About Users; Characteristics Of Strong Passwords - HP Cisco MDS 9020 - Fabric Switch Configuration Manual

Cisco mds 9000 family cli configuration guide, release 3.x (ol-16184-01, april 2008)
Hide thumbs Also See for Cisco MDS 9020 - Fabric Switch:
Table of Contents

Advertisement

Chapter 39
Configuring Users and Common Roles
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

About Users

The passphrase specified in the snmp-server user option and the password specified username option
are synchronized (see the
page
By default, the user account does not expire unless you explicitly configure it to expire. The expire
option determines the date on which the user account is disabled. The date is specified in the
YYYY-MM-DD format.
You can configure up to a maximum of 256 users on a switch.
Note
The following words are reserved and cannot be used to configure users: bin, daemon, adm, lp, sync,
Tip
shutdown, halt, mail, news, uucp, operator, games, gopher, ftp, nobody, nscd, mailnull, rpc, rpcuser, xfs,
gdm, mtsuser, ftpuser, man, and sys.
Note
User passwords are not displayed in the switch configuration file.
If a password is trivial (short, easy-to-decipher), your password configuration is rejected. Be sure to
Tip
configure a strong password as shown in the sample configuration. Passwords are case-sensitive.
"admin" is no longer the default password for any Cisco MDS 9000 Family switch. You must explicitly
configure a strong password.
Caution
Cisco MDS SAN-OS does not support all numeric user names, whether created with TACACS+ or
RADIUS, or created locally. Local users with all numeric names cannot be created. If an all numeric user
name exists on an AAA server and is entered during login, the user is not logged in.
To issue commands with the internal keyword for troubleshooting purposes, you must have an account
Tip
that is a member of the network-admin group.

Characteristics of Strong Passwords

A strong password has the following characteristics:
OL-16184-01, Cisco MDS SAN-OS Release 3.x
"SNMPv3 CLI User Management and AAA Integration" section on
31-3).
At least eight characters long
Does not contain many consecutive characters (such as "abcd")
Does not contain many repeating characters (such as "aaabbb")
Does not contain dictionary words
Does not contain proper names
Contains both upper- and lower-case characters
Configuring User Accounts
Cisco MDS 9000 Family CLI Configuration Guide
39-11

Advertisement

Table of Contents
loading

Table of Contents