Cisco Systems XR manual Defines a method list for authentication, Adds a user to a group, SR-98

Page 98

Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software

username

From global configuration mode, you can display all the configured usernames. However, you cannot display all the configured usernames in username configuration mode.

Each user is identified by a username that is unique across the administrative domain. Each user should be made a member of at least one user group. Deleting a user group may orphan the users associated with that group. The AAA server authenticates orphaned users but most commands are not authorized.

If you want to require a username and password on the console or for Telnet sessions, configure authentication using both the aaa authentication login default local command and the username command.

The predefined group root-system may be specified only by root-system users while administration is configured.

Note To enable the local networking device to respond to remote CHAP challenges, one username command entry must be the same as the hostname entry that has already been assigned to the other networking device.

Task ID

Examples

Task ID

Operations

aaa

read, write

 

 

The following example shows how to establish the unencrypted password password1 for the user user1:

RP/0/RP0/CPU0:router# configure

RP/0/RP0/CPU0:router(config)# username user1

RP/0/RP0/CPU0:router(config-un)# password 0 password1

Related Commands

Command

Description

 

aaa authentication

Defines a method list for authentication.

 

 

 

 

group

Adds a user to a group.

 

 

 

 

password (AAA)

Creates a login password for a user.

 

 

 

Cisco IOS XR System Security Command Reference

SR-98

Image 98
Contents SR-1 Aaa accounting SR-2SR-3 Creates a method list to be used for authorizationAaa Read, write Aaa accounting system default SR-4SR-5 Creates a method list for authenticationCreates a method list for authorization Aaa authentication SR-6SR-7 Radius, group named-group,local, or line optionsCreates a method list for accounting Command Description SR-8Local Aaa authorizationNetwork SR-9SR-10 Which specifies that TACACS+ authorization is used SR-11Aaa default-taskgroup SR-12Aaa group server radius SR-13Comprises three member servers SR-14Aaa group server tacacs+ SR-15SR-16 SR-17 Aaa accounting commandAccounting List named listname2 on a line template named configure SR-18SR-19 AuthorizationAuthorization command Listname4 on a line template named configure SR-20SR-21 Deadtime server-group configurationDeadtime minutes no deadtime Related Commands Description SR-22SR-23 Description AAADescription string No description Taskgroup SR-24Group SR-25Task ID Examples SR-26Inherit taskgroup SR-27SR-28 SR-29 Inherit usergroupInherit usergroup usergroup-name Sales user group SR-30SR-31 Login authenticationAuthentication login command SR-32 SR-33 Password AAAPassword 0 7 password No password 0 7 password SR-34 Radius-server dead-criteria time SR-35SR-36 Radius-server dead-criteria tries SR-37Dead-criteria time SR-38SR-39 Radius-server deadtimeRadius-server deadtime minutes No radius-server deadtime SR-40 Retransmit retries Timeout secondsRadius-server host SR-41SR-42 SR-43 Radius-server key SR-44Specifies a Radius server host SR-45Radius-server retransmit SR-46SR-47 Radius-server timeoutRadius-server timeout seconds No radius-server timeout Radius source-interface SR-48Outgoing Radius packets SR-49SR-50 SecretSecret 0 5 secret no secret 0 5 secret SR-51 Server Radius SR-52SR-53 Server TACACS+ SR-54Groups different TACACS+ server hosts into distinct lists SR-55Show aaa SR-56SR-57 Aaa usergroup operatorSR-58 Displays task IDs enabled for the currently logged-in user SR-59Show radius If no radius servers are configured, no output is displayedShow radius SR-60Field Description SR-61SR-62 Show radius accountingShow radius accounting Show radius authentication SR-63SR-64 Show radius authenticationShow radius authentication Show radius accounting SR-65SR-66 Show radius clientShow radius client SR-67 Show radius dead-criteria SR-68SR-69 Show radius server-groups No default behavior or valuesShow radius server-groups SR-70Field Description SR-71SR-72 Show tacacsShow tacacs SR-73 SR-74 Show tacacs server-groupsShow tacacs server-groups SR-75 SR-76 Show task supportedShow task supported SR-77 Ouni pkg-mgmt pos-dpt pppShow user SR-78SR-79 User allSR-80 SR-81 Tacacs-server host SR-82SR-83 SR-84 Tacacs-server keyTacacs-server key key-nameno tacacs-server key Specifies a TACACS+ host SR-85SR-86 Tacacs-server timeoutTacacs-server timeout seconds No tacacs-server timeout Tacacs source-interface SR-87Aaa group server radius SR-88Execute TaskWrite DebugSR-90 Taskgroup SR-91SR-92 Creates a task group description in task configuration modeAdds a task ID to a task group Timeout login response SR-93Enables AAA authentication for logins SR-94Usergroup SR-95Creates a description of a task group during configuration SR-96Username SR-97Adds a user to a group Defines a method list for authenticationCreates a login password for a user SR-98Users group SR-99Given operator privileges SR-100