
l A default user (i.e. "touch") is assigned a duration of 0 seconds . When additional users are created the
default duration value is 3600 seconds.
l The user creating the new user name is prompted for a password (regardless of whether they specified the
password keyword on the command line).
Deleting a User
The no user command is immediately executed and the user name is removed, with one exception: if the user
name is the only one with the admin flag enabled, the user name is not removed.
User Passwords
The password command allows a logged in user to change the password for their user name. A user name with
the admin flag can modify the password for any user name. The password itself is not permitted on the command
line, and is not displayed by a user context show command (or any eqcli command).
User Permissions
When a user attempts to access an object (cluster, server, server pool, VLAN, etc.) on Equalizer, the system
determines whether the user has permission to access the object as follows:
1. If the user’s definition has the admin flag enabled, then access is granted.
2. Otherwise, the user must have specific permission granted on the object for the access mode being
attempted. For example, if the user attempts to display a cluster, then the user must have read permission
on the cluster.
Permission to access an object is granted in one of two ways:
l The permit_object command gives the user the specified access permissions on the specified object.
l The permit_objlist command gives the user access permissions on all objects of a particular type as
listed in the object list specified on the command line.
Note - The permit_object and permit_objlist commands:
- can be used only on existing user logins.
- must be entered one at a time, on a line by themselves, with no other user context commands on the command line
So, for example, you cannot modify a user’s duration parameter and in the same command line include a
permit_object or permit_objlist command.
Using permit_object to Assign User Permissions on a Single Object
The user context permit_object command has the following syntax:
permit_object perm type object_name
The command assigns the given permission on the given object in the user context. The command
arguments are as follows:
l perm - One or more of the following permissions: read, write, delete. Multiple permissions must
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
183
Equalizer Administration Guide
Kommentare zu diesen Handbüchern