Username credential changes not recognised by CLI interface
Posted: Fri Oct 09, 2015 12:06 pm
Hello all,
We have found a peculiar issue with our Netonix WS-12-250A switches running firmware v1.2.0, regarding the changing of username credentials and being able to login to the CLI with the new username via SSH.
Both the web interface and the CLI allow you to change the username and password credentials independently – or so it appears!
If only the password alone is changed from either the web interface or the CLI, the password change is effected and you can login to either interface with the current username and new password - good.
However, if only the username alone is changed from either the web interface or the CLI, the username change is only effected via the web interface. The web interface allows login with the new username and existing password.
Attempting to login to the CLI with the new username and existing password will fail and result in 'access denied' (via SSH). The CLI will only accept a login with the previous username and existing password.
Thus the only way to ensure access consistency between the web interface and CLI is whenever making any changes to the username via the web interface or CLI, is for both credentials to be entered, that is the password, which is to remain the same, has to be re-entered.
In most cases, I guess this issue wouldn't be encountered as the username would be fairly static, its more likely that a change in password would occur after initial config, however, it appears in our initial configuration of the switches, there was a change required to correct the username before they went out to site and we found that there was a difference between access with the correct credentials via the web interface and CLI which we investigated and replicated with our lab Netonix switch.
After searching the forums, I couldn not find a post with this issue nor it being resolved in one of the more recent firmware releases so just highlighting here for information and consideration for a fix.
Many Thanks,
Professor_K
We have found a peculiar issue with our Netonix WS-12-250A switches running firmware v1.2.0, regarding the changing of username credentials and being able to login to the CLI with the new username via SSH.
Both the web interface and the CLI allow you to change the username and password credentials independently – or so it appears!
If only the password alone is changed from either the web interface or the CLI, the password change is effected and you can login to either interface with the current username and new password - good.
However, if only the username alone is changed from either the web interface or the CLI, the username change is only effected via the web interface. The web interface allows login with the new username and existing password.
Attempting to login to the CLI with the new username and existing password will fail and result in 'access denied' (via SSH). The CLI will only accept a login with the previous username and existing password.
Thus the only way to ensure access consistency between the web interface and CLI is whenever making any changes to the username via the web interface or CLI, is for both credentials to be entered, that is the password, which is to remain the same, has to be re-entered.
In most cases, I guess this issue wouldn't be encountered as the username would be fairly static, its more likely that a change in password would occur after initial config, however, it appears in our initial configuration of the switches, there was a change required to correct the username before they went out to site and we found that there was a difference between access with the correct credentials via the web interface and CLI which we investigated and replicated with our lab Netonix switch.
After searching the forums, I couldn not find a post with this issue nor it being resolved in one of the more recent firmware releases so just highlighting here for information and consideration for a fix.
Many Thanks,
Professor_K