<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Eddy, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854165#M40152</link>
    <description>&lt;P&gt;Eddy,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please enable debugs for aaa authentication and radius on the Nexus, then log in twice (i.e., a successful and a failed attempt) and show us the output?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2016 12:30:39 GMT</pubDate>
    <dc:creator>Javier Henderson</dc:creator>
    <dc:date>2016-03-01T12:30:39Z</dc:date>
    <item>
      <title>Remove user-account in n9k from AAA remote auth</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854164#M40151</link>
      <description>&lt;P&gt;I have configured AAA authentication using RADIUS in N9k.&lt;/P&gt;
&lt;P&gt;It works fine for first login but after that it fails. I suspect because the user-account in n9k cached it as network-operator.&lt;/P&gt;
&lt;P&gt;After the first login, i configured the radius server to reply using network-admin role.&lt;/P&gt;
&lt;P&gt;show user-account&lt;/P&gt;
&lt;P&gt;user:testuser&lt;BR /&gt; roles:network-operator&lt;BR /&gt;account created through REMOTE authentication&lt;BR /&gt;Credentials such as ssh server key will be cached temporarily only for this user&lt;BR /&gt; account&lt;BR /&gt;Local login not possible&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a way to remove this user-account &amp;nbsp;or setup a timeout?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854164#M40151</guid>
      <dc:creator>eddychristian10</dc:creator>
      <dc:date>2019-03-11T06:32:07Z</dc:date>
    </item>
    <item>
      <title>Eddy,</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854165#M40152</link>
      <description>&lt;P&gt;Eddy,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please enable debugs for aaa authentication and radius on the Nexus, then log in twice (i.e., a successful and a failed attempt) and show us the output?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 12:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854165#M40152</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2016-03-01T12:30:39Z</dc:date>
    </item>
    <item>
      <title>Below the output:</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854166#M40153</link>
      <description>&lt;P&gt;Below the output for failed attempt.&lt;/P&gt;
&lt;P&gt;I need to get the user to try again using other username.&lt;/P&gt;
&lt;P&gt;016 Mar 1 06:57:19 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: Unable to create&lt;BR /&gt; temporary user testuser. Error 0x404a000a usermod: group 'testuser' does not exist&lt;BR /&gt;r/home/admin/.ssh/admin': File exists (100663296) - login[807]&lt;BR /&gt;2016 Mar 1 06:57:19 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authenti&lt;BR /&gt;cation failed for user testuser from 172.16.74.23 - login[807]&lt;BR /&gt;2016 Mar 1 06:57:28 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: Unable to create&lt;BR /&gt; temporary user testuser. Error 0x404a000a usermod: group 'testuser' does not exist&lt;BR /&gt;(100663296) - login[807]&lt;BR /&gt;2016 Mar 1 06:57:28 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authenti&lt;BR /&gt;cation failed for user testuser from 172.16.74.23 - login[807]&lt;BR /&gt;2016 Mar 1 06:57:59 TWR5_SVR_RM_9300_1 %AUTHPRIV-2-SYSTEM_MSG: pam_unix(login:s&lt;BR /&gt;ession): close_session - error recovering username - login[807]&lt;BR /&gt;2016 Mar 1 06:58:32 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: Unable to create&lt;BR /&gt; temporary user testuser. Error 0x404a000a usermod: group 'testuser' does not exist&lt;BR /&gt;(100663296) - login[820]&lt;BR /&gt;2016 Mar 1 06:58:32 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authenti&lt;BR /&gt;cation failed for user testuser from 172.16.74.23 - login[820]&lt;BR /&gt;2016 Mar 1 07:08:27 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: Unable to create&lt;BR /&gt; temporary user testuser. Error 0x404a000a usermod: group 'testuser' does not exist&lt;BR /&gt;(100663296) - login[1128]&lt;BR /&gt;2016 Mar 1 07:08:27 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authenti&lt;BR /&gt;cation failed for user testuser from 172.16.74.23 - login[1128]&lt;BR /&gt;2016 Mar 1 07:08:36 TWR5_SVR_RM_9300_1 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authenti&lt;BR /&gt;cation failed for user exit from 172.16.74.23 - login[1128]&lt;BR /&gt;2016 Mar 1 07:08:41 TWR5_SVR_RM_9300_1 %AUTHPRIV-2-SYSTEM_MSG: pam_unix(login:s&lt;BR /&gt;ession): close_session - error recovering username - login[1128]&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;it was cleared by rebooting the switch and i managed to login successfully using network-admin role now. Before, It tried to add same username locally but it rejected because it was created by remote auth. "no username &amp;lt;user&amp;gt;" also didn't clear the user-account.&lt;/P&gt;
&lt;P&gt;There should be a way to clear it out or set a timeout value. Anyone facing the same issue in n9k?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 09:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854166#M40153</guid>
      <dc:creator>eddychristian10</dc:creator>
      <dc:date>2016-03-02T09:46:12Z</dc:date>
    </item>
    <item>
      <title>just for anyone who is having</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854167#M40154</link>
      <description>&lt;P&gt;just for anyone who is having the same problem. It's caused by a bug.&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/12763251/how-could-remove-cache-user-account-nexus-9k&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2016 04:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/2854167#M40154</guid>
      <dc:creator>eddychristian10</dc:creator>
      <dc:date>2016-03-15T04:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Below the output:</title>
      <link>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/3860478#M40155</link>
      <description>&lt;P&gt;YES. Yes I'm facing the same issue now and rebooting the switch fixed it for me. I tried this out in my lab switches to verify that reloading fixes the issue. But I can't possibly do this to hundreds of production switches. So...I may have to open a TAC case for this.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 20:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remove-user-account-in-n9k-from-aaa-remote-auth/m-p/3860478#M40155</guid>
      <dc:creator>David Carrasco</dc:creator>
      <dc:date>2019-05-21T20:36:01Z</dc:date>
    </item>
  </channel>
</rss>

