Configuring Task Groups - Cisco IOS XR Configuration Manual

System security configuration guide
Hide thumbs Also See for IOS XR:
Table of Contents

Advertisement

How to Configure AAA Services

Configuring Task Groups

Task-based authorization employs the concept of a task ID as its basic element. A task ID defines the
permission to execute an operation for a given user. Each user is associated with a set of permitted router
operation tasks identified by task IDs. Users are granted authority by being assigned to user groups that
are in turn associated with task groups. Each task group is associated with one or more task IDs selected
from the Cisco CRS-1 set of available task IDs. The first configuration task in setting up the
Cisco CRS-1 authorization scheme is to configure the task groups, followed by user groups, followed by
individual users.
Task Group Configuration
Task groups are configured with a set of task IDs per action type.
The inherit taskgroup command may be used to derive permissions from another group. Cyclic
references are detected and rejected. It is not possible to inherit from the root-system and owner-sdr
predefined groups.
Specific task IDs can be removed from a task group by specifying the no prefix for the task command.
The task group itself can be removed. Deleting a task group that is still referred to will result in an error.
Prerequisites
Before creating task groups and associating them with task IDs, the user should have some familiarity
with the router list of task IDs and purpose of each task ID. Use the show task supported command to
display a complete list of task IDs.
Restrictions
Only users with write permissions for the AAA task ID can configure task groups.
SUMMARY STEPS
1.
2.
3.
4.
5.
6.
7.
Cisco IOS XR System Security Configuration Guide
SC-184
Applying Method Lists for Applications, page SC-216
Configuring Login Parameters, page SC-220
configure
taskgroup taskgroup-name
description string
inherit taskgroup taskgroup-name
task {read | write | execute | debug} taskid-name
Repeat Step 5 for each task ID to be associated with the task group named in Step 2.
end
or
commit
Configuring AAA Services on Cisco IOS XR Software
(required)
(required)

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ios xr 3.5

Table of Contents