Security

 View Only
  • 1.  No expiry for one TACACS user

    Posted Jul 15, 2022 06:15 AM
    we have configured 90 days expiry settings for TACACS users, but we need to set no expiry for one TACACS user.


  • 2.  RE: No expiry for one TACACS user

    Posted Jul 15, 2022 10:08 AM
    Assuming you are using the local user's database?  I'm not aware of a way to do this other than use an external identity source (like Active Directory)


  • 3.  RE: No expiry for one TACACS user

    Posted Jul 15, 2022 11:55 PM
    Thanks for the response.

    yes we are using authentication source as Local User Repository.
    Authentication Sources:

    How we can integrate with AD for single user. we need to set no expiry for one user for tacacs authentication.


  • 4.  RE: No expiry for one TACACS user

    Posted Jul 18, 2022 08:49 AM
    I am not aware of this being possible for internal users.  Do you have an AD to integrate with?  
    1. Join ClearPass servers to domain
    2. Create Authentication source referencing your AD environment
    3. Specify AD authentication source in your TACACS+ policy with appropriate group or user enforcement profiles.