<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: API  X TACACS in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179891#M7681</link>
    <description>&lt;P&gt;For the management API, no. Like I said, those&amp;nbsp;&lt;SPAN&gt;permissions are controlled &lt;EM&gt;&lt;STRONG&gt;exclusively&lt;/STRONG&gt;&lt;/EM&gt; through the user's permissions profile. Management supports central authentication, but not central identification or authorization. Permissions and group memberships are totally ignored. Only the permissions profile matters.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2023 18:20:50 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-05-03T18:20:50Z</dc:date>
    <item>
      <title>API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179832#M7676</link>
      <description>&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;I'm facing a difficult problem regarding the API&lt;/P&gt;&lt;P&gt;Today we are using TACACS , and to escalate the necessary privileges, type a set command to go up to expert next.&lt;/P&gt;&lt;P&gt;I'm trying to integrate an application with rest api, but I'm getting error that the user doesn't have necessary privileges.&lt;/P&gt;&lt;P&gt;The configuration in the manager is with ALL IP ADDRESSES&lt;/P&gt;&lt;P&gt;but we are getting login error, and using curl to try to login we get error 401&lt;/P&gt;&lt;P&gt;When we use tacacs does the api need some kind of privilege?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 13:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179832#M7676</guid>
      <dc:creator>nãbru</dc:creator>
      <dc:date>2023-05-03T13:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179838#M7677</link>
      <description>&lt;P&gt;Which API? Management (to define firewall objects and rules) or OS-level (to define things like routes and interfaces)?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 14:14:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179838#M7677</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-05-03T14:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179841#M7678</link>
      <description>&lt;P&gt;&lt;SPAN&gt;API Management only&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 14:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179841#M7678</guid>
      <dc:creator>nãbru</dc:creator>
      <dc:date>2023-05-03T14:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179877#M7679</link>
      <description>&lt;P&gt;For the management API, permissions are controlled exclusively through the user's permissions profile. Log in to SmartConsole, go to Manage &amp;amp; Settings &amp;gt; Permissions &amp;amp; Administrators. The user must be defined there, and must have a permissions profile.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 16:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179877#M7679</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-05-03T16:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179890#M7680</link>
      <description>&lt;P&gt;This has already been done, but I get an insufficient privileges error.&lt;/P&gt;&lt;P&gt;My question was about tacacs in relation to the API, if you need any different privileges to use the API. Since local admin has been disabled and everything goes through tacacs&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:15:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179890#M7680</guid>
      <dc:creator>nãbru</dc:creator>
      <dc:date>2023-05-03T18:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179891#M7681</link>
      <description>&lt;P&gt;For the management API, no. Like I said, those&amp;nbsp;&lt;SPAN&gt;permissions are controlled &lt;EM&gt;&lt;STRONG&gt;exclusively&lt;/STRONG&gt;&lt;/EM&gt; through the user's permissions profile. Management supports central authentication, but not central identification or authorization. Permissions and group memberships are totally ignored. Only the permissions profile matters.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:20:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179891#M7681</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-05-03T18:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: API  X TACACS</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179892#M7682</link>
      <description>&lt;P&gt;Do you know what reasons might have related to insufficient privileges error.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 18:29:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/API-X-TACACS/m-p/179892#M7682</guid>
      <dc:creator>nãbru</dc:creator>
      <dc:date>2023-05-03T18:29:38Z</dc:date>
    </item>
  </channel>
</rss>

