HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 45

Changing an account password, Setting up RADIUS AAA service

Page 45 highlights

Changing an account password At each level of account access, you can change passwords for that account and accounts that have lesser privileges. If you log in to a user account, you can change only that account's password. If you log in to an admin account, you can change admin and user passwords. You must provide the old password when the account being changed has the same or higher privileges than the current login account. For example, if you are logged in as admin, you need admin passwords to change passwords for admin accounts (except when you change the default user account password at login), but you do not need user passwords to change passwords for user accounts. A new password must have at least one character different from the old password. The following rules also apply to passwords: • You cannot change passwords using SNMP. • Password prompting is disabled when security mode is enabled. • With Fabric OS 4.4.0 and later, you can use Advanced Web Tools to change admin-level account passwords. • With Fabric OS 3.2.0 and later, you cannot change default account names. For information on password behavior when you upgrade (or downgrade) firmware, see "Effects of firmware changes on accounts and passwords" on page 79. Changing the password for the current login account 1. Connect to the switch and log in as either admin or user. 2. Issue the password command: passwd 3. Enter the requested information at the prompts. Changing the password for a different account 1. Connect to the switch and log in as admin. 2. Issue the following password command: passwd name where name is the name of the account. 3. Enter the requested information at the prompts. If the named account has lesser privileges than the current login account, the old password of the named account is not required. If the named account has equal or higher privileges than the current login account, you are prompted to enter the old password of the named account. Setting up RADIUS AAA service Fabric OS 3.2, 4.4.0 and later support RADIUS authentication, authorization, and accounting service (AAA). When configured for RADIUS, a switch becomes a RADIUS client. In this configuration, authentication records are stored in the RADIUS host server database. Login and logout account name, assigned role, and time-accounting records are also stored on the RADIUS server for each user. By default, RADIUS service is disabled, so AAA services default to the switch local database. To enable RADIUS service, HP recommends that you access the CLI through an SSH connection so that the shared secret is protected. Multiple login sessions can configure simultaneously; the last session to apply a change leaves its configuration in effect. After a configuration is applied, it persists after a reboot or an HA failover. The configuration is chassis-based, so it applies to all logical switches (domains) on the switch and replicates itself on a standby CP blade, if one is present. It is saved in a configuration upload and applied in a configuration download. Fabric OS 5.x administrator guide 45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS 5.x administrator guide
45
Changing an account password
At each level of account access, you can change passwords for that account and accounts that have
lesser privileges.
If you log in to a user account, you can change only that account’s password.
If you log in to an admin account, you can change admin and user passwords. You must provide the old
password when the account being changed has the same or higher privileges than the current login
account. For example, if you are logged in as admin, you need admin passwords to change passwords
for admin accounts (except when you change the default user account password at login), but you do not
need user passwords to change passwords for user accounts.
A new password must have at least one character different from the old password. The following rules
also apply to passwords:
You cannot change passwords using SNMP.
Password prompting is disabled when security mode is enabled.
With Fabric OS 4.4.0 and later, you can use Advanced Web Tools to change admin-level account
passwords.
With Fabric OS 3.2.0 and later, you cannot change default account names.
For information on password behavior when you upgrade (or downgrade) firmware, see ”
Effects of
firmware changes on accounts and passwords
” on page 79.
Changing the password for the current login account
1.
Connect to the switch and log in as either admin or user.
2.
Issue the password command:
passwd
3.
Enter the requested information at the prompts.
Changing the password for a different account
1.
Connect to the switch and log in as admin.
2.
Issue the following password command:
passwd name
where
name
is the name of the account.
3.
Enter the requested information at the prompts.
If the named account has lesser privileges than the current login account, the old password of the named
account is not required. If the named account has equal or higher privileges than the current login
account, you are prompted to enter the old password of the named account.
Setting up RADIUS AAA service
Fabric OS 3.2, 4.4.0 and later support RADIUS authentication, authorization, and accounting service
(AAA). When configured for RADIUS, a switch becomes a RADIUS client. In this configuration,
authentication records are stored in the RADIUS host server database. Login and logout account name,
assigned role, and time-accounting records are also stored on the RADIUS server for each user.
By default, RADIUS service is disabled, so AAA services default to the switch local database.
To enable RADIUS service, HP recommends that you access the CLI through an SSH connection so that the
shared secret is protected. Multiple login sessions can configure simultaneously; the last session to apply a
change leaves its configuration in effect. After a configuration is applied, it persists after a reboot or an
HA failover.
The configuration is chassis-based, so it applies to all logical switches (domains) on the switch and
replicates itself on a standby CP blade, if one is present. It is saved in a configuration upload and applied
in a configuration download.