R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
263
If the authentication method is password, you do not need to create an SSH user or local user. However,
if you want to display all SSH users, including the password-only SSH users, for centralized management,
you can use this command to create them.
If you use the ssh user command to configure a host public key for a user who has already had a host
public key, the new one overwrites the old one.
You can change the authentication method, service type, and host public key for an SSH user when the
user is communicating with the SSH server, but your changes take effect only on the clients at the next
login.
For an SFTP or SCP user, the working directory depends on the authentication method:
If the authentication method is password, the working directory is authorized by AAA.
If the authentication method is publickey or password-publickey, the working directory is specified
by the authorization-attribute command in the associated local user view.
For an SSH user, the user role also depends on the authentication method:
If the authentication method is password, the user role is authorized by the remote AAA server or
the local device.
If the authentication method is publickey or password-publickey, the user role is specified by the
authorization-attribute command in the associated local user view.
Examples
# Create an SSH user named user1, set the service type sftp and the authentication method
password-publickey, and assign a host public key named key1 to the user.
<Sysname> system-view
[Sysname] ssh user user1 service-type sftp authentication-type password-publickey assign
publickey key1
# Create a local device management user named user1, set the password as 123456TESTplat&! in plain
text and the service type as ssh, and assign the working directory as flash:, the user role as
network-admin.
[Sysname] local-user user1 class manage
[Sysname-luser-manage-user1] password simple 123456TESTplat&!
[Sysname-luser-manage-user1] service-type ssh
[Sysname-luser-manage-user1] authorization-attribute work-directory flash: user-role
network-admin
Related commands
authorization-attribute
display ssh user-information
local-user
SSH client commands
bye
Use bye to terminate the connection with an SFTP server and return to user view.
Syntax
bye