HP A7533A HP StorageWorks Fabric OS 6.1.1 administrator guide (5697-0235, Dece - Page 63

Recovering accounts, Changing local account passwords

Page 63 highlights

To change account parameters: When changing account parameters, if you change the ADlist for the user account, all of the currently active sessions for that account will be logged out. For more information about changing the Admin Domain on an account, see Chapter 6, "Managing administrative domains" on page 153. 1. Connect to the switch and log in using an admin account. 2. Issue the following command: userconfig --change username [-r rolename] [-h admindomain_ID] [-a admindomain_ID_list] [-d description] [-e yes | no] -u -x where: username -r rolename -h admindomain_ID -a admindomain_ID_list -d description -e -u -x Specifies the account for which parameters are being changed. Changes the role to one of the names listed in Table 8 on page 58. In secure mode, role can also be changed to nonfcsadmin. An account cannot change its own role. Accounts with Admin role can change the role names of all user-defined accounts, except those with Admin roles. Optional: Changes the home Administrative Domain; if no Administrative Domain is specified, the lowest numbered Administrative Domain in the list is assigned. Optional: Changes the Administrative Domains the user may access; if no Administrative Domains are listed, the user is automatically assigned to AD0. Use comma-separated lists, ranges, or both. for example -a 0,9,10-15,244. Optional: Changes the description to the account. The description field can consist of up to 40 printable ASCII characters. The following characters are not allowed: asterisk (*), single quotation mark ('), quotation mark ("), exclamation point (!), semicolon (;), and colon (:). Optional: Enables or disables the account. Enter yes to enable the account or no to disable it. If you disable an account, all active CLI sessions for that account are logged out. You can enable or disable user-defined or default accounts. Unlocks the user account. Specifies an expired password that must be changed the first time the user logs in. Recovering accounts The following conditions apply to recovering user accounts: • The attributes in the backup database replace the attributes in the current account database. • An event is stored in the system message log, indicating that accounts have been recovered. To recover an account: 1. Connect to the switch and log in using an admin account. 2. If a backup database exists, issue the following command. userConfig --recover The AD list for a user account is not recovered; recovered accounts are given access only to AD0, regardless of previous AD assignments Changing local account passwords The following rules apply to changing passwords: • Users can change their own passwords. Fabric OS 6.1.1 administrator guide 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496

Fabric OS 6.1.1 administrator guide
63
To change account parameters:
When changing account parameters, if you change the ADlist for the user account, all of the currently
active sessions for that account will be logged out. For more information about changing the Admin
Domain on an account, see Chapter 6, ”
Managing administrative domains
” on page 153.
1.
Connect to the switch and log in using an admin account.
2.
Issue the following command:
userconfig --change
username
[-r
rolename
] [-h admindomain_ID]
[-a admindomain_ID_list] [-d
description
] [-e yes | no] -u -x
where:
Recovering accounts
The following conditions apply to recovering user accounts:
The attributes in the backup database replace the attributes in the current account database.
An event is stored in the system message log, indicating that accounts have been recovered.
To recover an account:
1.
Connect to the switch and log in using an admin account.
2.
If a backup database exists, issue the following command.
userConfig --recover
The AD list for a user account is not recovered; recovered accounts are given access only to AD0,
regardless of previous AD assignments
Changing local account passwords
The following rules apply to changing passwords:
Users can change their own passwords.
username
Specifies the account for which parameters are being changed.
-r rolename
Changes the role to one of the names listed in
Table 8
on
page 58. In secure mode, role can also be changed to
nonfcsadmin. An account cannot change its own role. Accounts
with Admin role can change the role names of all user-defined
accounts, except those with Admin roles.
-h admindomain_ID
Optional: Changes the home Administrative Domain; if no
Administrative Domain is specified, the lowest numbered
Administrative Domain in the list is assigned.
-a admindomain_ID_list
Optional: Changes the Administrative Domains the user may
access; if no Administrative Domains are listed, the user is
automatically assigned to AD0. Use comma-separated lists,
ranges, or both. for example -a 0,9,10-15,244.
-d description
Optional: Changes the description to the account. The
description field can consist of up to 40 printable ASCII
characters. The following characters are not allowed: asterisk
(*), single quotation mark (‘), quotation mark (“), exclamation
point (!), semicolon (;), and colon (:).
-e
Optional: Enables or disables the account. Enter
yes
to enable
the account or
no
to disable it. If you disable an account, all
active CLI sessions for that account are logged out. You can
enable or disable user-defined or default accounts.
-u
Unlocks the user account.
-x
Specifies an expired password that must be changed the first
time the user logs in.