Compared with level authorization, task authorization supports the customization of the user group and task group according to the application scenario. Therefore, task authorization provides a more flexible right control granularity.
The system view is displayed.
The AAA view is displayed.
The authorization scheme view is displayed.
The level authorization mode is configured.
The AAA view is displayed.
The task group is created, and the task group view is displayed.
The operation is allowed to be implemented on a specific command.
This command applies to a single command. Compared with the task command, this command is more granular and can be used for a single command or a batch of commands with the same prefix.
In the same task group, the priority of the rule command command is higher than that of the task command. When the rule command command configuration conflicts with the task command configuration, the rule command command configuration takes effect preferentially.
A specific task group is added to the current task group.
To allow the authority of the current task group to contain the authority of another task group or the current task group to inherit the authority of an existing task group, run the include task-group command.
If the authority of the contained task group changes, the authority of the current task group will change.
The AAA view is displayed.
The user group is created, and the user group view is displayed.
The specified task group is added to the current user group.
A specific user group is added to the current user group.
To allow the authority of the current user group to contain the authority of another user group or the current user group to inherit the authority of an existing user group, run the include user-group command.
The authority of a user group is determined by that of the user group it contains. If the authority of the contained user group changes, the authority of the current user group will change.
The operation is allowed to be implemented on a specific command.
This command applies to a single command.
The priorities of rules are displayed in descending order of rules configured in the user group view (including the rules inherited from other user groups using the include user-group command), rules configured in the task group view (rule command), and tasks configured in the task group (task).
If the rules configured in a user group conflict with the rules inherited from other user groups using the include user-group command, the rules configured in the user group take effect preferentially.
The AAA view is displayed.
A local user is created, and the password of the user is configured.
The new password is at least eight characters long and contains at least two of the following types: upper-case letters, lower-case letters, digits, and special characters, except the question mark (?) and space.
The local user is added to the specified user group.
The configuration is committed.