service local-user-protection
The user account can be deleted or modified without any authentication; that is, user account security is disabled.
Global configuration mode
This command allows for the deletion of user accounts or changing the password or
privilege level of the user (using the
username command) only upon successful validation of the existing user password.
If the command is enabled and you try to delete or modify a user account using the
username, you will be prompted for confirmation to proceed. Upon confirmation, you will be
prompted to provide the existing password. The attempt to modify or delete a user
account is successful only if the correct password is entered.
The
no form of the command disables user account security; the deletion or modification
of the user account without any authentication is allowed.
The following example permits the modification of the user account password only after providing the existing password.
device(config)# username user1 password xpassx device(config)# service local-user-protection device(config)# username user1 password ypasswordy User already exists. Do you want to modify: (enter 'y' or 'n'): y To modify or remove user, enter current password: ******
The following example prevents unauthorized modification of the user account password.
device(config)# username user1 password ypasswordy device(config)# service local-user-protection device(config)# username user1 password zpassz User already exists. Do you want to modify: (enter 'y' or 'n'): y To modify or remove user, enter current password: **** Error: Current password doesn't match. Access denied
| Release version | Command history |
|---|---|
| 08.0.40 | This command was introduced. |