I have been looking at the Fundamentals Configuration guide, but if you can tell me on which page it specifies the Radius attribute and format to be returned to specify the RBAC "user role", I would be grateful!
I got an answer from HP L3 support stating that I should just use the same HP vendor specifc attribute for Exec-Privilege (29), but give it the values 0-15 corresponding to the user roles level-0 through level-15. And, looking through the Fundamentals Configuration guide again, I found these notes on page 44:
"NOTE:
•
To be compatible with privilege-based access control, the device automatically converts privilege-based
user levels (0 to 15) assigned by an AAA server to RBAC user roles (level-0 to level-15).
•
If the AAA server assigns a privilege-based user level and a user role to a user, the user can use the
collection of commands and resources accessible to both the user level and the user role. "
The first note would confirm the answer that I received from HP L3 support. However, in a mixed Comware5/Comware7 environment, I now have to figure out how to send the old 0-3 Exec-Privilege values to the Comware5 devices and the new 0-15 Exec-Privilege values to the Comware7 devices. May just have to do this based on NAS IP address.
However, the second note confirms that there is some other Radius attribute that can be returned to specify a "user role". The HP Radius attribute 29 is the "privilege-based user role", so what attribute is used to specify a "user role"?
Paul