HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 30

Configuring user group attributes, Command, Remarks, system, user-group

Page 30 highlights

Step Command Remarks The following default settings apply: • No authorization ACL, idle timeout period, or authorized VLAN is configured for local users. • FTP, SFTP, or SCP users are authorized access to the root directory of the device, but they do not have the access permission. 7. (Optional.) Configure authorization-attribute { acl • The network-operator user role is authorization attributes for acl-number | idle-cut minute | assigned to local users that are the local user. user-role role-name | vlan vlan-id | created by a network-admin or work-directory directory-name } * level-15 user. For LAN users, only the settings for acl, idle-cut, and vlan take effect. For Telnet and terminal users, only the setting for user-role takes effect. For SSH and FTP users, only the settings for user-role and work-directory take effect. For other types of local users, no authorization attribute takes effect. • Set the password aging time: password-control aging aging-time • Set the minimum password 8. (Optional.) Configure length: password control attributes password-control length length for the local user. • Configure the password composition policy: password-control composition type-number type-number [ type-length type-length ] Optional. By default, the local user uses password control attributes of the user group to which the local user belongs. Only device management users support the password control function. 9. (Optional.) Assign the local user to a user group. group group-name By default, a local user belongs to the default user group system. Configuring user group attributes User groups simplify local user configuration and management. A user group comprises a group of local users and has a set of local user attributes. You can configure local user attributes for a user group to implement centralized user attributes management for the local users in the group. Local user attributes that are manageable include authorization attributes. By default, every newly added local user belongs to the default user group system and bears all attributes of the group. To assign a local user to a different user group, use the user-group command in local user view. To configure user group attributes: 21

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

21
Step
Command
Remarks
7.
(Optional.) Configure
authorization attributes for
the local user.
authorization-attribute
{
acl
acl-number
|
idle-cut
minute
|
user-role
role-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
The following default settings apply:
No authorization ACL, idle
timeout period, or authorized
VLAN is configured for local
users.
FTP, SFTP, or SCP users are
authorized access to the root
directory of the device, but they
do not have the access
permission.
The network-operator user role is
assigned to local users that are
created by a network-admin or
level-15 user.
For LAN users, only the settings for
acl
,
idle-cut
, and
vlan
take effect.
For Telnet and terminal users, only
the setting for
user-role
takes effect.
For SSH and FTP users, only the
settings for
user-role
and
work-directory
take effect.
For other types of local users, no
authorization attribute takes effect.
8.
(Optional.) Configure
password control attributes
for the local user.
Set the password aging time:
password-control aging
aging-time
Set the minimum password
length:
password-control length
length
Configure the password
composition policy:
password-control composition
type-number
type-number
[
type-length
type-length
]
Optional.
By default, the local user uses
password control attributes of the
user group to which the local user
belongs.
Only device management users
support the password control
function.
9.
(Optional.) Assign the
local user to a user group.
group
group-name
By default, a local user belongs to the
default user group
system
.
Configuring user group attributes
User groups simplify local user configuration and management. A user group comprises a group of local
users and has a set of local user attributes. You can configure local user attributes for a user group to
implement centralized user attributes management for the local users in the group. Local user attributes
that are manageable include authorization attributes.
By default, every newly added local user belongs to the default user group
system
and bears all attributes
of the group. To assign a local user to a different user group, use the
user-group
command in local user
view.
To configure user group attributes: