
Appendix A: Glossary
certificate An electronic document that contains a public key and is digitally signed by a
certificate See CA. authority
Challenge See CHAP.
Handshake
Authentication
Protocol
CHAP Challenge Handshake Authentication Protocol. An authentication protocol that is supported by PPP and also incorporated in RADIUS. With CHAP, the authenticator sends the client a “challenge” text. The client creates a hash value from its
cluster See enforcement cluster.
combination See CS. server
credentials A username and its corresponding password.
CS Combination Server. A NAC 800 that functions as both an ES and an MS and acts as a
D
data store The location where an endpoint’s credentials are stored. Possible data stores are: a local database of users, a Windows domain controller that runs Active Directory, an LDAP server such as OpenLDAP or Novell eDirectory, or another RADIUS server (accessed via proxy requests).
deployment Sometimes called “deployment option,” the way in which the NAC 800 is method connected to the LAN relative to other components such as routers, switches,
DHCP servers, and the Internet. The deployment method is determined by the quarantine method and the access method that the network will employ. The NAC 800 supports three deployment methods: 802.1X deployment, inline deploy- ment, and DHCP deployment.