cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
891
Views
0
Helpful
1
Replies

NxOS and Role Based Authorization

nsheridan
Level 1
Level 1

Guys,

Basic setup - using default default user admin I login and no problems - commands such as show mod and config changes, no problem: role =

network-admin

I create a user account with the same role as the admin user and I cannot issue the same commands - permission denied?

Stumped - any ideas what's missing here?

Thanks

1 Reply 1

nsheridan
Level 1
Level 1

Out of desperation, I tried combinations of shorter usernames, similar to the admin username

The result - for whatever reason it seems (I cannot confirm as such) if you use usernames for authentication locally in excess of 8 characters you cannot get full network-admin role privilidges

even though when you do a show user-account, it displays your full username and the correct role.

It seems almost as if the authenticaion element works, but the the role categorisation seems to fail for whatever reason (what I would call authorisation).

Feels like a bug to me, anyway putting it on tacacs tomorrow hopefully with different results

I am running 4.2(1)SV1(4) on an nexus 1000v.  I hope this saves you some time.

Apologies if this is a known issue or "feature" - but I was not aware of it. 

Review Cisco Networking for a $25 gift card