pwd

Collection of password-related attribs. The attribs are used to confirm the SuperUser password and enable the service mode used by support personnel. For information about managing users including user groups, passwords, and security levels, see the “Administration” chapter in the SMS User Guide.

Related Command users

Table 3-14 pwd Attributes

Attribute

Description

Type

Access

Range

 

 

 

 

 

pwd.group-adduser

Used to add a user to a user group.

String

write-only

 

 

 

 

 

 

pwd.group-deluser

Used to remove a user from a user group.

String

write-only

 

 

 

 

 

 

pwd.group-list

Used to list all groups, or groups with

String

read-only

 

 

users.

 

 

 

 

 

 

 

 

pwd.level

Attribute used to set the security level for

Int

read-write

 

 

the password.

 

 

 

 

 

 

 

 

pwd.service-enable

Used to enable/disable the service mode

Bool

read-write

0

 

password for the system.

 

 

 

 

To protect customer security, the service

 

 

 

 

mode is deactivated at the factory. To

 

 

 

 

enable the service mode account, the

 

 

 

 

customer must log in with an account that

 

 

 

 

has SuperUser rights and set this attrib to

 

 

 

 

yes. After service mode is enabled, a

 

 

 

 

service professional can log in to the

 

 

 

 

system with a secret one-time password.

 

 

 

 

To disable service mode, set the attrib to

 

 

 

 

no.

 

 

 

 

To clear this value, use a period (.).

 

 

 

 

Example:

 

 

 

 

set pwd.service-enable=false

 

 

 

 

 

 

 

 

pwd.user-add

Used to add a user and specify the user’s

String

write-only

 

 

default user group. User names must

 

 

 

 

comply with the rules defined by

 

 

 

 

pwd.level. You must also specify a user

 

 

 

 

group in the form of

 

 

 

 

?usergroup=username.

 

 

 

 

Example:

 

 

 

 

set pwd.user-add?superuser=

 

 

 

 

johnsmith

 

 

 

 

 

 

 

 

pwd.user-age

Attribute used to set the maximum age for

Int

read-write

 

 

a password.

 

 

 

 

 

 

 

 

pwd.user-del

Used to delete a user.

String

write-only

 

 

 

 

 

 

pwd.user-desc

Attribute used to describe the user

String

read-write

 

 

account.

 

 

 

 

 

 

 

 

pwd.user-email

Attribute used for the user account email

Email

read-write

 

 

address.

 

 

 

 

 

 

 

 

Security Management System CLI Reference 35

Page 45
Image 45
HP TippingPoint Next Generation Firewall manual Pwd