end.
    If it does, then I think you must have some iOS issue going on, assuming that you have the same issue on other networks that show the lock icon. In that case I'd try the below things in more or less the stated order. Check and see if any step fixes your problem and, if it does, don't continue. First,
    a. Try simply powering the iPad down (press and hold Sleep/Wake, then slide the red slider, etc.) and back on, see if the situation persists. If it does, then
    b. Cycle various settings in Settings > General > Wifi and > Networks, seeing is you can make whatever is latched up unlatch itself. This will sometimes help.
    c. Try going to Settings > General > Reset > Reset Network Settings.
    d. Try a Reset (System or Forced) by pressing and holding both the Home and Sleep/Wake buttons for about 10 seconds. Ignore the red slider when it appears, then when you see the white Apple logo appear on the blank screen you can release the buttons and allow a normal boot up to proceed.
    If still no luck at that point, you may have little left to try except for a fresh load of iOS and restoring from a backup.

  • How do I skip master password prompts

    I have master password enabled. Sometimes I want to skip entering the password, but on some sites it asks for my master password again and again on each new page. I (or someone else on my PC) doesn't want to log in, just to surf without all the prompts. Is there any way of turning this facility off temporarily?

    You can disable the Password Manager temporarily if you remove the check mark to remember passwords.
    That won't remove existing passwords.
    Tools > Options > Security: Passwords: "Remember passwords for sites"
    You can also use an extension to toggle the pref signon.rememberSignons between true/false
    Prefswitch: https://addons.mozilla.org/firefox/addon/6485
    Custom Buttons2: https://addons.mozilla.org/firefox/addon/5066

  • How to avoid password prompt in shell script for zip password protection

    Hi
    I am trying to set password protection to my oracle database export backup. Once the backup completed, it should compress with a password protection. Thats the plan. Initialy we were using the gzip for the compression. Then realized that there is no password protection for the gzip. Started using zip option. I tried using
    zip -P <password> filename
    But it was throwing below error.
    -bash-3.2$ zip -P expreports REPORTS_2013FEB14.dmp
    zip warning: missing end signature--probably not a zip file (did you
    zip warning: remember to use binary mode when you transferred it?)
    zip warning: (if you are trying to read a damaged archive try -F)
    zip error: Zip file structure invalid (REPORTS_2013FEB14.dmp)
    Not quite sure why.
    Then I used zip -e REPORTS_2013FEB14.dmp.zip REPORTS_2013FEB14.dmp
    But this prompting for the password. As I am trying to put the command in the script. It will be tough if it prompts for the password.
    I would like to know how to avoid the password prompting by saving somewhere or how the code should be written. Tried using expect feature of shell script. Below was the code I tried. It didnt work.
    [oracle@SF40V6636 test]$ cat repexp.sh
    zip -e REPORTS_imp.log.zip REPORTS_imp.log
    expect "Enter password:"
    send "imprep"
    expect "Verify password:"
    send "imprep"
    So please help in avoiding this password prompt or let me know how to change the code.
    Thanks
    SHIYAS M

    How about using gpg and adding a secret key to the requirement of a password? No one should be able to decrypt your file, not by knowing only the password.
    1. Generate a public and private key pair:
    $ gpg --gen-key
    When it shows "We need to generate a lot of random bytes…" open another terminal session and type "dd if=/dev/sda of=/dev/null" to create traffic. When the public and secret key created and signed you can Ctrl-C the dd command.
    To see what you have created:
    $ gpg --list-keys
    2. Encrypt and gzip your stuff:
    $ tar zcf stuff.tgz file_or_folder
    $ gpg recipient "Some Name" encrypt stuff.tgz
    $ rm -f stuff.tgz
    3. Decrypt and extract the archive:
    $ gpg batch yes --passphrase "password" -d stuff.tgz.gpg > stuff.tgz
    $ tar zxvf stuff.tgz
    Again, knowing the password alone will not let anybody decrypt your stuff.

  • How do I get Firefox to prompt me to remember a password for a site that has already been visited?

    How do I get Firefox to prompt me to remember a site password for a site that has already been visited (probably in private mode)?

    Remove site(s) from the Exceptions:
    * Firefox > Preferences > Security: Passwords: Exceptions
    *http://kb.mozillazine.org/Password_Manager
    *http://kb.mozillazine.org/User_name_and_password_not_remembered
    *Saved Password Editor: https://addons.mozilla.org/firefox/addon/saved-password-editor/

  • HT4113 I have an ipod that is disabled.  How do I enable it back when the kids can't remember what the password was?

    I have an ipod that is disabled.  How can I enable it when the kids don't remember the password?

    Place the iOS device in Recovery Mode and then connect to your computer and restore via iTunes. The iPod will be erased.
    iOS: Wrong passcode results in red disabled screen                          
    If recovery mode does not work try DFU mode.                         
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings

  • How do I get a supervisor password prompt to appear so I can configure the BIOS?

    Question How do I access the BIOS setup on a Thinkpad T60? 
    AnswerTo access the BIOS setup,
    1. Press the F1 key when the system boots
    2. You'll be prompted for the password.
    3. Enter your Supervisor password at the prompt
    The Power on password prompt and the supervisor password prompt are the same 
    If a power on password was configured you would need to enter this afterwards, the same applies to HDD password.

    You'll never get a supervisor prompt- I have PWR ON, HDD and Supervisor PWD.- If I want to enter to sipervisor mode, I have to enter the Supervisor PWD when asked for the Power On PWD....really tricky...

  • How do I enable an add-on in Firefox safe mode?

    So recently I have had a problem with Firefox crashing all the time and found out it was an add-on that was causing the problem.
    I have tried opening Firefox in safe-mode to disable add-ons but they are already disabled, so I want to know how to enable an add-on and then to permanently disable it so Firefox will open normally again. . .
    I have already tried to permanently disable all add-ons by using the Firefox options box but nothing happens after I click on the 'make changes and restart firefox' button. After I click it nothing happens and it remains frozen. ([https://support.mozilla.com/en-US/kb/Safe%20Mode Safe mode Window])
    So to make things short, how do I enable an add-on in Firefox safe mode?

    In Firefox 4 and later [http://kb.mozillazine.org/Safe_mode Safe mode] disables extensions and also disables hardware acceleration.
    *Tools > Options > Advanced > General > Browsing: "Use hardware acceleration when available"
    If disabling hardware acceleration works then check if there is an update available for your graphics display driver.
    You should still see a Disable button or Enable button (if you disabled them all) in the extension Manager (Tools > Add-ons > Extensions) if you start Firefox in Save mode.
    *https://support.mozilla.com/kb/Safe+Mode

Maybe you are looking for

  • How to disable Wizard in Ad-hoc Query Designer

    Hi everybody, I am using the Bex Ad-hoc Query Designer in a web application. The users should be able to define their own queries, but just for one info provider. I selected the info provider in the properties of the ad-hoc query designer in the web

  • Java/OpenJDK problem with OSS/osspd/ALSA/pulseaudio [SOLVED]

    I've got problems with sound output of java programs, which usually try to hog /dev/dsp, using pulseaudio and openjdk 7. Some rare java apps' sound methods surprisingly do work. Others (which the majority of java programs seem to use) do not. In Sun

  • Database access from Managed/Backing bean

    Hi, I would like to authenticate web users from a database table, I get the account details in the Welcome page, I wish to check if the user exists in the table (from the managed bean), how do I do this? Is this good practice to access the db from ma

  • Windows 7 SP1

    Just tried to install the driver "Creative Sound Blaster X-Fi series driver 2.8.005" on my XtremeMusic and it said operating system not recognized. Is there going to be an updated version of the driver that support Windows 7 SP? Does anyone know of a

  • I got my first Mac and will need microsoft office to migrate from my PCmi

    I got my first Mac last night and I will need Microsoft Office to work and to migrate the docs from my old sony Vaio PC with  Windows 7, where can