Chapter 1 Overview of Cisco Secure ACS
AAA Server Functions and Concepts
1-10
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Passwords
Cisco Secure ACS supports many common password protocols:
• ASCII/PAP
• CHAP
• MS-CHAP
• LEAP
• EAP-MD5
• EAP-TLS
• PEAP(EAP-GTC)
• ARAP
Passwords can be processed using these password authentication protocols based
on the version and type of security control protocol used (for example, RADIUS
or TACACS+) and the configuration of the AAA client and end-user client. The
following sections outline the different conditions and functions of password
handling.
RSA YesYesNoNoNoNoNoNoNoYes
ActivCard YesYesNoNoNoNoNoNoNoYes
CRYPTOCard Yes Yes No No No No No No No Yes
PassGo YesYesNoNoNoNoNoNoNoYes
Safeword Yes Yes No No No No No No No Yes
Vasco YesYesNoNoNoNoNoNoNoYes
RADIUS Token
Server
Yes Yes No No No No No No No Yes
Table 1-2 Authentication Protocol and User Database Compatibility (continued)
Database ASCII PAP CHAP ARAP
MS-
CHAP
v.1
MS-
CHAP
v.2 LEAP
EAP
-MD5
EAP
-TLS
PEAP
(EAP-
GTC)