HP StorageWorks Fabric OS 6.2 administrator guide (5697-0016, May 2009)

Fabric OS 6.2 administrator guide 71
Local database user accounts
User add, change, and delete operations are subject to the subset rule: An admin with ADlist 0-10 or
LFlist 1-10 cannot perform operations on an admin, user, or any role with an ADlist 11-25 or LFlist 11-128.
The user account being changed must have an ADlist or LFlist that is a subset of the account that is making
the change.
In addition to the default administrative and user accounts, Fabric OS supports up to 252 user-defined
accounts in each Logical Switch (domain). These accounts expand your ability to track account access and
audit administrative activities.
Default accounts
Table 12 lists the predefined accounts offered by Fabric OS that are available in the local switch user
database. The password for all default accounts for each switch should be changed during the initial
installation and configuration.
Admin Domain and Virtual Fabric considerations: Administrators can act on another account only if that
account has an Admin Domain or Logical Fabric list that is a subset of the administrator.
Displaying account information
1. Connect to the switch and log in using an account assigned to the admin role.
2. Enter the appropriate show operands for the account information you want to display:
•Enter userConfig
--show -a to show all account information for a Logical Switch.
•Enter userConfig
--show username to show account information for the specified account.
•Enter userConfig
--showad -a adminDomain_ID to show all accounts permitted to select
the specified adminDomain_ID.
•Enter userConfig
--showlf -l logicalFabric_ID for each LF in an LF_ID_list, displays a
list of users that include that LF in their LF permissions.
Creating an account
1. Connect to the switch and log in using an account assigned to the admin role.
2. Enter the following command:
userConfig --add username -r role [-l LF_ID_list] [-h VF_ID | AD_ID]
[-a AD_ID_list][-c chassis_role] [-d description] [-x]
User 4
ZoneAdmin 4
Table 11 Maximum number of simultaneous sessions (continued)
Role name Maximum sessions
Table 12 Default local user accounts
Account
name
Role Admin
Domain
Logical Fabric Description
admin Admin AD0-255
home: 0
LF1-128
home: 128
Most commands have
observe-modify permission.
factory Factory AD0-255
home: 0
LF1-128
home: 128
Reserved
root Root AD0-255
home: 0
LF1-128
home: 128
Reserved
user User AD0
home: 0
LF-128
home: 128
Most commands have
observe-only permission.