Check Roles

This scenario shows how to configure and use OSDx user roles.

Test Monitor Role

Description

A new user teldat is created using the predefined monitor role. This kind of role allows the execution of a reduced set of operational commands.

Scenario

Step 1: Set the following configuration in DUT0:

set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$Ubo1Ijo6tD9Kzspc$KERH6iy0mgip0ayf2TN.SuVvYZQ7lLxE8UWyHPnqkOuJvpP5h/FvCGUPirovBzCOPrHyS3IFIx/yfZka.w90t1'
set system login user teldat role monitor

Step 2: Run command service cnm restart at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 3: Run command show running at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 4: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:25:17 +00:00

Step 5: Login as admin user on DUT0.

Note

Dynamically change the required user-level for some specific operational commands.

Step 6: Modify the following configuration lines in DUT0:

set user-level 0 command 'show running'
set user-level 10 command 'show date'

Step 7: Run command service cnm restart at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 8: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:21 +00:00
# Warning: Configuration has not been saved
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$Ubo1Ijo6tD9Kzspc$KERH6iy0mgip0ayf2TN.SuVvYZQ7lLxE8UWyHPnqkOuJvpP5h/FvCGUPirovBzCOPrHyS3IFIx/yfZka.w90t1'
set system login user teldat role monitor
set user-level 0 command 'show running'
set user-level 10 command 'show date'

Step 9: Run command show date at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 10: Login as admin user on DUT0.


Test Operator Role

Description

A new user teldat is created using the predefined operator role. This kind of role allows the execution of some operational commands.

Scenario

Step 1: Set the following configuration in DUT0:

set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$9wmKRiODld/jNL6h$IyeKdq4ft3sLsieenTn3jiwdiDHxGjL79VHMdR6eR/aeCENd4qXW4eGIrjaNKdBh1uHQuCKFp/7m9SkBu8CUT1'
set system login user teldat role operator

Step 2: Run command service cnm restart at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 3: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:30 +00:00
# Warning: Configuration has not been saved
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$9wmKRiODld/jNL6h$IyeKdq4ft3sLsieenTn3jiwdiDHxGjL79VHMdR6eR/aeCENd4qXW4eGIrjaNKdBh1uHQuCKFp/7m9SkBu8CUT1'
set system login user teldat role operator

Step 4: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:25:30 +00:00

Step 5: Login as admin user on DUT0.

Note

Dynamically change the required user-level for some specific operational commands.

Step 6: Modify the following configuration lines in DUT0:

set user-level 0 command 'show running'
set user-level 10 command 'show date'

Step 7: Run command service cnm restart at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 8: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:34 +00:00
# Warning: Configuration has not been saved
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$9wmKRiODld/jNL6h$IyeKdq4ft3sLsieenTn3jiwdiDHxGjL79VHMdR6eR/aeCENd4qXW4eGIrjaNKdBh1uHQuCKFp/7m9SkBu8CUT1'
set system login user teldat role operator
set user-level 0 command 'show running'
set user-level 10 command 'show date'

Step 9: Run command show date at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 10: Login as admin user on DUT0.


Test Admin Role

Description

A new user teldat is created using the predefined admin role. This kind of role allows the execution of all operational commands and has access to the configuration menu.

Scenario

Step 1: Set the following configuration in DUT0:

set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$MWog.OS6sSmofMV1$y3iCNN..rM2hIblObaJA0d019yL3K4d71v80eFyD65sH6z87Mx8on0wCAjHfH2hbeV77GFz..qCPDhJVmRyo8.'
set system login user teldat role admin

Step 2: Run command service cnm restart at DUT0 and expect this output:

Show output
service inactive. doing nothing.

Step 3: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:43 +00:00
# Warning: Configuration has not been saved
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$MWog.OS6sSmofMV1$y3iCNN..rM2hIblObaJA0d019yL3K4d71v80eFyD65sH6z87Mx8on0wCAjHfH2hbeV77GFz..qCPDhJVmRyo8.'
set system login user teldat role admin

Step 4: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:25:43 +00:00

Step 5: Login as admin user on DUT0.

Note

Dynamically change the required user-level for some specific operational commands.

Step 6: Modify the following configuration lines in DUT0:

set user-level 0 command 'show running'
set user-level 10 command 'show date'

Step 7: Run command service cnm restart at DUT0 and expect this output:

Show output
service inactive. doing nothing.

Step 8: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:47 +00:00
# Warning: Configuration has not been saved
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$MWog.OS6sSmofMV1$y3iCNN..rM2hIblObaJA0d019yL3K4d71v80eFyD65sH6z87Mx8on0wCAjHfH2hbeV77GFz..qCPDhJVmRyo8.'
set system login user teldat role admin
set user-level 0 command 'show running'
set user-level 10 command 'show date'

Step 9: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:25:47 +00:00

Step 10: Login as admin user on DUT0.


Test Custom Role

Description

A new user teldat is created using a custom role. The user-level can be dynamically changed.

Scenario

Step 1: Set the following configuration in DUT0:

set system login role custom_role level 8
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$BLt68Yld4tfAx5ly$pLQ//D8Prnm58mPVfLR0rS5ucBJj.RzkoUkHCSDJEKP/mCQby60gYzCIJijc3t8Ol7ff6aOGv2JxjOi3jv.UC/'
set system login user teldat role custom_role

Step 2: Run command service cnm restart at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 3: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:56 +00:00
# Warning: Configuration has not been saved
set system login role custom_role level 8
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$BLt68Yld4tfAx5ly$pLQ//D8Prnm58mPVfLR0rS5ucBJj.RzkoUkHCSDJEKP/mCQby60gYzCIJijc3t8Ol7ff6aOGv2JxjOi3jv.UC/'
set system login user teldat role custom_role

Step 4: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:25:56 +00:00

Step 5: Login as admin user on DUT0.

Step 6: Modify the following configuration lines in DUT0:

set system login role custom_role level 14

Step 7: Run command service cnm restart at DUT0 and expect this output:

Show output
service inactive. doing nothing.

Step 8: Run command show running at DUT0 and expect this output:

Show output
# Teldat OSDx VM version v4.2.1.2
# Tue 03 Dec 2024 15:25:59 +00:00
# Warning: Configuration has not been saved
set system login role custom_role level 14
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system login user teldat authentication encrypted-password '$6$BLt68Yld4tfAx5ly$pLQ//D8Prnm58mPVfLR0rS5ucBJj.RzkoUkHCSDJEKP/mCQby60gYzCIJijc3t8Ol7ff6aOGv2JxjOi3jv.UC/'
set system login user teldat role custom_role

Step 9: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:26:00 +00:00

Step 10: Login as admin user on DUT0.

Step 11: Modify the following configuration lines in DUT0:

set system login role custom_role level 3

Step 12: Run command service cnm restart at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 13: Run command show running at DUT0 and expect this output:

Show output
CLI Error: Insufficient privileges

Step 14: Run command show date at DUT0 and expect this output:

Show output
Tue 03 Dec 2024 15:26:04 +00:00

Step 15: Login as admin user on DUT0.