System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

User identities

Want to summarize with AI?

Log in

Details the structure of user identities for AAA, describing user categories, group management, task group organization, predefined groups, and the group inheritance process to support flexible administrative access control.


A user identity is a user record that

  • assigns each router user a unique ID across the administrative domain

  • limits passwords and one-way encrypted secrets to a maximum of 253 characters, and

  • associates each user with at least one user group, enabling attributes such as task IDs.

Additional reference information

User identities are central to managing access and authorization in Cisco IOS XR. Each identity ties the user to permission sets, ensuring secure and auditable access control.

  • A user named “admin” may belong to the “network-admins” group, granting permission to perform high-level tasks.

  • A user with a unique ID "operator1" may only access operational commands, based on assigned attributes.

Counter-examples
  • Guest accounts without group assignment cannot perform authorized tasks.

  • Users with passwords exceeding 253 characters cannot be created.


Router user categories for AAA administrative access

Router users are classified by Cisco IOS XR AAA as follows:

  • Root system user: Owns the entire router chassis, has the highest privileges for all router components, and can monitor all secure domain routers in the system.

  • Root Secure Domain Router (SDR) user: Has administrative authority for a specific SDR.

  • SDR user: Has user access for a specific SDR.

Table 1. User categories

User category

Access scope

Root system user

Owns the entire router chassis, has the highest privileges over all router components, and can monitor all secure domain routers in the system.

Root Secure Domain Router (SDR) user

Has administrative authority for a specific SDR.

SDR user

Has user access for a specific SDR.

At least one root system user account must be created during router setup. Multiple root system users can exist.

Use the user category to determine the administrative scope that applies after AAA authenticates the user.


User groups for AAA services

A user group is a group object that

  • provides predefined user groups with defined attributes in Cisco IOS XR

  • allows administrators to configure user-defined user groups to meet operational needs, and

  • maintains independence between external TACACS+ or RADIUS user groups and local AAA database user groups on the router.

External user group behavior

User groups created in external servers are not related to the user group concept used in local AAA database configuration on the router. The management of external TACACS+ or RADIUS server user groups is independent, and the router does not recognize the user group structure. Remote user or group profiles may contain attributes specifying the groups (defined on the router) to which users belong, as well as individual task IDs. For more information, see the AAA password security and authorization policies chapter.

Configuration of user groups in external servers depends on the design of individual server products. Refer to the appropriate server product documentation for details.


Predefined user groups

Cisco IOS XR software provides predefined user groups whose attributes are already defined. Each group fulfills a particular administrative function.

Table 2. Predefined user groups

User group

Description

cisco-support

Used by the Cisco support team.

maintenance

Displays, configures, and executes commands for network, file, and user-related entities.

netadmin

Controls and monitors all system and network parameters.

provisioning

Displays and configures network, file, and user-related entities.

read-only-tg

Performs any show command but has no configuration ability.

retrieve

Displays network, file, and user-related information.

root-lr

Controls and monitors the specific secure domain router.

sysadmin

Controls and monitors all system parameters but cannot configure network protocols.

serviceadmin

Performs service administration tasks, for example Session Border Controller (SBC) tasks.

To verify the individual permissions of a user group, assign the group to a user and run the show user tasks command.


Task groups for AAA services

A task group is a task-permission object that

  • defines a collection of permitted task IDs for each action type

  • supports read, write, execute, and debug permissions on task IDs, and

  • allows configuration of task IDs both locally and from external AAA servers.

Additional reference information

Users can configure their own task groups to meet particular needs. Task IDs are defined in the router system and may also be configured in external TACACS+ or RADIUS servers. Task ID definitions may need to be supported before task groups are configured in external software.


Predefined task groups

Cisco IOS XR provides predefined task groups that administrators can use, typically for initial configuration.

Table 3. Predefined task groups

Task group

Description

cisco-support

Cisco support personnel tasks.

maintenance

Maintenance team tasks.

netadmin

Network administrator tasks.

operator

Operator day-to-day tasks, for demonstration purposes.

provisioning

Provisioning team tasks.

retrieve

Retrieve team tasks.

root-lr

Secure domain router administrator tasks.

sysadmin

System administrator tasks.

serviceadmin

Service administration tasks, for example SBC tasks.

Use the predefined task group as a starting authorization profile when its task set matches the intended operational role.


How group inheritance works

User groups and task groups can derive attributes from other groups of the same type. Inheritance is dynamic, meaning changes in the inherited group affect the inheriting group even when no explicit re-inheritance occurs.

Summary

The key components involved in the process are:

  • Administrator: Configures inheritance relationships between groups.

  • User group or task group: Receives attributes from inherited groups and maintains its own set of permissions.

  • AAA system: Calculates and updates the union of attributes for each group based on inheritance rules.

Group inheritance in Cisco IOS XR enables user groups and task groups to derive attributes dynamically from other groups, resulting in a union of permissions and roles.

Workflow

These stages describe how group inheritance works.

  1. The administrator configures group A to inherit from group B.

  2. The AAA system forms the new set of attributes for group A as the union of group A's attributes and group B's attributes.

  3. Any change in group B automatically affects group A through the inheritance relationship, even if group A is not explicitly re-inherited.

Result

The inheriting group has its original attributes as well as those derived from the inherited group, ensuring all appropriate permissions and roles are included.