HP StorageWorks Fabric OS 6.1.1 administrator guide (5697-0235, December 2009)

466 Understanding legacy password behavior
Password prompting behaviors
Table 98 describes the expected password prompting behaviors of various Fabric OS versions.
Does a user need to know the
old passwords when
changing passwords using
the passwd command?
Yes, except when
the root user
changes another
user’s password.
This is standard
UNIX behavior;
Fabric OS does not
enforce any
additional security.
Old password is
required only when
changing password for
the same level user
password. Changing
password for lower level
user does not require
old password. For
example, users connect
as admin; old admin
password is required to
change the admin
password. But old user
password is not
required to change the
user password.
4.4.0 to 5.1.0 only:
Old password is
required only when
changing password for
the same level user
password. Changing
password for lower level
user does not require old
password. For example,
users connect as admin;
old admin password is
required to change the
admin password. But old
user password is not
required to change the
user password.
Can passwd change
higher-level passwords? For
example, can admin change
root password?
Yes, but will ask for
the old password of
the higher-level
account (example
root).
Yes; if users connect as
admin, they can change
the root, factory, and
admin passwords.
However, if one
connects as user, one
can only change the
user password.
4.4.0 to 5.1.0 only:
Yes, if users connect as
admin, they can change
the root, factory and
admin passwords after
first entering the old
password for the
respective account.
Can API change passwords? Yes, only for admin. Yes, only for admin. Yes, only for admin.
Can Web Tools change
passwords?
No No No
Can SNMP change
passwords?
No No No
Table 97 Account/password characteristics matrix (continued)
Topic 4.0.0 4.1.0 to 4.2.0 4.4.0 and later
Table 98 Password prompting matrix
Topic 4.0.0 4.1.0 and later
Must all password prompts be completed
for any change to take effect?
No. Partial changes of all
four passwords are allowed.
No. Partial changes of all
four passwords are allowed.
When does the password prompt
appear?
When users connect as root,
factory, or admin, the
accounts with default
password will be prompted
for change. The accounts with
non-default password will not
be prompted.
When users connect as root,
factory, or admin, the
accounts with default
password will be prompted
for change. The accounts with
non-default password will not
be prompted.
Is a user forced to answer password
prompts before getting access to the
firmware?
No, users can enter Ctrl-c to
get out of password
prompting.
No, users can enter Ctrl-c to
get out of password
prompting.
Do users need to know the old root
password when answering prompting?
Yes in 4.0.0
No in 4.0.2 only
No
Are new passwords forced to be set to
something different than the old
passwords?
Yes Yes