username

Creates or updates a user account.
Syntax
username username-string { access-time begin-time to end-time | create-password password-string | enable | expires days | password password-string | privilege privilege-level { create-password password-string | password password-string } }
no username username-string { access-time begin-time to end-time | create-password password-string | enable | expires days | password password-string | privilege privilege-level { create-password password-string | password password-string } }
Command Default

The user account is not created.

Parameters
username-string
The configured username. You can enter up to 48 characters. The following characters are not allowed: #, {, }, and ;.
access-time begin-time to end-time
Configures the access permission for a specified period of time of the day, that is, between the specified beginning access time and ending access time.
create-password password-string
Creates an encrypted password for the user. You can enter up to 48 characters.
enable
Enables the user for login access after the login access is disabled.
expires days
Configures the password expiration time in days. Valid values range from 1 through 365. The default is 90.
privilege privilege-level
Sets the user's privilege level. The default privilege level is 0. You can specify one of the following levels:
0
Super User level (full read-write access).
4
Port Configuration level.
5
Read Only level.
6
Cloud user.
7
Does not have permission to read syslogs.
password password-string
Creates an encrypted password for the user. You can enter up to 48 characters.
Modes

Global configuration mode

Usage Guidelines

You must be logged in with Super User access (privilege level 0) to add or delete user accounts or configure or modify other access parameters.

When a user is given a privileged level of 7, they cannot obtain view syslog information when using the show logging command. They will see the following: "ERROR: This user does not have permissions to read syslog."

By default, user account details can be deleted or modified without any authentication. Unauthorized deletion or modification of the user account can be prevented using the service local-user-protection command. If the user account security is enabled using the service local-user-protection command, deletion of user accounts or changing the password or privilege level of the user is permitted only upon successful validation of the existing user password.

If the enable strict-password-enforcement command is enabled on the device, for the password string, you must enter a minimum of 15 characters containing the following combinations:

  • At least two uppercase characters
  • At least two lowercase characters
  • At least two numeric characters
  • At least two special characters

You can use the show user command to display the user account details.

The no form of the command removes the user or the other user parameters.

Examples

The following example configures the privilege level of Super User access (0) for a user.

device# configure terminal
device(config)# username user1 privilege 0 password *******

The following example configures an encrypted password for a user.

device# configure terminal
device(config)# username user1 create-password xpassx

The following example configures the access time for a user.

device# configure terminal
device(config)# username user1 access-time 00:00:00 to 12:00:00

The following example enables a user account if it is disabled.

device# configure terminal
device(config)# username user1 enable 

The following example sets the user password to expire in 30 days.

device# configure terminal
device(config)# username user expires 30

The following example prompts the user to confirm existing password before successful password modification.

device(config)# username user1 password xpassx
device(config)# service local-user-protection
device(config)# username user1 password ypasswordy
User already exists. Do you want to modify: (enter 'y' or 'n'): y
To modify or remove user, enter current password: ******

The following example sets the user privilege to 7, so that the specified user cannot access or read syslogs using the show logging command.

device# configure terminal
device(config)# username user privilege 7 password pass
History
Release version Command history
08.0.40 This command was modified to prompt the user to enter a valid password before deleting a user account or modifying the password or privilege level of the user.
09.0.00 This command was modified to remove the nopassword option. The command was modified to encrypt all created passwords.
09.0.00a This command was modified so that a user privilege of 7 can be applied. When this is configured, the specified user cannot access the output of the show logging command.
10.0.10d This command was modified to disallow use of the colon character (:) in usernames.
10.0.10f This command was modified to remove the following characters from username-string syntax: (#), ({), (}), or (;).