S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
18-7
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 18 Troubleshooting Users and Roles
User and Role Issues
Step 3
After a login attempt, use the
show logging logfile | last
command to view the most recent messages.
You should see messages such as:
2006 Mar 2 22:08:44 v_190 %AUTHPRIV-6-SYSTEM_MSG: START: telnet pid=10654 from=
::ffff:161.44.67.125
2006 Mar 3 03:08:49 v_190 %AUTHPRIV-7-SYSTEM_MSG: Got user name <testUser>
2006 Mar 3 03:08:53 v_190 %AUTHPRIV-7-SYSTEM_MSG: user testUser authenticated
2006 Mar 3 03:08:53 v_190 %AUTHPRIV-7-SYSTEM_MSG: PAM login: updating snmpv3 US
M for user testUser
2006 Mar 3 03:08:53 v_190 %AUTHPRIV-7-SYSTEM_MSG: PAM login: snmpv3 attribute v
alue (null)
2006 Mar 3 03:08:53 v_190 %AUTHPRIV-7-SYSTEM_MSG: PAM login: updating snmpv3 US
M success for user testUser
2006 Mar 3 03:08:53 v_190 %AUTH-6-SYSTEM_MSG: (login) session opened for user t
estFoo by (uid=0)
2006 Mar 3 03:08:53 v_190 %AAA-6-AAA_ACCOUNTING_MESSAGE: start:/dev/pts/1_161.4
4.67.125:testUser:
User Cannot Create Roles
Symptom
User cannot create roles.
User Cannot Create Other Users With Fabric Manager or Device Manager
Symptom
User cannot create other users with Fabric Manager or Device Manager.
Table 18-2
User Cannot Create Roles
Symptom
Possible Cause
Solution
User cannot create
roles.
User not assigned network-admin role. Assign network-admin role to the user. See the
“Verifying
Roles Using Device Manager” section on page 18-8
or the
“Verifying Roles Using the CLI” section on page 18-9
.
Table 18-3
User Cannot Create Other Users with Fabric Manager or Device Manager
Symptom
Possible Cause
Solution
User cannot create
other users.
User is not logged into Fabric Manager
or Device Manager with a privacy
password.
Log into Fabric Manager or Device Manager with a
password and a privacy password. A privacy password is
required to manage users via the GUI.
Note
If you have logged in as a network-admin using
MDS authentication, Device Manager and Fabric
Manager automatically provide the appropriate
encryption for this task, even if you did not specify
a specific privacy password.