Skip to content

system-user

The following operations can be performed on "system-user":

add| rm| set| unset| bind| unbind| show|

add system user

Adds a new user to the system. Note: You must provide the password after the user name.

Synopsis

add system user <userName> [-externalAuth ( ENABLED | DISABLED )] [-promptString <string>] [-timeout <secs>] [-logging ( ENABLED | DISABLED )] [-maxsession <positive_integer>] [-allowedManagementInterface ( CLI | API ) ...]

Arguments

userName

Name for a user. Must begin with a letter, number, or the underscore (_) character, and must contain only alphanumeric, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), and underscore characters. Cannot be changed after the user is added.

CLI Users: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, "my user" or 'my user').

password

Password for the system user. Can include any ASCII character.

externalAuth

Whether to use external authentication servers for the system user authentication or not

Possible values: ENABLED, DISABLED Default value: ENABLED

promptString

String to display at the command-line prompt. Can consist of letters, numbers, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), underscore (_), and the following variables: * %u - Will be replaced by the user name. * %h - Will be replaced by the hostname of the Citrix ADC. * %t - Will be replaced by the current time in 12-hour format. * %T - Will be replaced by the current time in 24-hour format. * %d - Will be replaced by the current date. * %s - Will be replaced by the state of the Citrix ADC.

Note: The 63-character limit for the length of the string does not apply to the characters that replace the variables.

timeout

CLI session inactivity timeout, in seconds. If Restrictedtimeout argument of system parameter is enabled, Timeout can have values in the range [300-86400] seconds. If Restrictedtimeout argument of system parameter is disabled, Timeout can have values in the range [0, 10-100000000] seconds. Default value is 900 seconds.

logging

Users logging privilege

Possible values: ENABLED, DISABLED Default value: DISABLED

maxsession

Maximum number of client connection allowed per user Default value: 20 Minimum value: 1 Maximum value: 40

allowedManagementInterface

Allowed Management interfaces to the system user. By default user is allowed from both API and CLI interfaces. If management interface for a user is set to API, then user is not allowed to access NS through CLI. GUI interface will come under API interface Default value: NS_INTERFACE_ALL

rm system user

Removes a system user from the appliance.

Synopsis

rm system user <userName>

Arguments

userName

Name of the system user to remove.

set system user

Modifies the specified parameters of a system-user entry.

Synopsis

set system user <userName> {-password } [-externalAuth ( ENABLED | DISABLED )] [-promptString <string>] [-timeout <secs>] [-logging ( ENABLED | DISABLED )] [-maxsession <positive_integer>] [-allowedManagementInterface ( CLI | API ) ...]

Arguments

userName

Name of the system-user entry to modify.

password

Password for the system user. Can include any ASCII character.

externalAuth

Whether to use external authentication servers for the system user authentication or not

Possible values: ENABLED, DISABLED Default value: ENABLED

promptString

String to display at the command-line prompt. Can consist of letters, numbers, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), underscore (_), and the following variables: * %u - Will be replaced by the user name. * %h - Will be replaced by the hostname of the Citrix ADC. * %t - Will be replaced by the current time in 12-hour format. * %T - Will be replaced by the current time in 24-hour format. * %d - Will be replaced by the current date. * %s - Will be replaced by the state of the Citrix ADC.

Note: The 63-character limit for the length of the string does not apply to the characters that replace the variables.

timeout

CLI session inactivity timeout, in seconds. If Restrictedtimeout argument of system parameter is enabled, Timeout can have values in the range [300-86400] seconds. If Restrictedtimeout argument of system parameter is disabled, Timeout can have values in the range [0, 10-100000000] seconds. Default value is 900 seconds.

logging

Users logging privilege

Possible values: ENABLED, DISABLED Default value: DISABLED

maxsession

Maximum number of client connection allowed per user Default value: 20 Minimum value: 1 Maximum value: 40

allowedManagementInterface

Allowed Management interfaces to the system user. By default user is allowed from both API and CLI interfaces. If management interface for a user is set to API, then user is not allowed to access NS through CLI. GUI interface will come under API interface Default value: NS_INTERFACE_ALL

unset system user

Resets the specified system user parameters.Refer to the set system user command for meanings of the arguments.

Synopsis

unset system user [-allowedManagementInterface ...] <userName> [-externalAuth] [-promptString] [-timeout] [-logging] [-maxsession]

bind system user

Binds a command policy or partition to a system user.

Synopsis

bind system user <userName> ((<policyName> <priority>) | -partitionName <string>)

Arguments

userName

Name of the system-user entry to which to bind the command policy.

policyName

Name of the command policy to bind to the system user.

priority

Integer specifying the priority of the command policy. A lower number specifies a higher priority. Policies are evaluated in the order of their priority numbers. Minimum value: 0 Maximum value: 999999999

partitionName

Name of the Partition to bind to the system user.

unbind system user

Unbinds a command policy or partition from the system user.

Synopsis

unbind system user <userName> (<policyName> | -partitionName <string>)

Arguments

userName

Name of the user entry from which to unbind the command policy.

policyName

Name of the command policy to unbind.

partitionName

Name of the Partition to unbind.

show system user

Displays information about all system users configured on the appliance, or about the specified user.

Synopsis

show system user [<userName>]

Arguments

userName

Name of a system user about whom to display information.

Output

groupName

The system group.

policyName

The name of command policy.

priority

The priority of the policy.

password

Password for the system user. Can include any ASCII character.

encrypted

hashmethod

externalAuth

Whether to use external authentication servers for the system user authentication or not

promptString

String to display at the command-line prompt. Can consist of letters, numbers, hyphen (-), period (.), hash (#), space ( ), at (@), equal (=), colon (:), underscore (_), and the following variables: * %u - Will be replaced by the user name. * %h - Will be replaced by the hostname of the Citrix ADC. * %t - Will be replaced by the current time in 12-hour format. * %T - Will be replaced by the current time in 24-hour format. * %d - Will be replaced by the current date. * %s - Will be replaced by the state of the Citrix ADC.

Note: The 63-character limit for the length of the string does not apply to the characters that replace the variables.

promptInheritedFrom

From where the prompt has been inherited.

timeout

CLI session inactivity timeout, in seconds. If Restrictedtimeout argument of system parameter is enabled, Timeout can have values in the range [300-86400] seconds. If Restrictedtimeout argument of system parameter is disabled, Timeout can have values in the range [0, 10-100000000] seconds. Default value is 900 seconds.

timeoutKind

From where the timeout has been inherited.

partitionName

Name of the Partition to bind to the system user.

logging

Users logging privilege

maxsession

Maximum number of client connection allowed per user

allowedManagementInterface

Allowed Management interfaces to the system user. By default user is allowed from both API and CLI interfaces. If management interface for a user is set to API, then user is not allowed to access NS through CLI. GUI interface will come under API interface

allowedManagementInterfaceKind

Value of allowed interface which can be inherited from Global, Group or User.

devno

count

stateflag

Was this article helpful?