Details the structure of user identities for AAA, describing user categories, group management, task group organization, predefined groups, and the group inheritance process to support flexible administrative access control.
A user identity is a user record that
-
assigns each router user a unique ID across the administrative domain
-
limits passwords and one-way encrypted secrets to a maximum of 253 characters, and
-
associates each user with at least one user group, enabling attributes such as task IDs.
Additional reference information
User identities are central to managing access and authorization in Cisco IOS XR. Each identity ties the user to permission sets, ensuring secure and auditable access control.
-
A user named “admin” may belong to the “network-admins” group, granting permission to perform high-level tasks.
-
A user with a unique ID "operator1" may only access operational commands, based on assigned attributes.
-
Guest accounts without group assignment cannot perform authorized tasks.
-
Users with passwords exceeding 253 characters cannot be created.