HP GbE2c HP GbE2c Ethernet Blade Switch for c-Class BladeSystem Application Gu - Page 29

User access control, Setting up user IDs - reset password

Page 29 highlights

User access control The switch allows an administrator to define end user accounts that permit end users to perform limited actions on the switch. Once end user accounts are configured and enabled, the switch requires username/password authentication. For example, an administrator can assign a user who can log into the switch and perform operational commands (effective only until the next switch reboot). The administrator defines access levels for each switch user, as shown in the following table. Table 6 User access levels User account Administrator Operator User Description Password The Administrator has complete access to all menus, information, and configuration commands on the switch, including the ability to change both the user and administrator passwords. admin The Operator manages all functions of the switch. The Operator can reset ports or oper the entire switch. The User has no direct responsibility for switch management. Users can view all switch status information and statistics but cannot make any configuration changes to the switch. user Passwords can be up to 128 characters in length for TACACS+, Telnet, SSH, console, and BBI access. When RADIUS authentication is used, the maximum password length is 16 characters. If RADIUS authentication is used, the user password on the Radius server will override the user password on the switch. Also note that the password-change command on the switch modifies only the "use switch" password and has no effect on the user password on the Radius server. RADIUS authentication and user password cannot be used concurrently to access the switch. Setting up user IDs The administrator can configure up to 10 user accounts. To configure an end-user account, perform the following steps: 1. Select a user ID to define. >> # /cfg/sys/access/user/uid 1 2. Define the user name and password. >> User ID 1 # name jane Current user name: New user name: jane (Assign name "jane" to user ID 1) 3. Define the user access level. By default, the end user is assigned to the user access level. To change the user's access level, enter the user Class of Service (cos) command, and select one of the available options. >> User ID 1 # cos 4. Enable the user ID. >> # /cfg/sys/access/user/uid /ena Once an end user account is configured and enabled, the user can login to the switch using the username/password combination. The level of switch access is determined by the user CoS for the account. The CoS corresponds to the user access levels described in the User access levels table. Accessing the switch 29

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165

Accessing the switch 29
User access control
The switch allows an administrator to define end user accounts that permit end users to perform limited actions on the
switch. Once end user accounts are configured and enabled, the switch requires username/password authentication.
For example, an administrator can assign a user who can log into the switch and perform operational commands
(effective only until the next switch reboot).
The administrator defines access levels for each switch user, as shown in the following table.
Table 6
User access levels
User account
Description
Password
Administrator
The Administrator has complete access to all menus, information, and
configuration commands on the switch, including the ability to change both the
user and administrator passwords.
admin
Operator
The Operator manages all functions of the switch. The Operator can reset ports or
the entire switch.
oper
User
The User has no direct responsibility for switch management.
Users can view all switch status information and statistics but cannot make any
configuration changes to the switch.
user
Passwords can be up to 128 characters in length for TACACS+, Telnet, SSH, console, and BBI access. When
RADIUS authentication is used, the maximum password length is 16 characters.
If RADIUS authentication is used, the user password on the Radius server will override the user password on the
switch. Also note that the password-change command on the switch modifies
only
the “use switch” password and has
no effect on the user password on the Radius server. RADIUS authentication and user password cannot be used
concurrently to access the switch.
Setting up user IDs
The administrator can configure up to 10 user accounts.
To configure an end-user account, perform the following steps:
1.
Select a user ID to define.
>> # /cfg/sys/access/user/uid 1
2.
Define the user name and password.
>> User ID 1 # name jane
(Assign name “jane” to user ID 1)
Current user name:
New user name: jane
3.
Define the user access level. By default, the end user is assigned to the user access level. To change the user’s
access level, enter the user Class of Service (
cos
) command, and select one of the available options.
>> User ID 1 # cos <user|oper|admin>
4.
Enable the user ID.
>> # /cfg/sys/access/user/uid <
#
>/ena
Once an end user account is configured and enabled, the user can login to the switch using the username/password
combination. The level of switch access is determined by the user CoS for the account. The CoS corresponds to the
user access levels described in the User access levels table.