Configuring User Group Attributes - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Step
5.
(Optional.) Place the local
user to the active or
blocked state.
6.
(Optional.) Configure
binding attributes for the
local user.
7.
(Optional.) Configure
authorization attributes for
the local user.
8.
(Optional.) Configure
password control attributes
for the local user.
9.
(Optional.) Assign the
local user to a user group.

Configuring user group attributes

User groups simplify local user configuration and management. A user group comprises a group of local
users and has a set of local user attributes. You can configure local user attributes for a user group to
implement centralized user attributes management for the local users in the group. Local user attributes
that are manageable include authorization attributes.
By default, every newly added local user belongs to the default user group system and bears all attributes
of the group. To assign a local user to a different user group, use the user-group command in local user
view.
To configure user group attributes:
Step
1.
Enter system view.
Command
state { active | block }
bind-attribute { ip ip-address |
location port slot-number
subslot-number port-number | mac
mac-address | vlan vlan-id } *
authorization-attribute { acl
acl-number | idle-cut minute |
user-role role-name | vlan vlan-id |
work-directory directory-name } *
Set the password aging time:
password-control aging
aging-time
Set the minimum password
length:
password-control length length
Configure the password
composition policy:
password-control composition
type-number type-number
[ type-length type-length ]
group group-name
Command
system-view
20
Remarks
By default, a created local user is in
active state and can request network
services.
By default, no binding attribute is
configured for a local user.
Binding attribute ip applies only to
LAN users using 802.1X.
Binding attributes location, mac, and
vlan apply only to LAN users.
By default, no authorization attribute
is configured for a local user.
For LAN users, only the settings for
acl, idle-cut, and vlan take effect.
For Telnet and terminal users, only
the setting for user-role takes effect.
For SSH and FTP users, only the
settings for user-role and
work-directory take effect.
For other types of local users, no
authorization attribute takes effect.
Optional.
By default, the local user uses
password control attributes of the
user group to which the local user
belongs.
The commands take effect only on
device management users.
By default, a local user belongs to the
default user group system.
Remarks
N/A

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents