Users Guide

Table Of Contents
580 | Management Access Dell PowerConnect W-Series ArubaOS 6.1 | User Guide
password-lock-out
password-lock-out-time
password-max-character-repeat.
password-min-digit
password-min-length
password-min-lowercase-characters
password-min-special-character
password-min-uppercase-characters
password-not-username
Management Authentication Profile Parameters
Table 115 describes configuration parameters on the Management Authentication profile page.
Managing Certificates
The Dell controller is designed to provide secure services through the use of digital certificates. Certificates
provide security when authenticating users and computers and eliminate the need for less secure password-based
authentication.
There is a default server certificate installed in the controller to demonstrate the authentication of the controller
for captive portal and WebUI management access. However, this certificate does not guarantee security in
production networks. Dell strongly recommends that you replace the default certificate with a custom certificate
issued for your site or domain by a trusted Certificate Authority (CA). This section describes how to generate a
Certificate Signing Request (CSR) to submit to a CA and how to import the signed certificate received from the
CA into the controller.
The controller supports client authentication using digital certificates for specific user-centric network services,
such as AAA FastConnect (see), VPN (see Chapter 17, “Virtual Private Networks”), and WebUI and SSH
management access. Each service can employ different sets of client and server certificates.
NOTE: In the CLI, you configure these options with the aaa authentication mgmt and aaa-server-group commands.
Table 115 Management Authentication Profile Parameters
Parameter Description
Enable Enables authentication for administrative users.
Default Role Select a predefined management role to assign to authenticated administrative users:
Root Default superuser role
guest-
provisioning
Guest provisioning role
location-api-mgmt Location API role
network-
operations
Network operations role
no-access No commands are accessible for this role
read-only Read-only role
no access Negates any configured parameter.
Server Group Name of the group of servers used to authenticate administrative users. See the CLI command aaa-server-
group,intheCLI Command Reference Guide for more information..