Configuring Temporary User Role Authorization; Configuration Guidelines - HP 10500 Series Configuration Manual

Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

SSH clients that use publickey or password-publickey authentication. User roles assigned to these
SSH clients are specified in their respective device management user accounts.
For more information about user lines, see "Login overview" and "Configuring CLI login." For more
information about SSH, see Security Configuration Guide.
To assign a user role to non-AAA authentication users on a user line:
Step
1.
Enter system view.
2.
Enter user line view or user
line class view.
3.
Specify a user role on the
user line.

Configuring temporary user role authorization

Temporary user role authorization allows you to obtain another user role without reconnecting to the
device. This feature is useful when you want to use a user role temporarily to configure a feature.
Temporary user role authorization is effective only on the current login. This feature does not change the
user role settings in the user account that you have been logged in with. The next time you are logged in
with the user account, the original user role settings take effect.

Configuration guidelines

When you configure temporary user role authorization, follow these guidelines:
Command
system-view
Enter user line view:
line { first-num1 [ last-num1 ] |
{ aux | vty } first-num2
[ last-num2 ] }
Enter user line class view:
line class { aux | vty }
user-role role-name
25
Remarks
N/A
For information about the priority
order and application scope of the
configurations in user line view and
user line class view, see "Logging into
the CLI."
Repeat this step to specify a maximum
of 64 user roles on a user line.
The following default settings apply:
The network-admin user role is
specified on the AUX user line for
default-MDC login users. The
network-operator user role is
specified on any other user line
for default-MDC login users.
The network-admin user role of
default-MDC login users changes
to mdc-admin after the users use
the switchto mdc command to log
into non-default MDCs.
The mdc-operator user role is
specified on user lines for other
non-default MDC login users.
The device cannot assign the
security-audit user role to non-AAA
authentication users.

Advertisement

Table of Contents
loading

Table of Contents