Fabric OS 5.2.x administrator guide
67
Creating Fabric OS user accounts
With RADIUS servers, set up user accounts by their true network wide identity rather than by the account
names created on a Fabric OS switch. Along with each account name, assign appropriate switch access
roles.
RADIUS supports all the defined RBAC roles described in
Table 9
on page 55.
Users must enter their assigned RADIUS account name and password when logging in to a switch that has
been configured with RADIUS. After the RADIUS server authenticates a user, it responds with the assigned
switch role in a
Vendor-Specific Attribute
(VSA). If the response does not have a VSA role assignment, the
“user” role is assigned. If no Administrative Domain is assigned then they are assigned to the default
Admin Domain AD0.
The syntax used for assigning VSA-based account switch roles on a RADIUS server is described in
Table 14
.
Table 14
Syntax for VSA-based account roles
Item
Value
Description
Type
26
1 octet
Length
7 or higher
1 octet, calculated by the server
Vendor ID
1588
4 octet, Brocade's SMI Private Enterprise Code
Vendor type
1
1 octet, Brocade-Auth-Role; valid attributes for the
Brocade-Auth-Role are:
SwitchAdmin
ZoneAdmin
FabricAdmin
BasicSwitchAdmin
Operator
User
Admin
2
Optional:
Specifies the Admin Domain member list. See
”
RADIUS configuration and admin domains” on page 69
.
Brocade-AVPairs1
3
Brocade-AVPairs2
4
Brocade-AVPairs3
5
Brocade-AVPairs4
Vendor length
2 or higher
1 octet, calculated by server, including vendor-type and
vendor-length
Attribute-specific data
ASCII string
multiple octet, maximum 253, indicating the name of assigned
role and other supported attribute values such as Admin
Domain member list.
Summary of Contents for AE370A - Brocade 4Gb SAN Switch 4/12
Page 18: ...18 ...
Page 82: ...82 Managing user accounts ...
Page 102: ...102 Configuring standard security features ...
Page 126: ...126 Maintaining configurations ...
Page 198: ...198 Routing traffic ...
Page 238: ...238 Using the FC FC routing service ...
Page 260: ...260 Administering FICON fabrics ...
Page 280: ...280 Working with diagnostic features ...
Page 332: ...332 Administering Extended Fabrics ...
Page 414: ...398 Configuring the PID format ...
Page 420: ...404 Configuring interoperability mode ...
Page 426: ...410 Understanding legacy password behaviour ...
Page 442: ...426 ...
Page 444: ......
Page 447: ......