Radius Authorization
Description
Authorization checks performed after successful user authentication.
Authorization decisions are based on the user's roles granted by the authenticator plugin configured in the RADIUS service. Different target services may be configured and required roles are defined for each target service. The target service is determined based on the "NAS-Identifier" RADIUS attribute (sent by the RADIUS client).
May be used by
Properties
Default Target Service (
defaultTargetService) Description
Required roles and other settings for the default target service.
The default target service is used if no information is available about which target service to choose and if none of the other target services matches the NAS-Identifier.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Target Services (
targetServices) Description
Defines required roles and other settings for each target service. The list is processed sequentially until the first service matches. If none matches, the default target service is used.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: RadiusAuthorization
id: RadiusAuthorization-xxxxxx
displayName:
comment:
properties:
defaultTargetService:
targetServices: