Configuring User Role Authentication - HP 10500 Series Configuration Manual

Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Keywords
scheme
local scheme
scheme local

Configuring user role authentication

Step
1.
Enter system view.
2.
Set an authentication
mode.
3.
(Optional.) Specify
the default target
user role for
temporary user role
authorization.
4.
Set a local
authentication
password for a user
role.
Authentication mode
Remote AAA authentication
through HWTACACS or
RADIUS (remote-only)
Local password
authentication first, and
then remote AAA
authentication
(local-then-remote)
Remote AAA authentication
first, and then local
password authentication
(remote-then-local)
Command
system-view
super authentication-mode
{ local | scheme } *
super default role rolename
In non-FIPS mode:
super password [ role
rolename ] [ { hash |
simple } password ]
In FIPS mode:
super password [ role
rolename ]
Description
The device sends the username and password to the
HWTACACS or RADIUS server for remote authentication.
To use this mode, you must perform the following
configuration tasks:
Configure the required HWTACACS or RADIUS
scheme, and configure the ISP domain to use the
scheme for the user. For more information, see
Security Configuration Guide.
Add the user account and password on the
HWTACACS or RADIUS server.
Local password authentication is performed first.
If no local password is configured for the user role in this
mode:
The device performs remote AAA authentication for
VTY users.
An AUX user can obtain another user role by either
entering a string or not entering anything.
Remote AAA authentication is performed first.
Local password authentication is performed in either of the
following situations:
The HWTACACS or RADIUS server does not respond.
The remote AAA configuration on the device is
invalid.
Remarks
N/A
By default, local-only authentication applies.
The following default settings apply:
For default-MDC login users, the default
target user role is network-admin.
For non-default-MDC login users, the
default target user role is mdc-admin.
Use this step for local password authentication.
By default, no password is configured.
If you do not specify the role rolename option,
the command sets a password for the default
target user role.
27

Advertisement

Table of Contents
loading

Table of Contents