AAA Server Groups (RADIUS/TACACS)

Configures, modifies, and retrieves RADIUS/TACACS server configuration. The URI to configure RADIUS/TACACS server group is:

/system/aaa/server-groups

Note: The valid server group names are "radius-default-group" and "tacacs-default-group".

To create or modify RADIUS server:

/system/aaa/server-groups

To create or modify TACACS server:

/system/aaa/server-groups

To delete RADIUS server configuration in the system:

/system/aaa/server-groups/server-group/radius-default-group

To delete TACACS server configuration in the system:

/system/aaa/server-groups/server-group/tacacs-default-group

To delete the entire AAA server configuration in the system:
/system/aaa/server-groups

Supported HTTP Operations

GET method

URL: https://<host>/restconf/data/system/aaa/server-groups
Request body: None
Response body:  
"openconfig-system:server-groups":{
  "server-group":[{
    "name":"radius-default-group",
    "config":{
      "name":"radius-default-group",
      "type":"openconfig-aaa:RADIUS"
    },
    "state":{},
    "servers":{
      "server":[{
        "address":"63.1.1.1",
        "config":{
          "name":"radius1",
          "address":"63.1.1.1"
        },
        "state":{},
        "radius":{
          "config":{
            "icx-openconfig-aaa-aug:purpose" : "accounting-only",
            "auth-port":101,
            "acct-port":201,
            "secret-key":"$P2lnRA==",
            "retransmit-attempts":4
          },
          "state":{
            "counters":{}
          }
        }
      }
    ]}
  },
  {
    "name":"tacacs-default-group",
    "config":{
      "name":"tacacs-default-group",
      "type":"openconfig-aaa:TACACS",
  "icx-openconfig-aaa-aug:retransmit-attempts" : 4
    },
    "state":{},
    "servers":{
      "server":[{
        "address":"93.1.1.1",
        "config":{
          "name":"tacacs1",
          "address":"93.1.1.1"
        },
        "state":{},
        "tacacs":{
          "config":{
            "icx-openconfig-aaa-aug:purpose" : "accounting-only",
            "auth-port":101,
            "secret-key":"$P2lnRA=="
          },
          "state":{
            "counters":{}
          }
        }
      ]}
    }
  ]}
}

PATCH or PUT method to add or modify RADIUS server:

URL: https://{{dut}}/restconf/data/system/aaa/server-groups
Request body:{
            "server-groups": {
                "server-group": [
                {
                    "name": "radius-default-group",
                    "config": {
                        "name": "radius-default-group",
                        "type": "RADIUS"
                    },
                    "servers": {
                        "server": [
                        {
                    "address": "63.1.1.1",
                            "config": {
                                "name": "radius1",
                                "address": "63.1.1.1"
                            },
                           "radius": {
                               "config": {
                                   "auth-port": "101",
                                   "acct-port": "201",
                                   "secret-key": "radius",
                                   "retransmit-attempts": "4",
                                   "purpose": "accounting-only"
                               }
                           }
                       }
                       ]
                   }
               }
               ]
           }
}
 	
Response body: None    

PATCH or PUT method to add or modify TACACS server:

URL: https://{{dut}}/restconf/data/system/aaa/server-groups
Request body:
 {
            "server-groups": {
                "server-group": [
                {
                    "name": "tacacs-default-group",
                    "config": {
                        "name": "tacacs-default-group",
                        "type": "TACACS",
                        "retransmit-attempts" : 4
                    },
                    "servers": {
                    "server": [
                        {
                            "address": "93.1.1.1",
                            "config": {
                                "name": "tacacs1",
                                "address": "93.1.1.1"
                            },
                           "tacacs": {
                               "config": {
                                   "port": "101",
                                   "secret-key": "tacacs",
                                   "purpose": "accounting-only"
                               }
                           }
                       }
                       ]
                   }
               }
               ]
           }
}
Response body: None    

To DELETE all the configured AAA server:

URL: https://{{dut}}/restconf/data/system/aaa/server-groups   
Request body: None    
Response body: None