49
Usage guidelines
A user group consists of a group of local users and has a set of local user attributes. You can
configure local user attributes for a user group to implement centralized management of user
attributes for the local users in the group. Configurable user attributes include password control
attributes and authorization attributes.
A user group with one or more local users cannot be removed.
The system predefined user group
system
cannot be removed, but you can modify its configuration.
Examples
# Create a user group named
abc
, and enter its view.
<Sysname> system-view
[Sysname] user-group abc
[Sysname-ugroup-abc]
Related commands
display user-group
validity-date
Use
validity-date
to set the validity time of a local user.
Use
undo validity-date
to remove the configuration.
Syntax
validity-date
time
undo validity-date
Default
A local user has no validity time and no time validity checking is performed.
Views
Local user view
Default command level
3: Manage level
Parameters
time
: Validity time of the local user, in the format HH:MM:SS-MM/DD/YYYY,
HH:MM:SS-YYYY/MM/DD, MM/DD/YYYY-HH:MM:SS, or YYYY/MM/DD-HH:MM:SS. HH:MM:SS
indicates the time, where HH ranges from 0 to 23, and MM and SS range from 0 to 59. MM/DD/YYYY
or YYYY/MM/DD indicates the date, where YYYY ranges from 2000 to 2035, MM ranges from 1 to 12,
and the range of DD depends on the month. Except for the zeros in 00:00:00, leading zeros can be
omitted. For example, 2:2:0-2008/2/2 equals 02:02:00-2008/02/02.
Usage guidelines
For temporary network access requirements, create a guest account, and specify a validity time and
an expiration time for the account to control the validity of the account. When a user uses the guest
account for local authentication and passes the authentication, the access device checks whether
the current system time is between the validity time and the expiration time. If it is, the device permits
the user to access the network. Otherwise, the device denies the access request of the user.
Examples
# Set the validity time of user
abc
to 12:10:20 on April 30, 2008, and set the expiration time to
12:10:20 on May 31, 2008.
<Sysname> system-view