1-89
Cisco ASA Series CLI Configuration Guide
 
Chapter 1      Configuring Connection Profiles, Group Policies, and Users
  Configuring User Attributes
The default policy assigned to the SSO server is DfltGrpPolicy.
The following example creates the group policy “my-sso-grp-pol” and assigns it to the SSO server 
named “example”:
hostname(config)# group-policy my-sso-grp-pol internal
hostname(config)# group-policy my-sso-grp-pol attributes
hostname(config-group-policy)# webvpn
hostname(config-group-webvpn)# sso-server value example
hostname(config-group-webvpn)#
Configuring User Attributes
This section describes user attributes and how to configure them. It includes the following sections:
• Viewing the Username Configuration, page 70-89
• Configuring Attributes for Individual Users, page 70-89
By default, users inherit all user attributes from the assigned group policy. The ASA also lets you assign 
individual attributes at the user level, overriding values in the group policy that applies to that user. For 
example, you can specify a group policy giving all users access during business hours, but give a specific 
user 24-hour access.
Viewing the Username Configuration
To display the configuration for all usernames, including default values inherited from the group policy, 
enter the all keyword with the show running-config username command, as follows:
hostname# show running-config all username
hostname# 
This displays the encrypted password and the privilege level. for all users, or, if you supply a username, 
for that specific user. If you omit the all keyword, only explicitly configured values appear in this list. 
The following example displays the output of this command for the user named testuser:
hostname# show running-config all username testuser
username testuser password 12RsxXQnphyr/I9Z encrypted privilege 15
Configuring Attributes for Individual Users
To configure specific users, you assign a password (or no password) and attributes to a user using the 
username command, which enters username mode. Any attributes that you do not specify are inherited 
from the group policy. 
The internal user authentication database consists of the users entered with the username command. The 
login command uses this database for authentication. To add a user to the ASA database, enter the 
username command in global configuration mode. To remove a user, use the no version of this command 
with the username you want to remove. To remove all usernames, use the clear configure username 
command without appending a username.