Heikki,
Thanks for the help. The cmd= was the trick as I was still attempting to
do the cmd\*.
On another not.. The shell:roles="blah1 blah2" doesn't work, but if you do
"blah1,blah2" then you get assigned both roles as expected.
Dave Heinz
On 8/1/13 5:07 PM, "Heikki Vatiainen" wrote:
>On
On 08/01/2013 09:06 PM, David Heinz wrote:
> I've been trying to craft an AuthorizeGroup statement to match:
> Thu Aug 1 18:01:06 2013: DEBUG: TacacsplusConnection Authorization
> REQUEST 6, 1, 2, 1, heinzdb, 0, 192.168.10.10, 4, service=shell cmd=
> cisco-av-pair* shell:roles*
How about this: