Advanced Operations 8
Switched Power Distribution Unit
65
EN
8.4.3 LDAPS Client Specifications
Secure Sockets Layer (SSL) version 3
Transport Layer Security (TLS) version 1 (RFC
2246)
x.509 version 3 Server Certificates (RFC 2459)
with RSA key sizes up to 4096 bits
Symmetric Cryptography Ciphers:
TLS_RSA_WITH_3DES_EDE_CBC_SHA (168-
bit)
TLS_RSA_WITH_DEX_CBC_SHA (56-bit)
TLS_RSA_WITH_AES_128_CBC_SHA (128-bit)
TLS_RSA_WITH_AES_256_CBC_SHA (256-bit)
Server certificates are accepted and used on –
the-fly
A NULL client certificate is sent to the server if a
client certificate is requested
8.5
The PDU family of products supports the Terminal
Access Controller Access Control System (TA-
CACS+) protocol. This enables authentication
and authorization with a central server;
user accounts do not need to be individually cre-
ated locally on each PDU device.
This allows administrators to pre-define and con-
figure (in each PDU product, and in the
server) a set of necessary privilege
levels, and users access rights for each. User’s
access rights can then be assigned or revoked
simply by making the user a member of one-or-
more pre-defined PDU privilege levels.
User account rights can be added, deleted, or
changed within without any changes
needed on individual PDU products.
The PDU supports 16 different privilege
levels; 15 are entirely configurable by the system
administrator (1 is reserved for default Admin level
access to all PDU resources).
TACAC+ Command Summary
Command
Description
Set Authorder
Specifies the authentication
order for each new session at-
tempt
Set TACACS
Enables/disables SSL support
Set TACACS Host
Sets the IP address or host-
name of the TACACS server
Set TACACS Key
Sets the TACACS encryption
key
Set TACACS Port
Sets the TACACS server port
number
Show TACACS
Displays TACACS configura-
tions
Add GrouptoTACACS
Grants a TACACS account
access to one or more groups
Add OutlettoTACACS
Grants a TACACS account
access to one or all outlets
Add PorttoTACACS
Grants a TACACS account
access to one or serial ports
Delete GroupfromTACACS
Removes access to one or
more groups for a TACACS ac-
count
Delete OutlettoTACACS
Removes access to one or
more outlets for a TACACS ac-
count
Delete PortfromTACACS
Removes access to one or
more serial ports for a TACACS
account
Set TacPriv Access
Sets the access level for a
TACACS account
Set TacPriv Envmon
Grants or removes privileges to
view input and environmental
monitoring status
List TacPrivs
Displays access levels for all
TACACS accounts
List TacPriv
Displays all accessible out-
let/groups/ports for a TACACS
account
Enabling and Setting up Support
There are a few configuration requirements for
properly enabling and setting up sup-
port. Below is an overview of the minimum re-
quirements:
1. Enable support.
2. Define the IP address and domain com-
ponent of at least one server.
3. Set the key configured on the
supporting server.
Enabling and disabling support:
The Set TACACS command is used to enable or
disable support.