User Accounts Overview

You can create accounts for local users with passwords. Account passwords are encrypted. You can assign privilege levels to local user accounts.

Up to 32 local user accounts can be defined on a RUCKUS device. User accounts regulate who can access the management functions in the CLI.

For each local user account, you specify a user name and password. You also can specify the management privilege level, which can be one of the following:

  • 0 - Super User level (default) - Allows complete read-and-write access to the system. This is generally for system administrators and is the only privilege level that allows you to configure passwords.

  • 4 - Port Configuration level - Allows read-and-write access for specific ports, but not for global parameters.

  • 5 - Read Only level - Allows access to the Privileged EXEC mode and User EXEC mode with read access only.
  • 6 - Cloud User
  • 7 - No Syslog Read - Allows access to the Privileged EXEC mode and User EXEC mode with read access only, but does not allow viewing of syslog information when using the show logging command.

User Account Guidelines

Be aware of the following guidelines for user accounts.

  • If the message of the day (MOTD) is configured, it will be displayed after the SSH, or console session is successfully authenticated. The MOTD is configured using the banner motd command.
  • Users are locked out (disabled) if they fail to log in after three attempts (the default setting). This feature is automatically enabled. Use the disable-on-login-failure command to change the number of login attempts (up to 10) before users are locked out.
  • Error messages are displayed when the username or password for SSH or Enable mode authentication is incorrect; however, the reason for failure is not specified.

Password Combination Rules

When the device is powered on for the first time without the startup configuration, the device will prompt the user to change the default admin username and password. The username and password must be different from each other. You must enter a minimum of nine characters and up to 60 characters containing the following combinations when you create and enable a user password:

  • At least one upper-case character
  • At least one lower-case character
  • At least one numeric character
  • At least one special character; allowed characters: !, @, #, $, %, ^, &, (, and )
Note: Password character minimum and combination requirements are strictly enforced.

Password Masking

By default, when you use the CLI to create a user password, the password displays on the console as you type it. For enhanced security, you can configure the RUCKUS device to mask the password characters entered at the CLI.

To enable password masking, enter the following commands.
device# configure terminal
device(config)# enable user password-masking

The following example shows the CLI behavior when a username and password are configured with password masking enabled. A username may contain up to 48 characters; the following characters are not allowed: #, {, }, and ;.

device# configure terminal
device(config)# username kelly password
Enter Password: 
Note: When password masking is enabled, press the Enter key before entering the password, and enter the password when prompted.

Password Aging

For enhanced security, password aging enforces quarterly updates of all user passwords. After 90 days, the CLI automatically prompts users to change their passwords when they attempt to sign on.

When password aging is enabled, the software records the system time that each user password was configured or last changed. The time displays in the output of the show running-config command, indicated by set-time.

device# show running-config
Current configuration:
....
username waldo password .....
username raveen set-time 2086038248
....

A username set-time configuration is removed in the following cases:

  • The username and password are deleted from the configuration
  • The username password expires

When a username set-time configuration is removed, it no longer appears in the show running-config output.

Note: If a username does not have an assigned password, the username does not have a set-time configuration.

Password History

By default, a RUCKUS device stores each user's last five passwords; however, you can configure the device to store up to 15 passwords for each user using the enable user password-history command. This password history is for security purposes. When changing a user password, the user cannot use any of the previously configured passwords. If a user attempts to use a stored password, the system prompts the user to choose a different password.

User Login Attempts

If a user fails to log in to the device after a configured number of login attempts (by default, 3 attempts), the user is locked out until the recovery timer expires.. You can configure the maximum number of invalid login attempts a user can make before being locked out (allowed values are 1 through 10).

You can also configure a recovery time for user accounts (by default, 3 minutes or 180 seconds) to allow disabled users to reattempt login. Only a valid login attempt re-enables the account. The configured recovery time is applicable for all user accounts and can be configured in the range of 3 through 120 minutes. If your user account is locked, wait for the recovery time to pass. If you attempt to log in again, the timer will reset and start over.

The following example configures user account lockout after three failed login attempts. It also configures recovery time as 40 seconds. Only a valid login attempt after the recovery time has elapsed can unlock and reset the account.

device(config)# enable user disable-on-login-failure 3 login-recovery-time in-secs 40

To manually re-enable a user account, you can perform one of the following actions:

  • Reboot the device to re-enable all locked-out users.
  • Enter the username name-string enable command to re-enable a specific user account.
    Note: You must have user privilege level 0 to re-enable other users with this command.

Password Expiration

You can set a user password to expire. Once a password expires, you must assign a new password to the user. The days before expiration can be set as a value from 1 through 365. The default is 90 days.

The expiry details of the user password can be viewed using the show users command.

device(config)# user test expires 10
device(config)# show users
Username               Password                             Encrypt   Priv  Status   Expire Time
==================================================================================================
super                  $6$e11fe691$ef41oRXXgrXi1x1auOXjZ     enabled   0    enabled    90 days
king                   $6$f1022451$kswy2/kA6/DvtwDyvAnuQ     enabled   0    enabled    90 days
king2                  $6$1aaeeaea$KVc5t3yYjecJ5rq436x27     enabled   0    enabled    90 days
test                   $6$M78fhauw$RVzyUnnhbexquwNptMH6H     enabled   0    enabled    10 days
test1                  $6$M78fhauw$RVzyUnnhbexquwNptMH6H     enabled   0    enabled    90 days