17 
Examples 
# Configure ISP domain test to use HWTACACS scheme tac for user role authentication. 
<Sysname> system-view 
[Sysname] super authentication-mode scheme 
[Sysname] domain test 
[Sysname-domain-test] authentication super hwtacacs-scheme tac 
Related commands 
•  authentication default 
•  hwtacacs scheme 
•  radius scheme 
authorization command 
Use authorization command to specify the command authorization method. 
Use undo authorization command to restore the default. 
Syntax 
In non-FIPS mode: 
authorization command { hwtacacs-scheme hwtacacs-scheme-name [ local ] [ none ] | local [ none ] | 
none } 
undo authorization command 
In FIPS mode: 
authorization command { hwtacacs-scheme hwtacacs-scheme-name [ local ] | local } 
undo authorization command 
Default 
The default authorization method of the ISP domain is used for command authorization. 
Views 
ISP domain view 
Predefined user roles 
network-admin 
Parameters 
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a 
case-insensitive string of 1 to 32 characters. 
local: Performs local authorization. 
none: Does not perform authorization. The authorization server does not verify whether the entered 
commands are permitted by the user role. The commands are executed successfully if the user role has 
permission to the commands. 
Usage guidelines 
Command authorization restricts login users to execute only authorized commands by employing an 
authorization server to verify whether or not each entered command is permitted.