30
Configuring user role authentication
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set an
authentication
mode.
super authentication-mode
{
local
|
scheme
}
*
By default, local-only authentication applies.
3.
(Optional.) Specify
the default target
user role for
temporary user role
authorization.
super default role
role-name
The following default settings apply:
•
For default-MDC login users, the default
target user role is network-admin.
•
For non-default-MDC login users, the
default target user role is mdc-admin.
4.
Set a local
authentication
password for a user
role.
•
In non-FIPS mode:
super password
[
role
role-name
] [ {
hash
|
simple
}
string
]
•
In FIPS mode:
super password
[
role
role-name
]
Use this step for local password authentication.
By default, no password is set.
If you do not specify the
role
role-name
option,
the command sets a password for the default
target user role.
Obtaining temporary user role authorization
Perform the following task in user view:
Task
Command
Remarks
Obtain the temporary
authorization to use a
user role.
super
[
role-name
]
If you do not specify the
role-name
argument, you
obtain the default target user role for temporary user
role authorization.
The operation fails after three consecutive
unsuccessful password attempts.
The user role must have the permission to execute the
super
command to obtain temporary user role
authorization.
Displaying and maintaining RBAC settings
Execute
display
commands in any view.
Task
Command
Display user role information.
display role
[
name role-name
]
Display user role feature
information.
display role feature
[
name
feature-name
|
verbose
]
Display user role feature group
information.
display role feature-group
[
name feature-group-name
]
[
verbose
]
Содержание FlexNetwork 10500 Series
Страница 139: ...130 Sysname display version ...