Network Device Authentication
A lot of people outside of the network space are quite surprised to find out that network devices don't always support LDAP. There are convenient reasons for this. Doing Authentication Most devices will support RADIUS with varied levels of "support". For others, they will support TACACS+ as well as RADIUS. Finally, a subset of devices will support LDAP. RADIUS You have to map in the dictionary for the appropriate attributes. Example, Juniper, Cisco, etc have their own special attributes. FreeRadius keeps a good list, but it may require occasional additions for other vendors TACACS+ Is a pile of shit, but a convenient pile of shit for cisco environments. Most people use shrubbery.net's tac_plus or Cisco ACS. ACS is well known for being horrible at the worst times. Also, building your own TACACS+ box means it will last until the apocalypse unlike ACS. Why not just LDAP everywhere? Three easy reasons: LDAP is usually maintained by someone els...