HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 29

Displaying and maintaining local users and local user groups

Page 29 highlights

By default, every newly added local user belongs to the system default user group system and bears all attributes of the group. To change the user group to which a local user belongs, use the user-group command in local user view. To configure attributes for a user group: Step Command Remarks 1. Enter system view. system-view N/A 2. Create a user group and enter user group view. user-group group-name N/A • Set the password aging time: 3. Configure password control attributes for the user group. password-control aging Optional. aging-time • Set the minimum password By default, the global settings apply. The global settings include length: a 90-day password aging time, a password-control length length minimum password length of 10 • Configure the password characters, and at least one composition policy: password composition type and at password-control composition least one character required for type-number type-number each password composition type. [ type-length type-length ] 4. Configure the authorization attributes for the user group. authorization-attribute { acl acl-number | idle-cut minute | level level | user-profile profile-name | vlan vlan-id | work-directory directory-name } * Optional. By default, no authorization attribute is configured for a user group. 5. Set the guest attribute for the user group. group-attribute allow-guest Optional. By default, the guest attribute is not set for a user group, and guest users created by a guest manager through the Web interface cannot join the group. NOTE: For more information about password control attributes configuration commands, see Security Command Reference. Displaying and maintaining local users and local user groups Task Display local user information Display the user group configuration information. Command Remarks display local-user [ idle-cut { disable | enable } | service-type { ftp | lan-access | ssh | telnet | terminal | web } | state { active | block } | user-name user-name | vlan vlan-id ] [ slot slot-number ] [ | { begin | exclude | include } regular-expression ] Available in any view display user-group [ group-name ] [ | { begin | exclude | include } regular-expression ] Available in any view 19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

19
By default, every newly added local user belongs to the system default user group system and bears all
attributes of the group. To change the user group to which a local user belongs, use the
user-group
command in local user view.
To configure attributes for a user group:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a user group and enter
user group view.
user-group
group-name
N/A
3.
Configure password control
attributes for the user group.
Set the password aging time:
password-control aging
aging-time
Set the minimum password
length:
password-control length
length
Configure the password
composition policy:
password-control composition
type-number
type-number
[
type-length
type-length
]
Optional.
By default, the global settings
apply. The global settings include
a 90-day password aging time, a
minimum password length of 10
characters, and at least one
password composition type and at
least one character required for
each password composition type.
4.
Configure the authorization
attributes for the user group.
authorization-attribute
{
acl
acl-number
|
idle-cut
minute
|
level
level
|
user-profile
profile-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
Optional.
By default, no authorization
attribute is configured for a user
group.
5.
Set the guest attribute for the
user group.
group-attribute
allow-guest
Optional.
By default, the guest attribute is not
set for a user group, and guest
users created by a guest manager
through the Web interface cannot
join the group.
NOTE:
For more information about password control attributes configuration commands, see
Security Command
Reference
.
Displaying and maintaining local users and local user groups
Task
Command
Remarks
Display local user information
display local-user
[
idle-cut
{
disable
|
enable
} |
service-type
{
ftp
|
lan-access
|
ssh
|
telnet
|
terminal
|
web
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
]
[
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the user group configuration
information.
display user-group
[
group-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view