Chapter4MonthlyMaintenanceItems
4.4CheckingUserSecurityManagement
Purpose
Thistopicdescribeshowtochecktheusersecuritymanagementcongurationtoconrm
thesystemadministratoridentities.
Steps
1.Checktheusernamesandthepasswords.
2.Checktheenablepasswords.
ReferenceStandards
Runtheshowrunning-configadm-mgrcommandtochecktheusernamesandthe
passwords.
Innormalsituations,theuserpasswordsaredisplayedintheencryptedformat.Consider
thefollowingsuggestionswhilesettingthepassword.
lDonotusesimplewordssuchaszte,zxr10andwhoasusernames.
lSetauserpasswordwithatleast6bits.Setthepasswordcontainingatleasttwoof
thefollowingtypes:number,lowercase,uppercaseandspecialcharacter.
Iftheuserpasswordsarenotdisplayedwithintheencryptedformat,itisnecessaryto
encryptthem.
Forexample:
ZXR10#showrunning-configadm-mgr
system-user
authentication-template1
bind-authentication-template2001
$
authorization-template1
bind-authorization-template2001
local-privilege-level15
$
usernamezte-L15
bindauthentication-template1
bindauthorization-template1
passwordencryptede09a66ada5ddf9e2c17976f988fa508b43c2b6636096567
d62fac3390409d8b2authentication-template1authorization-template1
4-3
SJ-20150114102049-013|2015-01-15(R1.0)ZTEProprietaryandCondential