User Accounts Overview
Up to 32 local user accounts can be defined on a RUCKUS device. User accounts regulate who can access the management functions in the CLI.
For each local user account, you specify a user name and password. You also can specify the management privilege level, which can be one of the following:
- 0 - Super User level (default) - Allows complete read-and-write access to the system. This is generally for system administrators and is the only privilege level that allows you to configure passwords.
- 4 - Port Configuration level - Allows read-and-write access for specific ports, but not for global parameters.
- 5 - Read Only level - Allows access to the Privileged EXEC mode and User EXEC mode with read access only.
- 6 - Cloud User
- 7 - No Syslog Read - Allows
access to the Privileged EXEC mode and User EXEC mode with read access only, but
does not allow viewing of syslog information when using the
show loggingcommand.
User Account Guidelines
Be aware of the following guidelines for user accounts.
- If the message of the day (MOTD)
is configured, it will be displayed after the SSH, or console session is
successfully authenticated. The MOTD is configured using the
banner motdcommand. - Users are locked out (disabled)
if they fail to log in after three attempts (the default setting). This feature
is automatically enabled. Use the
disable-on-login-failurecommand to change the number of login attempts (up to 10) before users are locked out. - Error messages are displayed when the username or password for SSH or Enable mode authentication is incorrect; however, the reason for failure is not specified.
Password Combination Rules
When the device is powered on for the first time without the startup configuration, the device will prompt the user to change the default admin username and password. The username and password must be different from each other. You must enter a minimum of nine characters and up to 60 characters containing the following combinations when you create and enable a user password:
Password Masking
By default, when you use the CLI to create a user password, the password displays on the console as you type it. For enhanced security, you can configure the RUCKUS device to mask the password characters entered at the CLI.
To enable password masking, enter the following commands.device# configure terminal device(config)# enable user password-masking
The following example shows the CLI behavior when a username and password are configured with password masking enabled. A username may contain up to 48 characters; the following characters are not allowed: #, {, }, and ;.
device# configure terminal device(config)# username kelly password Enter Password:
Password Aging
For enhanced security, password aging enforces quarterly updates of all user passwords. After 90 days, the CLI automatically prompts users to change their passwords when they attempt to sign on.
When password aging is enabled, the
software records the system time that each user password was configured or last
changed. The time displays in the output of the show running-config
command, indicated by set-time.
device# show running-config Current configuration: .... username waldo password ..... username raveen set-time 2086038248 ....
A username set-time configuration is removed in the following cases:
When a username set-time
configuration is removed, it no longer appears in the show running-config
output.
Password History
By default, a RUCKUS device stores
each user's last five passwords; however, you can configure the device to store up
to 15 passwords for each user using the enable user
password-history command. This password history is for security
purposes. When changing a user password, the user cannot use any of the previously
configured passwords. If a user attempts to use a stored password, the system
prompts the user to choose a different password.
User Login Attempts
If a user fails to log in to the device after a configured number of login attempts (by default, 3 attempts), the user is locked out until the recovery timer expires.. You can configure the maximum number of invalid login attempts a user can make before being locked out (allowed values are 1 through 10).
You can also configure a recovery time for user accounts (by default, 3 minutes or 180 seconds) to allow disabled users to reattempt login. Only a valid login attempt re-enables the account. The configured recovery time is applicable for all user accounts and can be configured in the range of 3 through 120 minutes. If your user account is locked, wait for the recovery time to pass. If you attempt to log in again, the timer will reset and start over.
The following example configures user account lockout after three failed login attempts. It also configures recovery time as 40 seconds. Only a valid login attempt after the recovery time has elapsed can unlock and reset the account.
device(config)# enable user disable-on-login-failure 3 login-recovery-time in-secs 40
To manually re-enable a user account, you can perform one of the following actions:
Password Expiration
You can set a user password to expire. Once a password expires, you must assign a new password to the user. The days before expiration can be set as a value from 1 through 365. The default is 90 days.
The expiry details of the user
password can be viewed using the show users command.
device(config)# user test expires 10 device(config)# show users Username Password Encrypt Priv Status Expire Time ================================================================================================== super $6$e11fe691$ef41oRXXgrXi1x1auOXjZ enabled 0 enabled 90 days king $6$f1022451$kswy2/kA6/DvtwDyvAnuQ enabled 0 enabled 90 days king2 $6$1aaeeaea$KVc5t3yYjecJ5rq436x27 enabled 0 enabled 90 days test $6$M78fhauw$RVzyUnnhbexquwNptMH6H enabled 0 enabled 10 days test1 $6$M78fhauw$RVzyUnnhbexquwNptMH6H enabled 0 enabled 90 days