Configuring User Role Authentication - HP 5920 series Fundamentals Configuration Manual

Hide thumbs Also See for 5920 series:
Table of Contents

Advertisement

Table 10 User role authentication modes
Keywords
local
scheme
local scheme
scheme local

Configuring user role authentication

Step
1.
Enter system view.
2.
Set an authentication
mode.
3.
Set a local
authentication
password for a user
role.
Authentication mode
Local password
authentication only
(local-only)
Remote AAA authentication
through HWTACACS or
RADIUS (remote-only)
Local password
authentication first, and
then remote AAA
authentication
(local-then-remote)
Remote AAA authentication
first, and then local
password authentication
(remote-then-local)
Command
system-view
super authentication-mode
{ local | scheme } *
In non-FIPS mode:
super password [ role
rolename ] [ { hash |
simple } password ]
In FIPS mode:
super password [ role
rolename ]
Description
The device uses the locally configured password for
authentication.
If no local password is configured for a user role in this
mode, an AUX user can obtain the user role authorization
by either entering a string or not entering anything.
The device sends the username and password to the
HWTACACS or RADIUS server for remote authentication.
To use this mode, you must perform the following
configuration tasks:
Configure the required HWTACACS or RADIUS
scheme, and configure the ISP domain to use the
scheme for the user. For more information, see Security
Configuration Guide.
Add the user account and password on the
HWTACACS or RADIUS server.
Local password authentication is performed first.
If no local password is configured for the user role in this
mode:
The device performs remote AAA authentication for
VTY users.
An AUX user can obtain a temporary user role by either
entering a string or not entering anything.
Remote AAA authentication is performed first. If the
HWTACACS or RADIUS server does not respond, or the
remote AAA configuration on the device is invalid, local
password authentication is performed.
Remarks
N/A
By default, local-only authentication applies.
Use this step for local password authentication.
By default, no password is configured.
If you do not specify the role rolename option,
the command sets the password for
network-admin.
60

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents