HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 43

Creating and maintaining user-defined accounts, Displaying account information

Page 43 highlights

Creating and maintaining user-defined accounts In addition to the default administrative and user accounts, Fabric OS supports up to 15 user-defined accounts in each logical switch (domain). These accounts expand your ability to track account access and audit administrative activities. User-defined accounts can be assigned either admin-, switchAdmin-, or user-level roles. Admin-level accounts allow up to two simultaneous login sessions. User-level accounts allow up to four simultaneous login sessions. The total number of simultaneous login sessions allowed per logical switch is 15. You can change passwords on user-defined accounts as described in "Changing an account password" on page 45. If the TC feature is enabled, the system keeps track of account names and login attempts. (See "Tracking and controlling switch changes" on page 35 for details on enabling the TC feature.) For large enterprises, Fabric OS also supports RADIUS services, as described in "Setting up RADIUS AAA service" on page 45. The following procedures are for operations you can perform on user-defined accounts. NOTE: If you are operating in secure mode, you can perform these operations only on the primary FCS switch. Displaying account information 1. Connect to the switch and log in as admin. 2. Issue one of the following commands: • userConfig --show -a to show all account information for a logical switch • userConfig --show -b to show all backup account information for a logical switch • userConfig --show username to show account information for the specified account name Accounts with the admin role can display information about all accounts on the logical switch. Accounts with the switchAdmin role can display information about all accounts on the logical switch; however, they cannot display information about security, user management, or zoning. Accounts with the user role can display information only about themselves. Creating a user-defined account Accounts with the admin role can create accounts. Accounts with the user role cannot. 1. Connect to the switch and log in as admin. 2. Issue the following command: userConfig --add username -r rolename [-d description] where: username Specifies the account name, which must begin with an alphabetic character. The name can consist of 8 to 40 characters. It is case-sensitive and can contain alphabetic and numeric characters, the dot, and the underscore. It must be different from all other account names on the logical switch. -r rolename Specifies the role: either admin, switchAdmin, or user in nonsecure mode; admin, user, or nonfcsadmin in secure mode. -d description Is an optional argument that adds a description to the account. The description field can be up to 40 printable ASCII characters. The following characters are not allowed: asterisk (*), quotation mark ("), exclamation point (!), semicolon (;), and colon (:). Fabric OS 5.x administrator guide 43

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS 5.x administrator guide
43
Creating and maintaining user-defined accounts
In addition to the default administrative and user accounts, Fabric OS supports up to 15 user-defined
accounts in each logical switch (domain). These accounts expand your ability to track account access and
audit administrative activities.
User-defined accounts can be assigned either admin-, switchAdmin-, or user-level roles. Admin-level
accounts allow up to two simultaneous login sessions. User-level accounts allow up to four simultaneous
login sessions. The total number of simultaneous login sessions allowed per logical switch is 15.
You can change passwords on user-defined accounts as described in ”
Changing an account password
” on
page 45.
If the TC feature is enabled, the system keeps track of account names and login attempts. (See ”
Tracking
and controlling switch changes
” on page 35 for details on enabling the TC feature.)
For large enterprises, Fabric OS also supports RADIUS services, as described in ”
Setting up RADIUS AAA
service
” on page 45.
The following procedures are for operations you can perform on user-defined accounts.
NOTE:
If you are operating in secure mode, you can perform these operations only on the primary FCS
switch.
Displaying account information
1.
Connect to the switch and log in as admin.
2.
Issue one of the following commands:
userConfig --show -a
to show all account information for a logical switch
userConfig --show -b
to show all backup account information for a logical switch
userConfig --show
username
to show account information for the specified account name
Accounts with the admin role can display information about all accounts on the logical switch. Accounts
with the switchAdmin role can display information about all accounts on the logical switch; however, they
cannot display information about security, user management, or zoning. Accounts with the user role can
display information only about themselves.
Creating a user-defined account
Accounts with the admin role can create accounts. Accounts with the user role cannot.
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
userConfig --add
username
-r
rolename
[-d
description
]
where:
username
Specifies the account name, which must begin with an alphabetic
character. The name can consist of 8 to 40 characters. It is case-sensitive
and can contain alphabetic and numeric characters, the dot, and the
underscore. It must be different from all other account names on the
logical switch.
-r
rolename
Specifies the role: either
admin
,
switchAdmin
, or
user
in nonsecure
mode;
admin
,
user
, or
nonfcsadmin
in secure mode.
-d
description
Is an optional argument that adds a description to the account. The
description field can be up to 40 printable ASCII characters. The
following characters are not allowed: asterisk (*), quotation mark (“),
exclamation point (!), semicolon (;), and colon (:).