Outlines the implementation of task-based authorization, allowing authorized XR VM users to access router administration data via NETCONF and gRPC. It describes how the system maps user task groups to the System Admin VM, streamlining administrative access without requiring redundant user profiles on the admin instance.
This chapter describes the implementation of the administrative model of task-based authorization used to control user access in the software system.
| Feature Name |
Release Information |
Feature Description |
|---|---|---|
| OC support for AAA user |
Cisco IOS XR Release 7.3.2 |
This feature allows all authorized users on XR VM to access administration data on the router through NETCONF or gRPC interface, similar to accessing the CLI. This functionality works by internally mapping the task group of the user on XR VM to a predefined group on System Admin VM. Therefore, the NETCONF and gRPC users can access the administrative information on the router even if their user profiles do not exist on System Admin VM. Command added:
|
OC Support for AAA User
Provides details about OC (OpenConfig) support for AAA (Authentication, Authorization, Accounting) users, including release information and feature descriptions.
AAA services
Explains how authentication, authorization, and accounting (AAA) services create a robust framework for managing user access an
Admin access methods for NETCONF and gRPC
Explains how authorized users can securely access administrative data on Cisco IOS XR routers using NETCONF and gRPC, including internal user group mapping for efficient management.