HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 44

Deleting a user-defined account, Changing account parameters, in secure mode.

Page 44 highlights

3. In response to the prompt, enter a password for the account. The password is not displayed when you enter it on the command line. Deleting a user-defined account Only accounts with the admin role can delete user-defined accounts on the logical switch. 1. Connect to the switch and log in as admin. 2. Issue the following command: userConfig --delete username where username specifies the account name. You cannot delete the default accounts. An account cannot delete itself. All active CLI sessions for the deleted account are logged out. 3. Enter y at the prompt for confirmation. Changing account parameters Accounts with the admin role can change information for accounts that have lesser permissions. Accounts with the user role cannot. 1. Connect to the switch and log in as admin. 2. Issue the following command: userconfig --change username [-r rolename] [-d description] [-e yes | no] where: username Changes the account attribute for username. The account must already exist. -r rolename Is an optional argument that changes the role: either admin, switchAdmin, or user in nonsecure mode; admin, user, or nonfcsadmin in secure mode. An account cannot change its own role. You can change the role name of a user-defined account only with a lower level of authorization. -d description Is an optional argument; the account description. The description field can be up to 40 printable ASCII characters. The following characters are not allowed: asterisk (*), quotation mark ("), exclamation point (!), semicolon (;), and colon (:). You can change the description of a user-defined account only with a lower level of authorization. -e Is an optional argument; enter yes to enable the account or enter no to disable it. If you disable an account, all active CLI sessions for that account are logged out. You can enable or disable user-defined or default accounts. Recovering user-defined accounts If a backup account exists (in secure mode), you can recover it with the following command: userConfig --recover The following conditions apply to recovering user accounts: • Only accounts with admin or higher roles can recover accounts. • The attributes in the backup database replace the attributes in the current account database. • An event is stored in the system message log, indicating that accounts have been recovered. 44 Configuring standard security features

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

44
Configuring standard security features
3.
In response to the prompt, enter a password for the account.
The password is not displayed when you enter it on the command line.
Deleting a user-defined account
Only accounts with the admin role can delete user-defined accounts on the logical switch.
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
userConfig --delete
username
where
username
specifies the account name. You cannot delete the default accounts. An account
cannot delete itself. All active CLI sessions for the deleted account are logged out.
3.
Enter
y
at the prompt for confirmation.
Changing account parameters
Accounts with the admin role can change information for accounts that have lesser permissions. Accounts
with the user role cannot.
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
userconfig --change
username
[-r
rolename
] [-d
description
] [-e yes | no]
Recovering user-defined accounts
If a backup account exists (in secure mode), you can recover it with the following command:
userConfig --recover
The following conditions apply to recovering user accounts:
Only accounts with admin or higher roles can recover accounts.
The attributes in the backup database replace the attributes in the current account database.
An event is stored in the system message log, indicating that accounts have been recovered.
where:
username
Changes the account attribute for
username
. The account must already
exist.
-r
rolename
Is an optional argument that changes the role: either
admin
,
switchAdmin
, or
user
in nonsecure mode;
admin
,
user
, or
nonfcsadmin
in secure mode.
An account cannot change its own role.
You can change the role name of a user-defined account only with a
lower level of authorization.
-d
description
Is an optional argument; the account description. The description field
can be up to 40 printable ASCII characters. The following characters are
not allowed: asterisk (*), quotation mark (“), exclamation point (!),
semicolon (;), and colon (:).
You can change the description of a user-defined account only with a
lower level of authorization.
-e
Is an optional argument; enter
yes
to enable the account or enter
no
to
disable it. If you disable an account, all active CLI sessions for that
account are logged out. You can enable or disable user-defined or
default accounts.