HP A7533A HP StorageWorks Fabric OS 6.1.1 administrator guide (5697-0235, Dece - Page 466

Password prompting behaviors

Page 466 highlights

Table 97 Account/password characteristics matrix (continued) Topic 4.0.0 4.1.0 to 4.2.0 4.4.0 and later Does a user need to know the old passwords when changing passwords using the passwd command? Yes, except when the root user changes another user's password. This is standard UNIX behavior; Fabric OS does not enforce any additional security. Old password is required only when changing password for the same level user password. Changing password for lower level user does not require old password. For example, users connect as admin; old admin password is required to change the admin password. But old user password is not required to change the user password. 4.4.0 to 5.1.0 only: Old password is required only when changing password for the same level user password. Changing password for lower level user does not require old password. For example, users connect as admin; old admin password is required to change the admin password. But old user password is not required to change the user password. Can passwd change higher-level passwords? For example, can admin change root password? Yes, but will ask for the old password of the higher-level account (example root). Yes; if users connect as admin, they can change the root, factory, and admin passwords. However, if one connects as user, one can only change the user password. 4.4.0 to 5.1.0 only: Yes, if users connect as admin, they can change the root, factory and admin passwords after first entering the old password for the respective account. Can API change passwords? Yes, only for admin. Yes, only for admin. Yes, only for admin. Can Web Tools change No No No passwords? Can SNMP change No No No passwords? Password prompting behaviors Table 98 describes the expected password prompting behaviors of various Fabric OS versions. Table 98 Password prompting matrix Topic 4.0.0 4.1.0 and later Must all password prompts be completed for any change to take effect? When does the password prompt appear? No. Partial changes of all four passwords are allowed. When users connect as root, factory, or admin, the accounts with default password will be prompted for change. The accounts with non-default password will not be prompted. No. Partial changes of all four passwords are allowed. When users connect as root, factory, or admin, the accounts with default password will be prompted for change. The accounts with non-default password will not be prompted. Is a user forced to answer password prompts before getting access to the firmware? No, users can enter Ctrl-c to get out of password prompting. No, users can enter Ctrl-c to get out of password prompting. Do users need to know the old root Yes in 4.0.0 No password when answering prompting? No in 4.0.2 only Are new passwords forced to be set to Yes Yes something different than the old passwords? 466 Understanding legacy password behavior

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496

466
Understanding legacy password behavior
Password prompting behaviors
Table 98
describes the expected password prompting behaviors of various Fabric OS versions.
Does a user need to know the
old passwords when
changing passwords using
the
passwd
command?
Yes, except when
the root user
changes another
user’s password.
This is standard
UNIX behavior;
Fabric OS does not
enforce any
additional security.
Old password is
required only when
changing password for
the same level user
password. Changing
password for lower level
user does not require
old password. For
example, users connect
as admin; old admin
password is required to
change the admin
password. But old user
password is not
required to change the
user password.
4.4.0 to 5.1.0 only:
Old password is
required only when
changing password for
the same level user
password. Changing
password for lower level
user does not require old
password. For example,
users connect as admin;
old admin password is
required to change the
admin password. But old
user password is not
required to change the
user password.
Can passwd change
higher-level passwords? For
example, can admin change
root password?
Yes, but will ask for
the old password of
the higher-level
account (example
root).
Yes; if users connect as
admin, they can change
the root, factory, and
admin passwords.
However, if one
connects as user, one
can only change the
user password.
4.4.0 to 5.1.0 only:
Yes, if users connect as
admin, they can change
the root, factory and
admin passwords after
first entering the old
password for the
respective account.
Can API change passwords?
Yes, only for admin.
Yes, only for admin.
Yes, only for admin.
Can Web Tools change
passwords?
No
No
No
Can SNMP change
passwords?
No
No
No
Table 97
Account/password characteristics matrix (continued)
Topic
4.0.0
4.1.0 to 4.2.0
4.4.0 and later
Table 98
Password prompting matrix
Topic
4.0.0
4.1.0 and later
Must all password prompts be completed
for any change to take effect?
No. Partial changes of all
four passwords are allowed.
No. Partial changes of all
four passwords are allowed.
When does the password prompt
appear?
When users connect as root,
factory, or admin, the
accounts with default
password will be prompted
for change. The accounts with
non-default password will not
be prompted.
When users connect as root,
factory, or admin, the
accounts with default
password will be prompted
for change. The accounts with
non-default password will not
be prompted.
Is a user forced to answer password
prompts before getting access to the
firmware?
No, users can enter
Ctrl-c
to
get out of password
prompting.
No, users can enter
Ctrl-c
to
get out of password
prompting.
Do users need to know the old root
password when answering prompting?
Yes in 4.0.0
No in 4.0.2 only
No
Are new passwords forced to be set to
something different than the old
passwords?
Yes
Yes